A new serious threat has been identified in the world of crypto security — a vulnerability codenamed Ill Bloom. The issue is related to insufficient entropy during seed phrase generation, which critically narrows the space of possible combinations and makes private keys vulnerable to brute-force attacks.

Blockchain security experts have already recorded a coordinated withdrawal of funds from 431 vulnerable wallets. The total amount of stolen assets is at least $3.14 million. Of this, approximately $2.57 million was in Bitcoin, $285,778 in Ethereum, $177,225 in Rootstock, $80,970 in Tron, and $23,473 in Polygon. It is important to emphasize: this is only the confirmed minimum damage; actual losses may be significantly higher.

Scope of the problem and affected networks

Researchers analyzed a sample of 2,114 addresses but emphasize that this is only a portion of potentially compromised wallets. The vulnerability affects several major blockchains: Bitcoin, Ethereum, Polygon, Rootstock, Tron, and Solana. The SlowMist team has already joined the investigation, indicating the seriousness of the situation.

According to expert estimates, the weak seed phrase generation mechanism has existed since at least 2018. Users continued to create potentially dangerous wallets until recent weeks. Activity on the studied addresses was recorded from September 2018 to May 2026. Particularly alarming is the fact that even after the warning was published on July 4, approximately $2 million was withdrawn from related addresses — although it is possible that owners moved the funds themselves.

Who is at risk?

The good news: hardware wallets and most popular software solutions are not affected. The main risk group consists of little-known mobile applications. Due to the ongoing threat, technical details of the vulnerability are not yet disclosed. Instead, researchers have released a public tool for checking addresses and notified wallet developers.

My analysis: Ill Bloom is a classic example of how a fundamental error in implementing basic cryptography can lead to catastrophic consequences. The problem has existed for years, and the fact that attackers were able to coordinate the withdrawal of funds from hundreds of wallets points to the systemic nature of the threat. I recommend that all users, especially those using little-known mobile wallets, immediately check their addresses through the provided tool and, if necessary, move funds to more reliable solutions.