The world of cryptocurrencies has faced a new serious threat. A massive vulnerability, dubbed Ill Bloom, has affected thousands of crypto wallets, and in my estimation, the actual damage could be significantly higher than the already recorded $5 million. The problem lies in a fundamental flaw — weak entropy during seed phrase generation, making private keys vulnerable to brute-force attacks.

How the attack works and who is at risk

Attackers use brute force to recover seed phrases due to insufficient randomness during their creation. Confirmed breach cases have affected wallets on Bitcoin, Ethereum, Polygon, Rootstock, Tron, and Solana networks. Analysis of a sample of 2,114 addresses shows this is just the tip of the iceberg. Security researchers, including the SlowMist team, have already joined the investigation.

On May 27, a coordinated attack was recorded: approximately $3.14 million was withdrawn from 431 vulnerable wallets. The lion's share — $2.57 million — came from Bitcoin. The remaining losses were distributed as follows: Ethereum — $285,778, Rootstock — $177,225, Tron — $80,970, and Polygon — $23,473. However, this is only the "confirmed minimum." After a warning was published on July 4, about another $2 million was withdrawn from related addresses, although it is possible that owners moved the funds themselves.

Root of the problem and timeline

The vulnerable seed phrase generation mechanism has existed since at least 2018. Users continued to create potentially dangerous wallets until recent weeks. Activity of addresses in the sample dates from September 2018 to May 2026. It is important to emphasize: the problem does not affect hardware wallets or most popular software solutions. The main risk group is little-known mobile applications that likely used low-quality random number generators.

What to do and my assessment

Due to the ongoing threat, technical details are not yet disclosed. However, a tool for checking addresses has already been released, and wallet developers have been notified. I recommend that anyone who used little-known mobile wallets before 2026 immediately check their addresses and move funds if necessary.

My comment: The Ill Bloom vulnerability is yet another reminder that cryptocurrency security starts with choosing the right tools. Saving on wallet quality can cost you all your assets. Weak entropy is not a bug but developer negligence, and the market should severely punish such projects.