Coinspect warned that thousands of cryptocurrency wallets may be vulnerable to a weakness in recovery phrase generation, known as Ill Bloom, which could allow unauthorized drain...
Coinspect warned that thousands of cryptocurrency wallets may be vulnerable to a weakness in recovery phrase generation, known as Ill Bloom, which could allow unauthorized drainage of funds. The issue stems from an insecure pseudorandom number generator used during seed creation on certain software wallets, affecting Bitcoin, Ethereum, Polygon, Rootstock, Tron and Solana addresses, with vulnerabilities dating to 2018 and more frequently observed in lesser‑known mobile applications. Coinspect reported that since May 27, at least $5 million has been taken from exposed wallets, including $3.1 million from 431 of 2,114 vulnerable addresses identified in a May 27 attack and an additional $2 million moved on Sunday. The research indicated that users who generated seeds with hardware wallets or widely used software wallets are not affected, while the strongest candidates are those who used less common mobile wallets. Coinspect has not disclosed details of the active exploit and has released a wallet‑checking tool for users to assess potential exposure. SlowMist noted on X that it is monitoring the Ill Bloom risk alert. Coinspect said it will continue to monitor the vulnerability, and further analysis may reveal additional affected networks or addresses.
- Publisher
- cointelegraph
- Reliability
- high
- Published
- 7/6/2026, 10:00:24 AM
- Retrieved
- 7/6/2026, 10:00:24 AM
- Relevance
- 80%
- Confidence
- 85%

