TL;DR
- Security researchers have disclosed the Ill Bloom vulnerability, which exposes cryptocurrency wallets created with weak recovery phrase generation.
- Coinspect says attackers have stolen at least $5 million since May 27 and warns thousands of wallets may still be vulnerable.
- The flaw affects certain wallet software rather than blockchain networks, and users can check their wallet using Coinspect’s free tool.
A newly disclosed security flaw known as the Ill Bloom vulnerability could leave thousands of cryptocurrency wallets exposed to theft due to a weakness in how some wallet recovery phrases were generated. Security researchers at Coinspect estimate attackers have already stolen at least $5 million by exploiting wallets created with insufficient randomness.
The issue does not affect blockchain networks themselves. Instead, it targets certain wallet implementations that relied on an insecure pseudorandom number generator when creating seed phrases. Because a wallet’s recovery phrase is used to derive all of its private keys, weak entropy during seed generation can compromise the entire wallet.
Weak randomness can expose wallet recovery phrases
Cryptocurrency wallets rely on randomly generated recovery phrases to secure users’ funds. If the randomness used during seed phrase generation is predictable or insufficient, attackers don’t need to attempt to break modern cryptography. They may just be able to recreate the same recovery phrase.
According to Coinspect, the affected wallets were created using software that failed to generate enough entropy when producing recovery phrases. The vulnerability affects wallets across six blockchain ecosystems: Bitcoin, Ethereum, Polygon, Rootstock, Tron, and Solana.
The Ill Bloom vulnerability demonstrates that even strong cryptographic algorithms can be undermined if the process used to generate wallet recovery phrases is flawed.

Millions already stolen
Researchers say attackers have already exploited the weakness to steal at least $5 million worth of cryptocurrency from affected wallets since May 27. They believe the true figure may be significantly higher.
According to Coinspect, an attack on May 27 targeted 431 of the 2,114 vulnerable wallets identified by the researchers, draining approximately $3.1 million. On the day the company publicly disclosed the vulnerability, an additional $2 million was moved from exposed wallets before more users could secure their funds.
Unlike many software vulnerabilities that can be fixed with an update, wallets created from weak recovery phrases cannot simply be repaired.
Blockchain security remains intact
Coinspect’s findings reinforce that the issue lies in wallet software, not the blockchains themselves. The vulnerability highlights the importance of secure random number generation, which forms the foundation of cryptographic security across digital systems.
Current evidence suggests hardware wallets and most widely used software wallets remain safe. According to Coinspect, the highest risk is concentrated among certain lesser-known mobile wallet implementations, with vulnerable wallets dating back to at least 2018. The incident also echoes the 2023 Trust Wallet browser extension vulnerability. It similarly exposed wallets because of weaknesses in seed phrase generation rather than blockchain security itself.
Users urged to review wallet security
To help users determine whether they may be at risk, Coinspect has released a free public tool that allows users to check their wallet addresses against its database of identified vulnerable wallets. The company said it is intentionally withholding full technical details of the exploit until affected users have more time to move their funds, reducing the risk of copycat attacks. Blockchain security firm SlowMist also said it is monitoring the situation.
Users who believe they may have created a wallet using affected software should migrate their assets to a newly generated wallet from a trusted provider. Security researchers also recommend keeping wallet software up to date and following official guidance as more information becomes available.
Although the vulnerability affects only a subset of wallet implementations, its disclosure underscores how weaknesses in wallet software can create significant risks, even when the underlying blockchain remains secure.








