Tools Crypto Exploit Tracker exploit-0038
Exploit record
Ill Bloom Wallet Vulnerability
- Loss
- $5M
- Attack vector
- Private Key Compromise
- Chain
- Multichain
- Sector
- Wallet
What happened
A coordinated sweep on 27 May 2026 drained about $3.1 million from 431 wallets whose seed phrases were generated with a weak random-number generator, the 'Ill Bloom' flaw. A further $2.1 million in USDT was stolen later, pushing confirmed losses past $5 million.
Certain older or lesser-known software wallets used an insecure pseudorandom number generator during seed phrase creation, shrinking the keyspace enough for attackers to brute-force recovery phrases and derive private keys. Security firm Coinspect, which disclosed the flaw publicly in early July, traced 2,114 exposed addresses with on-chain activity across Bitcoin, Ethereum, Rootstock, Tron and Polygon, with first-funding dates from 2018 to May 2026; hardware wallets and mainstream software wallets were not affected.
One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026
