The Ill Bloom vulnerability is one of the most worrying threats to emerge in the crypto space recently , allowing malicious actors to empty users’ wallets without having to steal passwords or compromise systems. Cybersecurity firm Coinspect uncovered the flaw, which is found in the way some wallet software generates seed phrases — the words that fully control access to funds. The attack is already underway and the damage is running into millions of dollars.

According to Coinspect ’s findings , a coordinated theft occurred on May 27, 2025 , removing approximately $3.1 million from 431 wallets over a period of a few hours. The attack was characterized as coordinated because hundreds of unrelated wallets transferred their balances to the same few addresses at almost the same time. Since then, approximately another $2 million has been moved from exposed wallets, although it is unclear how much of that was stolen and how much was moved by their owners to a safe location.
See also: Microsoft: Vulnerability exposes millions of Android crypto wallet users
The technical background of the Ill Bloom vulnerability is relatively simple in its logic, but devastating in its consequences. Every self-custody wallet starts with a recovery phrase, usually 12 or 24 words , randomly selected from a huge pool of possible combinations. The randomness is what makes the phrase difficult to guess. The affected wallets, however, used a weak random-number generator , which drastically reduced the number of possible phrases to a range that an attacker could search.
How the Ill Bloom attack works on crypto wallets
Coinspect reconstructed the attack from start to finish: it worked through the full set of phrases the weak generator could produce, extracted the wallet addresses corresponding to each phrase, and checked the public blockchain for addresses that still held funds. The result is a watchlist of wallets created with weak phrases, regardless of the application used. Coinspect has not disclosed the exact size of this reduced pool, nor the names of the affected applications.
The overall impact is significant: as of May 27, over $5 million has been removed from these wallets. Coinspect considers this an underestimation, as it has only mapped a portion of the addresses and expects to discover more. At their peak in 2022, the same wallets were worth $12.56 million, although most of that value had already been reduced before the May 27 theft. The affected wallets mostly date back to 2018 and involve older or lesser-known mobile apps.
Hardware wallets are not affected by the Ill Bloom vulnerability , nor are most mainstream software wallets . The risk is mostly found in older or lesser-known mobile apps . Coinspect has created a free checker tool at illbloom.org , where users can paste their public wallet address to check if it is on the vulnerable list. The tool accepts Bitcoin , Tron , Solana , and Ethereum (including Polygon , BNB , and other EVM chains ) addresses .
See also: SHub Stealer: New version targets popular browsers & crypto wallets

Ill Bloom: What users should do to protect themselves
If the check returns a positive result, the recovery phrase should be considered compromised immediately. The funds are not safe simply because they have not been moved yet — the attacker can act at any time. The user should create a new wallet with a completely new phrase (12 to 24 words) and transfer their funds there as soon as possible. Reinstalling the old application or entering the same phrase elsewhere does not offer any security. A safe option is to use a hardware wallet, generating a new phrase on the device — without entering the old one.
A clean check result does not guarantee absolute security, as the list is still incomplete. However, a positive result is a clear warning. Important: a single weak phrase can compromise funds on every blockchain it checks, so users should check every address associated with the same seed — not just those that have already been emptied.
Coinspect also warns of scams that may arise from this situation. Scammers may offer to rescue users’ funds. A legitimate audit never requires confidential information. The company emphasizes that it will never ask for seed phrases, private keys, signatures, or approvals, nor will it ask users to send funds to recover or protect a wallet. Users should never enter their recovery phrase, private key, password, or backup file on any site or message. According to The Hacker News, the case remains under investigation and further revelations about the number of affected applications are expected.
See also: GitHub Phishing: Fake OpenClaw tokens to steal crypto wallets
The Ill Bloom is a reminder of how critical the quality of “randomness” is in generating cryptographic keys. Even a small weakness in the random-number generator can turn a seemingly secure wallet into an easy target. Users using older cryptocurrency apps — especially those from 2018 — are urged to immediately check their wallets and take the necessary protective measures before it’s too late.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
