LIVE MARKET DATA SAT 11 JUL 2026 UTC [ VIEW ALL COINS ]
// Regulation

“Ill Bloom” Seed-Flaw Drains $5M as 431 of 2,114 Flagged Wallets Hit

Weak-randomness bug in seed-phrase generation has moved $5M across six chains since May 27, with hardware wallets untouched, Coinspect says.

Tomas Keller · ·3 min read
“Ill Bloom” Seed-Flaw Drains $5M as 431 of 2,114 Flagged Wallets Hit

A security defect dubbed “Ill Bloom” has moved roughly $5 million out of self-custody wallets since May 27, according to research firm Coinspect, which published its initial findings on Sunday. The bug traces to weak randomness in seed-phrase generation and spans six chains — Bitcoin, Ethereum, Polygon, Rootstock, Tron and Solana — with vulnerable addresses dating as far back as 2018.

Coinspect said the root cause sits in a flawed pseudo-random number generator used by some software wallets when creating the private keys behind a recovery phrase. A narrowed key range makes those keys guessable for an attacker who has decoded the pattern, meaning the drains stem from predictable key generation rather than phishing or a smart-contract exploit.

Two drain events, one address set

On-chain data tied to a single cluster of addresses shows how concentrated the damage has been. In a bulk sweep on May 27, attackers pulled roughly $3.1 million from 431 of 2,114 wallets flagged as vulnerable. A second wave on Sunday moved another $2 million from exposed accounts, pushing the confirmed total to about $5 million.

Coinspect cautioned that its analysis may not yet capture every chain or every address generated under the same weak pattern, meaning the real figure is likely higher. The spread across six networks points to a shared coding flaw rather than an incident isolated to one blockchain.

Exposure traces back to 2018

The timing is a central concern: Coinspect says vulnerable wallets go back to 2018, and new exposed addresses were still being generated in recent weeks. That long tail suggests the weak generation pattern has been carried across multiple codebases over the years rather than confined to one application that can simply be patched and forgotten.

Current evidence indicates users who generated seed phrases with a hardware wallet are unaffected, and most widely used software wallets appear safe. The highest-risk profile is owners who created recovery phrases in lesser-known mobile software wallets — often the same clients used to hold speculative tokens or DeFi positions — who are being urged to check the published tool and migrate to freshly generated keys.

SlowMist confirms monitoring as sentiment stays fearful

Security team SlowMist confirmed it is tracking the Ill Bloom weak-randomness warning and has urged users to review legacy wallet addresses that may predate current security standards. The parallel monitoring signals the industry is treating this as an ecosystem-wide entropy failure rather than a single theft, with the response centered on detection and migration rather than a single vendor patch.

The disclosure lands during a risk-averse stretch for the broader market. COINOTAG’s aggregated data puts the Fear & Greed Index at 24, deep in “Extreme Fear” territory, with Bitcoin dominance at 69.3%. BTC/USDT was last changing hands near $62,853, up 0.21% on the day, with 24-hour volume of $11.35 billion, a long/short split of 63.1%/36.9% and an RSI of 48.6.

More Regulation

Leave a Reply

Your email address will not be published. Required fields are marked *