← Radar

Incident case file

Sign in to watch

Ill Bloom — Weak Randomness Wallet Vulnerability

Incident date July 5, 2026

0 views

ActiveBitcoinEthereumPolygonRootstockTronSolana (BNB ChainMonadArbitrumGnosisOptimismBaseAvaxLineaHyperEVM per Coinspect FAQ)Weak Randomness / Wallet Generation VulnerabilityCluster: ILLBLOOM-PRNG-2026-07

Estimated loss

$5M

Victims identified

431
Victim group joining is coming soon.

Investigation

50%

Facts and investigation

Attacker: MISSING — Coinspect has deliberately withheld the primary attacker EOA(s) as part of a staged disclosure process ('avoiding details that could make exploitation easier'). No verbatim attacker address has been published as of this report.

Funds moved to: PARTIAL. Confirmed collector address for lower-balance victims: bc1phdwxpx7x5z6mkrzppwgqxd4l797w2p6saj39q558wqcgw5766cwsk9rzlf (per @coinspect tweet, July 10, 2026 18:51 UTC; balance observed 0.05085211 BTC / ~$3,266 at time of capture via Blockchair). Coinspect explicitly states 'higher-balance victims are being drained to separate destination addresses' — those remain undisclosed. May 27, 2026 coordinated sweep of 431 accounts ($3,140,968) converged on a small number of Ethereum collector ad
Dataset 'Ill Bloom Exposed Address Set 1 of June 2026': 2,114 active addresses identified across Bitcoin, Ethereum, Tron, Rootstock, Polygon, first-funded between September 2018 and May 2026. May 27, 2026 coordinated sweep drained 431 accounts for $3,140,968, split: Bitcoin $2,573,522, Ethereum $285,778, Rootstock $177,225, Tron $80,970, Polygon $23,473. One single Bitcoin account lost over $1.1M. Historical peak exposure of the dataset: $12.56M in April 2022. Detection methodology: destination

Timeline: Prior to May 27, 2026: root-cause discovery of the weak-PRNG seed generation vulnerability by unidentified attacker(s), later named 'Ill Bloom' by Coinspect (from the first weak seed phrase produced, 'illness blossom'). May 27, 2026: coordinated sweep across the analyzed address set — 431 accounts drained for $3,140,968 in total, funds converging on a small number of Ethereum collector addresses within hours. Between May 27 and July 5, 2026: Coinspect investigates and coordinates a staged responsible disclosure with affected wallet vendors, withholding technical exploit details and vendor names to limit further harm. July 5, 2026 (Sunday): Coinspect publicly discloses the Ill Bloom vulnerability and launches a public address checker at illbloom.org. July 5-6, 2026: approximately $2M additional value moves from exposed wallets — Coinspect does not characterize all of this as theft, noting it could partly reflect users proactively migrating funds after the warning. July 6, 2026: wide media pickup (TechTimes, BeInCrypto, Cointelegraph, crypto.news, Cryptonomist); SlowMist confirms it is monitoring the alert on X. July 10, 2026, 18:51 UTC: Coinspect posts an active-drain alert on X identifying a Bitcoin collector address (bc1phdwxpx7...k9rzlf) receiving funds from lower-balance addresses in the exposed set, while stating that higher-balance victims are being drained to separate, undisclosed destinations. Investigation remains ongoing; additional affected addresses continue to be identified.

Sources and coverage

Victim testimonies

No testimonies yet.

+ Add my testimony → (coming soon)