Coinspect Warns: 'Ill Bloom' Flaw Drains $5 Million from Crypto Wallets Since 2018

Coinspect identified 2,114 vulnerable wallet addresses and confirmed a May 27 attack that targeted 431 wallets, draining about $3.1 million; a second wave later drained roughly $2 million from additional exposed wallets.
The Ill Bloom weakness is not tied to a single wallet app or chain; wallets created since 2018—and even some created recently—can be compromised, indicating an industry-wide wallet-implementation entropy issue rather than a single buggy app.
SlowMist is actively monitoring the Ill Bloom alert and has urged users to check older wallet addresses for signs of compromise.
This is a wallet-implementation security risk rather than a Bitcoin protocol flaw; historical examples, such as a 2023 Trust Wallet vulnerability identified by Ledger researchers, show that similar entropy-related issues have appeared across wallet ecosystems and were often patched before funds were stolen.
A security flaw called "Ill Bloom" has drained at least $5 million from crypto wallets across six blockchains since May 27, according to Coinspect. The blockchain security firm identified 2,114 vulnerable wallet addresses and confirmed attackers are actively exploiting the weakness right now.
The flaw hits wallets on Bitcoin, Ethereum, Polygon, Rootstock, Tron, and Solana, reports CryptoNews. It stems from weak randomness used during seed-phrase creation — the process that generates the secret recovery words tied to a wallet. Wallets built this way since 2018 could be at risk.
The first attack hit on May 27. Coinspect confirmed that 431 wallets were drained in a coordinated strike, with about $3.1 million stolen, according to KuCoin. A second wave followed in the days after, pulling roughly $2 million more from additional exposed wallets.
Coinspect found 2,114 vulnerable addresses in total. The speed of the second wave suggests attackers are actively scanning for weak wallets, not waiting. Parameter noted that funds can be taken at any time once a wallet is flagged as vulnerable.
The Ill Bloom flaw is not a bug in Bitcoin or any other blockchain protocol. It is a wallet-software problem. Some mobile wallet apps used weak entropy — meaning poor-quality randomness — when generating seed phrases, according to Traders Union. That makes the phrases easier to guess or recreate.
The issue dates back to 2018, but some recently created wallets are also affected. Researchers point out that hardware wallets and many modern software wallets appear much less exposed. This is an industry-wide gap in wallet implementation, not a single buggy app, says CryptoNews.
Security firm SlowMist is actively monitoring the Ill Bloom alert. It has urged users to check older wallet addresses for signs of compromise, according to Crypto.news. The warning is especially aimed at people who created mobile wallets between 2018 and today.
Coinspect has released a free tool to help users verify if their wallet addresses are at risk. Anyone who used a lesser-known mobile wallet app in recent years should check their addresses immediately. If a wallet is flagged, moving funds to a new, secure wallet right away is the recommended step, per KuCoin.
Ill Bloom is not the first case of weak seed generation causing losses. In 2023, Ledger researchers found a similar entropy flaw in Trust Wallet. That vulnerability was patched before large-scale theft occurred, according to Parameter. But the Ill Bloom case shows not all such flaws get caught in time.
Researchers say the broader lesson is about wallet software quality. Strong randomness during seed creation is a basic security requirement. When developers skip it or get it wrong, users pay the price — sometimes years later, as the 2018 origin date of this flaw makes clear, notes Traders Union.
Publishers
12
Articles
9
Reach
21