A security disclosure from Coinspect is drawing renewed attention to a basic but often invisible failure point in crypto wallets: how the recovery phrase gets generated in the first place.

The firm calls the flaw Ill Bloom. At its core, it is a weak, predictable random-number generator used by certain software wallets when creating a new seed phrase. Instead of pulling from a source of randomness strong enough to make the resulting 12- or 24-word phrase practically impossible to guess, the affected implementations used a generator with far less entropy than assumed — narrow enough that an attacker who understands the flaw can work backward from a public wallet address to the private key controlling it.

How the flaw actually works

A wallet’s security ultimately rests on the unpredictability of its seed phrase. If that phrase is generated using a strong, properly seeded random-number generator, guessing it is computationally infeasible. Ill Bloom breaks that assumption: the affected wallets used an insecure pseudorandom number generator during phrase creation, which shrinks the effective space of possible phrases down to something attackers can search.

Coinspect’s research traces the issue back to wallets created as early as 2018, meaning some exposed funds have been sitting in vulnerable addresses for years without their owners knowing.

Who is actually at risk

Two things narrow the blast radius considerably.

First, hardware wallets are not affected. Coinspect’s disclosure is specific to certain software wallet implementations — apps that generate and store keys on a general-purpose phone or computer rather than dedicated hardware.

Second, most mainstream software wallets are not affected either. Coinspect has identified five vulnerable implementations, more often found among lesser-known mobile wallet apps rather than the widely used names in the space. The firm has deliberately not published the full list of affected apps yet, citing an ongoing staged disclosure process — one affected developer has already notified its users, while others are reportedly discontinued, unresponsive, or still being identified.

The vulnerability spans multiple chains rather than a single ecosystem: Coinspect’s disclosure lists wallets across Bitcoin, Ethereum, Polygon, Rootstock, Tron and Solana as exposed, since the flaw sits in the wallet software’s key-generation code rather than in any one blockchain’s protocol.

The scale of the damage

Coinspect identified 2,114 wallets it considers vulnerable based on its analysis of the flawed generator’s output space. On May 27, 2026, attackers drained 431 of them, taking $3.1 million in a single coordinated sweep. Total losses tied to Ill Bloom have since climbed past $5 million as attackers continue working through the remaining exposed addresses.

That gap — thousands of identified vulnerable wallets against a fraction actively drained so far — is the uncomfortable part of this disclosure. It implies remaining exposed funds are still sitting in addresses attackers can plausibly reach, for as long as those funds stay in place.

What you can actually do about it

Coinspect has published a free checking tool at illbloom.org that lets users verify whether their wallet address falls within the flagged vulnerable set. If a check comes back clear — or if funds are held on a hardware wallet or a well-established mainstream software wallet — Coinspect’s findings do not indicate exposure.

For anyone who cannot confirm which random-number generator their wallet software used when the seed phrase was first created, especially for wallets set up on lesser-known mobile apps years ago, the safer move is to treat the funds as if they could be exposed: generate a brand-new wallet using a wallet you can verify is unaffected, then move funds to that new address rather than waiting for confirmation.

Why this matters beyond one disclosure

Ill Bloom is a reminder that wallet security failures do not always look like a hacked exchange or a drained smart contract. A flaw sitting quietly in key-generation code can go undetected for years, because the wallet behaves normally in every visible way right up until an attacker who understands the flaw comes looking. The years-long gap between when some of these wallets were created and when the flaw surfaced is the pattern worth remembering, independent of this specific case.

Bottom line

Ill Bloom is not evidence that crypto wallets in general are unsafe — hardware wallets and mainstream software wallets fall outside its scope. It is evidence that the specific software implementation of a wallet, not just the blockchain it connects to, determines whether a seed phrase is actually as random as it needs to be. Anyone unsure which category their wallet falls into has a free way to check, and a clear next step if the answer is uncertain: move the funds rather than assume they are fine.

Advertisement

Sources and review

This article was checked against the primary or authoritative sources below .

Frequently asked questions

What is the Ill Bloom vulnerability?

It is a flaw, disclosed by security firm Coinspect, in how certain software wallets generate seed phrases. Some implementations used an insecure pseudorandom number generator, making the resulting recovery phrase predictable enough for an attacker to reconstruct and take control of the wallet.

Are hardware wallets affected?

No. Coinspect says wallets generated on hardware devices are not affected, and most mainstream software wallets are not either. The flaw is limited to a small number of software wallet implementations that used the same flawed randomness source.

How much has been stolen so far?

An attack on May 27, 2026 hit 431 of 2,114 identified vulnerable wallets, draining $3.1 million. Total losses linked to Ill Bloom have since passed $5 million as attackers continue targeting the remaining exposed addresses.

Which wallets are vulnerable?

Coinspect has identified five vulnerable wallet implementations but has not named all of them publicly, citing an ongoing staged disclosure process. One affected wallet app has notified its users directly; others are reportedly discontinued, unmaintained, or still unidentified.

How can I check if my wallet is affected?

Coinspect published a free checking tool at illbloom.org. Funds held in a wallet generated on a hardware device, or in one of the well-established mainstream software wallets, are not considered at risk based on Coinspect's findings so far.

Advertisement

V

Vijay Rathod

Independent crypto and financial-markets analyst covering Bitcoin, altcoins, macroeconomics, and trading news. More about the author →