TLDR Hundreds of crypto wallets across EVM chains have been drained in an ongoing attack. Each wallet was targeted for relatively small amounts with most victimsTLDR Hundreds of crypto wallets across EVM chains have been drained in an ongoing attack. Each wallet was targeted for relatively small amounts with most victims

Crypto Wallets Compromised Across Chains, ZachXBT Tracks Attacker

2026/01/02 15:56
3 min read
For feedback or concerns regarding this content, please contact us at crypto.news@mexc.com

TLDR

  • Hundreds of crypto wallets across EVM chains have been drained in an ongoing attack.
  • Each wallet was targeted for relatively small amounts with most victims losing under $2,000.
  • The total amount stolen has reached approximately $107,000 and continues to increase.
  • ZachXBT has identified a suspicious address connected to the wallet-draining activity.
  • The method used by the attacker to access the wallets is still unknown.

Hundreds of crypto wallets have been drained across multiple EVM-compatible chains, with the attack still ongoing, according to on-chain investigator ZachXBT, who reported the losses in his Telegram channel, confirming a total of $107,000 stolen so far, though this figure is expected to rise.

Attacker Targets Low-Balance Wallets Across EVM Chains

The attacker continues to drain wallets across Ethereum-compatible chains, focusing on low-value accounts with funds under $2,000 each. ZachXBT shared that although individual losses are small, the cumulative impact grows as more wallets are compromised.

The investigator flagged the suspicious address 0xAc2e5153170278e24667a580baEa056ad8Bf9bFB as linked to the thefts. No details have emerged about how the attacker gains access to the wallets, leaving the vulnerability unresolved.

The method of compromise remains unknown, creating concerns of continued exploitation across affected chains. As of now, the attacker remains unidentified, and victims keep reporting unauthorized withdrawals from their wallets.

Trust Wallet Breach Tied to Extension Update Exploit

During the December holiday period, Trust Wallet confirmed a separate breach tied to its browser extension version 2.68. In a post-mortem, the company revealed that exposed GitHub secrets allowed the attacker to bypass standard release procedures.

The attacker registered “metrics-trustwallet[.]com” and deployed a trojanized extension version with backdoor capabilities. This malware harvested wallet mnemonic phrases and transmitted them to a malicious server, “api.metrics-trustwallet[.]com”.

Around one million users were prompted to update to version 2.69 after the compromised version appeared on the Chrome Store. Trust Wallet CEO Eowyn Chen explained that a platform issue during the update caused the extension to become temporarily unavailable.

The new update added a verification feature to help reimbursement claimants prove wallet ownership. Trust Wallet confirmed around $7 million in losses from the attack and began compensating affected users shortly after.

Crypto Exploits Surge During December, FBI Issues Scam Warning

Blockchain security firm PeckShield reported 26 crypto-related exploits in December, resulting in about $76 million in stolen funds. While the number is lower than November’s $194.27 million, attacks continue to occur across various platforms.

Researchers said a new malware version called Shai-Hulud 3.0 featured improvements in obfuscation and compatibility. This version aimed to prolong campaign activity without introducing new techniques, according to Upwind’s Guy Gilad and Moshe Hassan.

Nansen believes attackers are routing stolen assets through Tornado Cash, Railgun, THORChain, and TRON OTC venues. These services may obscure the asset flow, complicating traceability efforts for investigators and victims.

The FBI warned Americans about rising phishing and non-delivery scams during the holidays, linked to $785 million in annual losses. Credit card fraud added another $199 million, increasing concerns around seasonal cybercrime targeting personal and financial data.

Chainalysis and TRM Labs estimated crypto thefts reached $2.7 billion last year, the highest yearly total recorded. The largest attack targeted Dubai-based exchange Bybit, with about $1.4 billion stolen in a single breach.

North Korean state-linked groups reportedly stole over $2 billion in crypto during the year.
Since 2017, these actors have accumulated around $6 billion, funding programs despite international sanctions.

The post Crypto Wallets Compromised Across Chains, ZachXBT Tracks Attacker appeared first on CoinCentral.

Market Opportunity
Ambire Wallet Logo
Ambire Wallet Price(WALLET)
$0.00914
$0.00914$0.00914
+4.10%
USD
Ambire Wallet (WALLET) Live Price Chart
Disclaimer: The articles reposted on this site are sourced from public platforms and are provided for informational purposes only. They do not necessarily reflect the views of MEXC. All rights remain with the original authors. If you believe any content infringes on third-party rights, please contact crypto.news@mexc.com for removal. MEXC makes no guarantees regarding the accuracy, completeness, or timeliness of the content and is not responsible for any actions taken based on the information provided. The content does not constitute financial, legal, or other professional advice, nor should it be considered a recommendation or endorsement by MEXC.

You May Also Like

Red state lawmaker warns something ominous hiding behind Supreme Court's 'five alarm fire'

Red state lawmaker warns something ominous hiding behind Supreme Court's 'five alarm fire'

A former lawmaker from a red state warned that something ominous is hiding behind the latest "five-alarm fire" from the Supreme Court, according to a new report
Share
Rawstory2026/05/15 08:07
One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight

The post One Of Frank Sinatra’s Most Famous Albums Is Back In The Spotlight appeared on BitcoinEthereumNews.com. Frank Sinatra’s The World We Knew returns to the Jazz Albums and Traditional Jazz Albums charts, showing continued demand for his timeless music. Frank Sinatra performs on his TV special Frank Sinatra: A Man and his Music Bettmann Archive These days on the Billboard charts, Frank Sinatra’s music can always be found on the jazz-specific rankings. While the art he created when he was still working was pop at the time, and later classified as traditional pop, there is no such list for the latter format in America, and so his throwback projects and cuts appear on jazz lists instead. It’s on those charts where Sinatra rebounds this week, and one of his popular projects returns not to one, but two tallies at the same time, helping him increase the total amount of real estate he owns at the moment. Frank Sinatra’s The World We Knew Returns Sinatra’s The World We Knew is a top performer again, if only on the jazz lists. That set rebounds to No. 15 on the Traditional Jazz Albums chart and comes in at No. 20 on the all-encompassing Jazz Albums ranking after not appearing on either roster just last frame. The World We Knew’s All-Time Highs The World We Knew returns close to its all-time peak on both of those rosters. Sinatra’s classic has peaked at No. 11 on the Traditional Jazz Albums chart, just missing out on becoming another top 10 for the crooner. The set climbed all the way to No. 15 on the Jazz Albums tally and has now spent just under two months on the rosters. Frank Sinatra’s Album With Classic Hits Sinatra released The World We Knew in the summer of 1967. The title track, which on the album is actually known as “The World We Knew (Over and…
Share
BitcoinEthereumNews2025/09/18 00:02
Data focus shifts to payrolls – Societe Generale

Data focus shifts to payrolls – Societe Generale

The post Data focus shifts to payrolls – Societe Generale appeared on BitcoinEthereumNews.com. Societe Generale analysts note a quiet data calendar ahead of key
Share
BitcoinEthereumNews2026/04/02 17:52

KAIO Global Debut

KAIO Global DebutKAIO Global Debut

Enjoy 0-fee KAIO trading and tap into the RWA boom