TLDR
The Ill Bloom wallet vulnerability has allowed attackers to drain more than $5 million from weakly generated crypto wallets across major chains, exposing thousands of self-custody users to ongoing risk.
- A flaw in recovery phrase generation has let attackers brute-force seed phrases, with at least $5 million stolen from Bitcoin, Ethereum, Tron, Solana and other chains.
- The main risk is for users of lesser-known mobile software wallets that used poor randomness when creating seeds, while hardware wallets and most mainstream apps appear unaffected.
- More losses are possible as vulnerable wallets still exist, so users and wallet providers are being urged to run checks, rotate to safer wallets, and tighten key-generation practices.
Deep Dive
1. How The Ill Bloom Exploit Works
Security firm Coinspect found that some wallet software used insecure pseudorandom number generators when creating recovery phrases, making seed phrases and private keys much easier to guess than intended.
Reports show at least $5 million has already been drained from exposed wallets across Bitcoin, Ethereum, Polygon, Rootstock, Tron and Solana, with one wave of attacks stealing about $3.1 million from 431 wallets on May 27 and another $2 million at the end of June, according to a Cointelegraph summary.
Coinspect stresses this is not a single-wallet bug but a pattern affecting multiple lesser-known software wallets created since 2018, and has released a public address-checking tool while withholding full exploit details to avoid helping attackers, as covered by crypto.news.
2. Who Is Most At Risk And How To Reduce It
Research so far indicates that hardware wallets and most up-to-date mainstream software wallets are not affected; the highest risk is for users who generated seeds in obscure or older mobile wallet apps that may have weak randomness.
Coinspect and other firms advise that users who see unexplained fund movements should treat Ill Bloom as a possible cause and immediately move assets to newly generated wallets created with reputable software or hardware devices, without reusing old seed phrases, as highlighted in CoinMarketCaps community coverage.
If you ever used a niche or older mobile wallet, it is wise to treat those seeds as potentially unsafe, verify exposure using trusted tools, and migrate funds to stronger key-generation setups.
3. What To Watch Next In Wallet Security
Coinspect says vulnerable wallets are still being created, meaning attackers can keep scanning for weak key material and draining funds until affected software is patched and users migrate.
Security firms such as SlowMist are monitoring Ill Bloom, and researchers are urging wallet providers to add weak mnemonic detection to catch unsafe seeds before users deposit significant funds, according to Tokenposts report.
This fits a wider pattern in 2026 where many of the largest crypto losses stem from wallet, key and operational failures rather than smart contract bugs, underlining the need for better entropy, hardware-backed signing and routine key hygiene across the ecosystem.
Confidence: high because multiple independent security firms and news outlets report the same mechanism, affected chains and loss estimates.
Conclusion
Ill Bloom is a key-generation flaw rather than a single-app hack, and it has already led to millions of dollars in losses across major networks.
For everyday crypto users, the main takeaway is that the safety of your wallet depends heavily on how its seed was created: strong randomness, reputable software and hardware devices matter as much as on-chain protocol security.
Watching for wallet security updates, checking older addresses for exposure and favoring robust key-generation tools can significantly reduce the risk of similar exploits going forward.
