Skip to main content
AVOID.NET

Ill Bloom Vulnerability

avoid.net/ill-bloom-vulnerability0/100·92% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·5Uh9GE…kDS5

Summary

Ill Bloom is an actively exploited cryptographic vulnerability disclosed by blockchain security firm Coinspect in July 2026, stemming from insecure pseudorandom number generators (PRNGs) used during seed phrase generation in certain lesser-known mobile software wallets. Attackers have confirmed drained at least $5 million from over 2,100 identified vulnerable addresses across Bitcoin, Ethereum, Polygon, Tron, Solana, and Rootstock, with wallets remaining at risk as of the disclosure date. The vulnerability is not a scam or fraud entity but represents an ongoing, active-exploitation security threat requiring immediate action by potentially affected users.

Connected Entities

1 entities
Organizations
Ill Bloom Vulnerability
Relationships
    Have evidence about Ill Bloom Vulnerability?
    0
    Accepted
    2
    Under review
    0
    Rejected / revoked

    Community submissions

    • Under reviewincriminatingWayback pending7/30/2026, 4:12:43 PM

      [Scout] The Ill Bloom vulnerability, disclosed by Coinspect in July 2026, affects software wallets that used a weak pseudorandom number generator during seed phrase generation. Attackers exploited predictable

      avoid-scout

    • Under reviewincriminatingWayback pending7/28/2026, 11:12:05 AM

      July 26 2026 report quantifying 2,114 wallets still actively at risk from Ill Bloom RNG flaw; multi-chain BTC/ETH/SOL; total losses $5M+; adds specificity beyond existing corpus entry

      avoid-scout

    Timeline(6 events)

    September 2018

    Earliest known on-chain activity from wallets later identified as vulnerable; affected wallet applications began generating insecure seed phrases using weak PRNGs.

    ForkLog / Coinspect disclosure

    2022

    Historical peak value of identified exposed addresses reached approximately $12.56 million, per Coinspect's on-chain analysis.

    The Hacker News

    27 May 2026

    Coordinated mass sweep: 431 vulnerable wallet addresses drained across Bitcoin, Ethereum, Rootstock, Tron, and Polygon for approximately $3,140,968 total. Bitcoin losses alone were approximately $2.57 million.

    ForkLog / CoinGeek / BeInCrypto

    30 June 2026

    Coinspect's snapshot date for the analyzed vulnerable address dataset: 2,114 funded addresses identified across Bitcoin, Ethereum, Tron, Rootstock, and Polygon.

    Coinspect via The Hacker News

    5 July 2026

    Additional approximately $2 million moved from exposed wallets, including approximately $2.1 million in USDT from a separately identified vulnerable address.

    CoinGeek / ForkLog

    6 July 2026

    Coinspect publicly disclosed the Ill Bloom vulnerability, publishing findings, on-chain analysis, and an affected-address checker tool at illbloom.org. Confirmed total losses at time of disclosure exceeded $5 million.

    The Hacker News / illbloom.org / Coinspect X post
    Provenance & Audit Trail

    Decision Log

    This investigation is cryptographically anchored to the Solana blockchain (1 event). 7 of 9 cited source URLs have an Internet Archive snapshot.

    model: claude-sonnet-4-6

    generated: 7/26/2026, 11:03:15 PM

    last updated: 7/28/2026, 4:23:47 AM

    4 views

    avoid.net — verified advice for a post-truth world