A massive security issue, dubbed Ill Bloom, is jeopardizing the funds of users across thousands of crypto wallets. Blockchain security experts have already recorded over $5 million in confirmed losses, and this is just the tip of the iceberg.
Root of the Problem: Weak Seed Phrase Entropy
At the core of the vulnerability lies a critical flaw in the seed phrase generation mechanism. Some wallets, primarily obscure mobile applications, use weak entropy, which catastrophically narrows the space of possible combinations. This makes private keys vulnerable to brute-force attacks. Using computational power, attackers can recover the keys and gain full access to victims' assets. The issue affects the multi-chain environment, including Bitcoin, Ethereum, Polygon, Rootstock, Tron, and Solana.
Timeline of Attacks and Scale of Damage
The first coordinated fund withdrawal was recorded on May 27. At that time, approximately $3.14 million was moved from 431 vulnerable wallets. The lion's share of losses fell on Bitcoin — $2.57 million. Ethereum lost $285,778, Rootstock — $177,225, Tron — $80,970, and Polygon — $23,473. However, this was only the first wave. Already on July 4, after the public disclosure of the vulnerability, about another $2 million was withdrawn from related addresses. However, it is possible that some of these funds were moved by the owners themselves for security reasons.
An analysis of 2,114 addresses from the sample showed that the vulnerable mechanism has existed since at least 2018, and users continued to create potentially dangerous wallets until recent weeks. This means the list of victims could be significantly broader, and the investigation, which the SlowMist team has joined, is ongoing.
Who is at Risk and What to Do?
An important point: hardware wallets and most popular software solutions (e.g., MetaMask, Trust Wallet) are not affected by this vulnerability. The main risk group consists of obscure or outdated mobile applications where developers neglected security standards during key generation.
Due to the ongoing threat to active wallets, researchers have not yet disclosed all technical details of the attack. Instead, they have released a public tool for checking addresses for susceptibility to the Ill Bloom vulnerability and notified the developers of the problematic wallets.
Expert Opinion: This situation is yet another stark reminder that self-custody requires not just storing keys, but understanding how those keys were generated. Blind trust in any "convenient" mobile wallet can lead to a total loss of funds. Users are strongly advised to check their historical addresses through security tools and, at the slightest doubt, immediately migrate to trusted hardware or open-source software solutions.