Ill Bloom Vulnerability Drains $5M From Crypto Wallets, BTC Holders Urged to Act

Ill Bloom Vulnerability Drains $5M From Crypto Wallets, BTC Holders Urged to Act

N
News Editor 01
2026-07-23 16:35:23
Blockchain security firm Coinpect warns of the 'Ill Bloom' flaw actively exploited since late May, siphoning at least $5 million from wallets created as early as 2018. Hardware wallets remain safe; BTC holders urged to check addresses.
Ill Bloomvulnerabilitycrypto wallet securityseed phrasebrute-force attack

Blockchain security firm Coinspect has issued an urgent warning over a vulnerability dubbed "Ill Bloom", which has been actively exploited to drain at least $5 million from crypto wallets since May 27. The flaw primarily affects lesser-known mobile software wallets created as far back as 2018.

Two Waves of Attacks: Over 400 Wallets Breached

According to Coinspect's data, the first attack on May 27 directly compromised 431 out of 2,114 exposed wallets, resulting in the theft of approximately $3.1 million in crypto assets. A second wave on Sunday, June 7, stole nearly $2 million more from remaining vulnerable wallets. Coinspect noted that the actual number of compromised wallets could be higher, as similar weaknesses may exist across different blockchains and address types.

The company has not yet released full technical details but provides a free scanning tool for users to check if their addresses are at risk. For those who experienced unauthorized transfers, Coinspect said the Ill Bloom vulnerability could be a potential cause.

Hardware Wallets Safe; Older Software Wallets at Highest Risk

Coinspect emphasized that, based on current evidence, users who generated seed phrases with a hardware wallet are unaffected. Most up-to-date software wallets also appear immune. The highest risk group includes users who created seed phrases in obscure mobile wallet apps, where entropy (randomness) in the generation process was insufficient.

Blockchain security firm SlowMist said Monday on X that it is closely monitoring Coinspect's Ill Bloom warning. The incident highlights a persistent security gap: low-entropy seed phrases that make brute-force attacks feasible.

Historical Echo: Trust Wallet and Libbitcoin Similar Flaws

This is not the first time entropy-related flaws have led to major thefts. In 2023, Ledger's security team found that seed phrases generated via the Trust Wallet browser extension had only about 4 billion possible combinations — enough for attackers to crack a wallet in less than a day. Earlier that year, a flaw in Libbitcoin Explorer allowed brute-forcing of private keys, leading to the theft of roughly $900,000 in crypto assets.

For Bitcoin holders, the takeaway is clear: if your wallet seed phrase was generated on an old or obscure mobile app years ago, move funds to a hardware wallet or a well-audited software wallet immediately. The Ill Bloom incident serves as a stark reminder that randomness quality remains a critical security layer in self-custody.

This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan.
100

Disclaimer:

The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.

Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.