ZachXBT Warns of Silent Wallet Drains Across Multiple EVM Networks

Source: CryptoTale Original Title: ZachXBT Warnings Silent Wallet Drains Across EVM Chains Original Link: https://cryptotale.org/zachxbt-warnings-silent-wallet-drains-across-evm-chains/

  • ZachXBT traced wallet drains across EVM networks, with losses staying small per address.
  • A single Ethereum address keeps receiving funds, which signals activity across chains.
  • Analysts study approvals, signatures, and extensions, yet the exploit method is unknown.

Blockchain investigator ZachXBT has warned the crypto community about an unexplained wallet-draining activity affecting multiple EVM-compatible blockchains. The activity has already led to more than $107,000 in losses. Individual wallets typically lose less than $2,000. Still, the number of affected addresses continues to grow. The source of the drains remains unidentified.

On-chain tracking has linked the stolen funds to a single Ethereum address that repeatedly receives transfers from unrelated victims. The address, 0xAc2e5153170278e24667a580baEa056ad8Bf9bFB, has appeared across multiple transactions tied to the activity. Funds continue to move into the address, indicating the draining has not stopped.

Rather than large, isolated thefts, the activity relies on small withdrawals spread across many wallets. This pattern appears to delay detection. As a result, losses build quietly while victims remain unaware until balances drop.

Cross-Chain Pattern Draws Attention

Reports show the activity spans several EVM-based networks. Affected wallets appear on Ethereum, BNB Chain, Base, Arbitrum, Polygon, Optimism, and other EVM ecosystems. The breadth of networks involved has raised questions about a shared point of failure.

Because EVM chains rely on similar wallet standards and signing flows, investigators suspect the exploit does not target one protocol. Instead, it may involve common wallet logic or permission handling. Many wallets share similar approval processes and user prompts.

Despite growing data, no confirmed cause has emerged. Analysts continue to examine token approval abuse, deceptive signature requests, and possible supply chain issues affecting wallet software. Some research also focuses on browser extensions. None of these theories has been confirmed so far.

December Exploits Provide Wider Context

The wallet drains follow a month marked by several major crypto security incidents. Security researchers reported 26 significant exploits in December. A small number of cases accounted for most of the losses. The largest involved a single user who lost $50 million in an address poisoning scam.

In address poisoning attacks, threat actors send small transactions from addresses that closely resemble legitimate ones. Victims later copy the wrong address from transaction history during a transfer. Funds then move irreversibly to the attacker. These scams rely on visual similarity rather than technical flaws.

Security teams also documented another December incident involving a private key leak tied to a multi-signature wallet. That breach resulted in losses of about $27.3 million. The case showed that even wallets requiring multiple approvals remain vulnerable when key security fails.

Browser Wallets Remain Exposed

Browser-based wallets attract the most attackers, mainly because they are continuously connected to the Internet. One Christmas Day incident drained approximately $7 million from a browser extension wallet. Another December incident targeted a blockchain protocol with an approximate loss of $3.9 million.

The occurrences of these incidents are a clear indication of the risks that are still present in online wallet environments. Most security researchers recommend hardware wallets, which maintain private keys offline, as the safest option for long-term storage.

Regarding the current EVM wallet draining, security teams have suggested that users revoke unused approvals, check connected applications, and reduce signing activity. Many of them also recommend transferring assets to new wallets with new seed phrases while monitoring is ongoing.

ETH4.25%
BNB2.27%
ARB3.7%
OP4.06%
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 6
  • Repost
  • Share
Comment
0/400
WalletDivorcervip
· 3h ago
Is there yet another silent wallet vulnerability? I'm honestly speechless, there's a new trick every day.
View OriginalReply0
SoliditySurvivorvip
· 3h ago
Another silent drain? ZachXBT really can't hold back anymore
View OriginalReply0
WagmiAnonvip
· 3h ago
Coming back with silent drain again? You should add a memo reminder for this trick.
View OriginalReply0
AllInAlicevip
· 3h ago
NGL, another silent account theft. Is this time cross-chain? They should have reviewed the contract earlier...
View OriginalReply0
SingleForYearsvip
· 3h ago
Bro, are you warning again that the wallet is being quietly exploited? This cross-EVM trick is really hard to defend against.
View OriginalReply0
StablecoinGuardianvip
· 3h ago
Silent vampirism? Better keep a close eye on your wallet...
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)