Disclosure of technical details for the wallet vulnerability.
Wallet Flaw Details
Coinspect Security has now released details behind the Ill Bloom vulnerability, which I’ve independently helped research. See post no. 20 for previous context.
Summarized briefly, the underlying flaw comes from the popular crypto-js JavaScript library, which started using a very insecure custom random number generator function based on Math.random() in 2014. Cryptocurrency wallet software which used affected versions of crypto-js, either directly or through libraries like ferrumnet bip39, ended up with a catastrophic lack of entropy in their long-lived wallet secrets.
At the moment, Coinspect has released three new articles:
- Technical Ill Bloom details
- Identifying affected wallet applications
- Drain analysis for Chinese mnemonics
A future Milk Sad blog post will outline more details and impacts of this flaw.
Public Ill Bloom Address Lists
I’ve uploaded lists of weak cryptocurrency addresses of vulnerable Ill Bloom wallets in the public Milk Sad research data collection. For Ill Bloom, this currently covers BTC, ETH and LTC.
Note that the data is known to be incomplete due to the large potential search range. It should represent a good starting point for other researchers who want to look into the on-chain history of the affected wallets.