An attack on May 27, 2026 hit 431 of 2,114 identified vulnerable wallets, draining $3.1 million. Total losses have since passed $5 million.
Coinspect says wallets generated on hardware devices are not affected, and most mainstream software wallets aren't either — only five identified implementations are.
Some affected wallets were created as early as 2018, meaning funds could have sat exposed for years before the flaw surfaced.
Coinspect published a free tool at illbloom.org to check if a wallet address falls in the flagged vulnerable set.
Coinspect has not yet named all five affected wallet apps publicly, citing a staged disclosure process — more names could surface.
Read More →