Skip to main content
Sign in

Ill Bloom Vulnerability

avoid.net/ill-bloom-vulnerability0/100·92% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

Ill Bloom is an actively exploited cryptographic vulnerability disclosed by blockchain security firm Coinspect in July 2026, stemming from insecure pseudorandom number generators (PRNGs) used during seed phrase generation in certain lesser-known mobile software wallets. Attackers have confirmed drained at least $5 million from over 2,100 identified vulnerable addresses across Bitcoin, Ethereum, Polygon, Tron, Solana, and Rootstock, with wallets remaining at risk as of the disclosure date. The vulnerability is not a scam or fraud entity but represents an ongoing, active-exploitation security threat requiring immediate action by potentially affected users.

Have evidence about Ill Bloom Vulnerability?

Timeline(6 events)

2018-09-01

Earliest known on-chain activity from wallets later identified as vulnerable; affected wallet applications began generating insecure seed phrases using weak PRNGs.

ForkLog / Coinspect disclosure

2022-01-01

Historical peak value of identified exposed addresses reached approximately $12.56 million, per Coinspect's on-chain analysis.

The Hacker News

2026-05-27

Coordinated mass sweep: 431 vulnerable wallet addresses drained across Bitcoin, Ethereum, Rootstock, Tron, and Polygon for approximately $3,140,968 total. Bitcoin losses alone were approximately $2.57 million.

ForkLog / CoinGeek / BeInCrypto

2026-06-30

Coinspect's snapshot date for the analyzed vulnerable address dataset: 2,114 funded addresses identified across Bitcoin, Ethereum, Tron, Rootstock, and Polygon.

Coinspect via The Hacker News

2026-07-05

Additional approximately $2 million moved from exposed wallets, including approximately $2.1 million in USDT from a separately identified vulnerable address.

CoinGeek / ForkLog

2026-07-06

Coinspect publicly disclosed the Ill Bloom vulnerability, publishing findings, on-chain analysis, and an affected-address checker tool at illbloom.org. Confirmed total losses at time of disclosure exceeded $5 million.

The Hacker News / illbloom.org / Coinspect X post
Provenance & Audit Trail
6 Wayback Archives

Decision Log

  • #1publish⛓ pending7/26/2026, 11:03:27 PM
    hash: DNhR2jGS8nMou2JA5Ckv1vdk5GwaJ1ucqh4T6HiQFac3

6 of 9 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 7/26/2026, 11:03:15 PM

last updated: 7/27/2026, 8:50:59 PM

avoid.net — verified advice for a post-truth world