YFarmX

Tools Crypto Exploit Tracker exploit-0038

Exploit record

Ill Bloom Wallet Vulnerability

Loss
$5M
Attack vector
Private Key Compromise
Chain
Multichain
Sector
Wallet

What happened

A coordinated sweep on 27 May 2026 drained about $3.1 million from 431 wallets whose seed phrases were generated with a weak random-number generator, the 'Ill Bloom' flaw. A further $2.1 million in USDT was stolen later, pushing confirmed losses past $5 million.

Certain older or lesser-known software wallets used an insecure pseudorandom number generator during seed phrase creation, shrinking the keyspace enough for attackers to brute-force recovery phrases and derive private keys. Security firm Coinspect, which disclosed the flaw publicly in early July, traced 2,114 exposed addresses with on-chain activity across Bitcoin, Ethereum, Rootstock, Tron and Polygon, with first-funding dates from 2018 to May 2026; hardware wallets and mainstream software wallets were not affected.

One record from the Crypto Exploit Tracker, maintained by the Security Desk. Data: CSV · JSON ·RSS · CC BY 4.0 with attribution to YFarmX.Tracker updated · 15 September 2026