CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Attackers Exploit ‘Ill Bloom’ Vulnerability to Drain $3.1 Million From Cryptocurrency Wallets

July 10, 2026

Security firm Coinspect has disclosed a crypto wallet flaw called ‘Ill Bloom’ that is being actively exploited by attackers. The vulnerability stems from weak randomness in the generation of recovery phrases (seed phrases) by certain wallet software, allowing attackers to predict and brute-force the phrases and drain funds. On May 27, 2026, a coordinated sweep drained approximately $3.1 million from 431 wallets. Coinspect has traced 2,114 exposed addresses across Bitcoin, Ethereum, Rootstock, Tron, and Polygon, with over $5 million leaving these wallets since the sweep. The flaw primarily affects older or lesser-known mobile wallets, some dating back to 2018. Hardware wallets and most mainstream software wallets are not affected. Coinspect has not named the specific apps involved but provides a free checker at illbloom.org for users to test if their wallet address is compromised. The vulnerability is similar to previous flaws like Milk Sad (CVE-2023-39910) and Randstorm. Users with matched addresses are advised to treat their recovery phrase as compromised, create a new wallet with a fresh phrase, and move funds immediately. Coinspect is working to identify the affected wallet apps and notify vendors.

CVEs: CVE-2023-39910, CVE-2023-31290, CVE-2026-55200, CVE-2026-46817

Companies: Coinspect

Products: Libbitcoin Explorer, Trust Wallet