Incident case file
Sign in to watchIll Bloom — Weak Randomness Wallet Vulnerability
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: MISSING — Coinspect has deliberately withheld the primary attacker EOA(s) as part of a staged disclosure process ('avoiding details that could make exploitation easier'). No verbatim attacker address has been published as of this report.
Timeline: Prior to May 27, 2026: root-cause discovery of the weak-PRNG seed generation vulnerability by unidentified attacker(s), later named 'Ill Bloom' by Coinspect (from the first weak seed phrase produced, 'illness blossom'). May 27, 2026: coordinated sweep across the analyzed address set — 431 accounts drained for $3,140,968 in total, funds converging on a small number of Ethereum collector addresses within hours. Between May 27 and July 5, 2026: Coinspect investigates and coordinates a staged responsible disclosure with affected wallet vendors, withholding technical exploit details and vendor names to limit further harm. July 5, 2026 (Sunday): Coinspect publicly discloses the Ill Bloom vulnerability and launches a public address checker at illbloom.org. July 5-6, 2026: approximately $2M additional value moves from exposed wallets — Coinspect does not characterize all of this as theft, noting it could partly reflect users proactively migrating funds after the warning. July 6, 2026: wide media pickup (TechTimes, BeInCrypto, Cointelegraph, crypto.news, Cryptonomist); SlowMist confirms it is monitoring the alert on X. July 10, 2026, 18:51 UTC: Coinspect posts an active-drain alert on X identifying a Bitcoin collector address (bc1phdwxpx7...k9rzlf) receiving funds from lower-balance addresses in the exposed set, while stating that higher-balance victims are being drained to separate, undisclosed destinations. Investigation remains ongoing; additional affected addresses continue to be identified.
Sources and coverage
- Articleillbloom.orghttps://illbloom.org/
- Articlethehackernews.comhttps://thehackernews.com/2026/07/attackers-exploit-ill-bloom.html
- Articletechtimes.comhttps://www.techtimes.com/articles/319796/20260706/crypto-wallets-lose-5m-broken-random-number-generator-ill-bloom-disclosure.htm
- Articlecoingeek.comhttps://coingeek.com/ill-bloom-flaw-puts-2114-digital-wallets-at-risk-report/
- Articlebeincrypto.comhttps://beincrypto.com/ill-bloom-vulnerability-crypto-wallets/
- Articlecrypto.newshttps://crypto.news/coinspect-warns-ill-bloom-flaw-may-drain-more-crypto-wallets/
- Articleen.cryptonomist.chhttps://en.cryptonomist.ch/2026/07/06/ill-bloom-vulnerability-crypto-wallets/
- Articlethecurrencyanalytics.comhttps://thecurrencyanalytics.com/altcoins/ill-bloom-flaw-puts-thousands-of-crypto-wallets-at-risk-across-multiple-chains-273270
- Articlecryip.cohttps://cryip.co/ill-bloom-vulnerability-puts-thousands-of-crypto-wallets-at-risk/
- Articletradingview.comhttps://www.tradingview.com/news/cointelegraph:e1ab8d173094b:0-thousands-of-crypto-wallets-at-risk-from-ill-bloom-vulnerability-coinspect/
- Articlex.comhttps://x.com/coinspect/status/2075608748572258521
- Articleblockchair.comhttps://blockchair.com/bitcoin/address/bc1phdwxpx7x5z6mkrzppwgqxd4l797w2p6saj39q558wqcgw5766cwsk9rzlf
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)