logo

Attackers Exploit 'Ill Bloom' Vulnerability to Drain Over $5 Million From Cryptocurrency Wallets

ID: 1d6ace34-e664-5307-9ed1-667890d0c1c0

STIX ID: report--1d6ace34-e664-5307-9ed1-667890d0c1c0

Feed Name: The Hacker News

Threat Score
75/100

Date Published: 2026-07-10

Date Updated: 2026-07-18

Author: [email protected] (The Hacker News)

...
...

**Executive summary:** Coinspect disclosed a weakness called "Ill Bloom" in the seed-phrase generation of older or lesser-known crypto wallets that used a weak random-number generator; attackers reconstructed the limited set of possible phrases, matched derived addresses on-chain, and carried out coordinated sweeps that have so far stolen millions across Bitcoin, Ethereum and other chains. The firm traced thousands of exposed addresses, confirmed a May 27 coordinated theft that drained about $3.1M (total confirmed losses >$5M), provides an online checker (illbloom.org) to detect affected addresses, and advises immediately creating fresh wallets (preferably hardware-generated) and moving funds; five vulnerable implementations were identified but not yet named.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.