Share
Subscribe to the AlphaWire Newsletter
Thousands of cryptocurrency wallets could remain vulnerable after blockchain security company Coinspect disclosed a long-running weakness in how some software wallets generated recovery phrases. The flaw, named Ill Bloom, stems from weak randomness during seed phrase creation, allowing attackers to predict wallet credentials in certain cases and drain funds across multiple blockchain networks.
According to Coinspect, the vulnerability appears to have affected wallets created as far back as 2018, with affected wallets continuing to be created until recent weeks. The findings suggest the issue remained active for years before being publicly disclosed, prompting the company to launch a wallet checker that helps users identify potentially exposed addresses.
Today we are publishing the first Ill Bloom findings: affected-address checker + on-chain analysis to help users identify exposed addresses and protect their assets.
🔗 https://t.co/U0b4f3jtgz
⚠️ We will never ask for seed phrases, private keys, signatures, or approvals, or ask…— Coinspect Security (@coinspect) July 6, 2026
According to Coinspect, Ill Bloom affects recovery phrases generated with insufficient randomness by certain software wallets. The company said exposed wallets span Bitcoin, Ethereum, Polygon, Rootstock, Tron, Solana, and Ethereum layer-2 networks, though it has not publicly identified the vulnerable applications while responsible disclosure efforts continue.
Hundreds of accounts were drained of ~$3M on May 27, 2026. In the last few hours, another ~$2M was moved from exposed wallets.
Thousands of accounts remain at risk across Bitcoin, Ethereum + L2s, Tron, and Solana.
— Coinspect Security (@coinspect) July 6, 2026
Researchers analyzed a monitored data set containing 2,114 exposed wallet seeds with confirmed onchain activity. Within that group, a coordinated drain on May 27, 2026, emptied 431 wallets, resulting in $3.14 million in stolen cryptocurrency. Coinspect said its broader investigation has identified more than $5 million in stolen assets across exposed wallets.

Rather than publishing technical exploit details, Coinspect launched a public address checker that allows users to determine whether their wallet addresses appear in its monitored data set. The company said it intentionally withheld exploit information to reduce the risk of copycat attacks while continuing to identify additional affected wallets.
Coinspect noted an important limitation in its findings, saying the analyzed address set represents only a measured subset of confirmed exposure rather than every affected wallet. Current evidence also indicates that hardware wallets are not impacted, while most modern software wallets appear unaffected. The strongest candidates remain recovery phrases generated by lesser-known mobile wallet applications.
SlowMist acknowledged the disclosure and encouraged users to check historical wallet addresses through the Ill Bloom website while thanking Coinspect for its responsible disclosure process.
We're closely monitoring the Ill Bloom wallet weak randomness risk alert from @coinspect .
Please check whether any of your historical wallet addresses are affected👉 https://t.co/cTRltZCfyB
Thanks to @coinspect for the responsible disclosure. Stay safe! https://t.co/cC6OTxqvpX
— SlowMist (@SlowMist_Team) July 6, 2026
Ill Bloom adds to a series of wallet security flaws disclosed in recent years. In 2023, Ledger’s security team disclosed an entropy generation flaw in the Trust Wallet browser extension before any funds were stolen. That same year, attackers exploited a weakness in Libbitcoin Explorer to steal about $900,000 through private key brute-force attacks. Coinspect said additional findings and wallet detection tools will be released as the investigation progresses.
Create a free account to continue reading AlphaClub articles and access exclusive features.
Share