The Ill Bloom vulnerability, discovered by blockchain security firm Coinspect, has been linked to over $5 million in cryptocurrency theft. Affected wallet apps generated BIP-39 recovery phrases using weak, predictable random number generators instead of cryptographically secure entropy. This makes recovery phrases mathematically guessable, exposing funds across Bitcoin, Ethereum, and more than a dozen other blockchains. A coordinated sweep on May 27 drained $3.1 million from 431 wallets in a single day. Hardware wallets are unaffected; risk concentrates in older or obscure mobile apps and browser extensions, some dating to 2018. Users can check exposure at illbloom.org. If an address matches, the recovery phrase must be considered fully compromised — patching the app does not fix an already-generated phrase. The only remedy is generating a completely new wallet and moving funds immediately. Auditors are advised to statistically test generated phrases rather than trusting the entropy library used.