Thousands of cryptocurrency wallets may be vulnerable to theft due to weak seed phrase generation, according to blockchain security firm Coinspect, which has identified the issue as “Ill Bloom.”
The vulnerability affects wallets created on major blockchain networks, including Bitcoin, Ethereum, Polygon, Rootstock, Tron, and Solana. Coinspect said the flaw comes from weak randomness used during wallet creation, making some private keys easier to predict than they should be.
Today we are publishing the first Ill Bloom findings: affected-address checker + on-chain analysis to help users identify exposed addresses and protect their assets.
🔗 https://t.co/U0b4f3jtgz
⚠️ We will never ask for seed phrases, private keys, signatures, or approvals, or ask…— Coinspect Security (@coinspect) July 6, 2026
The company has released a wallet-checking tool to help users determine whether their wallet addresses may be affected. According to Coinspect, some vulnerable wallets date back to 2018, while new cases have still been identified in recent weeks.
How does the Ill Bloom vulnerability put wallets at risk?
Coinspect said the issue is linked to poor random number generation during the creation of seed phrases. Since seed phrases are used to generate private keys, weak randomness can make wallets easier for attackers to crack.
The firm warned that users who noticed funds leaving their wallets without authorization could have been affected by the vulnerability.
Coinspect has not disclosed the full technical details of the exploit, saying the decision is intended to reduce the risk of further attacks while users secure their funds.
More than $5 million already been moved from exposed wallets
Early findings from Coinspect show that attackers drained about $3.1 million from 431 wallets during an attack on May 27 involving 2,114 vulnerable accounts. Another $2 million was moved from exposed wallets on Sunday.
The company estimates that at least $5 million has been transferred from vulnerable wallets so far. However, it believes the actual figure could be higher because its investigation does not yet cover every affected blockchain or address.
We’re closely monitoring the Ill Bloom wallet weak randomness risk alert from @coinspect .
Please check whether any of your historical wallet addresses are affected👉 https://t.co/cTRltZCfyB
Thanks to @coinspect for the responsible disclosure. Stay safe! https://t.co/cC6OTxqvpX
— SlowMist (@SlowMist_Team) July 6, 2026
Blockchain security firm SlowMist said it is also monitoring the Ill Bloom alert and advised users to review older wallet addresses for possible exposure. Meanwhile, Cardano founder Charles Hoskinson revealed an experimental smart contract designed to help users recover lost self-custody wallets without exposing their secret recovery phrases.
Which wallets are most likely to be affected?
Coinspect said there is currently no evidence that hardware wallets are affected by the flaw. It also noted that most modern software wallets do not appear to be vulnerable based on its ongoing research.
Instead, the company believes the highest risk is among users who created wallets through less popular mobile wallet apps, particularly older versions.
Users who discover their wallets are vulnerable are advised to transfer their assets to a newly generated wallet created with trusted software or a hardware wallet. Coinspect also warned against reusing an older seed phrase that may have been generated with weak randomness.
Enjoyed this? Bookmark DeFi Planet, explore related topics, and follow us on Twitter, LinkedIn, Facebook, Instagram, Threads and CoinMarketCap Community for seamless access to high-quality industry insights
Take control of your crypto portfolio with DEFI PLANET PRO, DeFi Planet’s suite of analytics.























































































