TLDR
An active cross?chain attack drained hundreds of retail EVM wallets today, with most losses on Ethereum (ETH), BNB Chain (BNB), and Base, and a suspicious receiver address 0xAc2e9bFB flagged by researchers Cointelegraph.
- Total losses are around $107,000%%CKPROTECTED2%% so far, typically under $2,000%%CKPROTECTED4%% per wallet The Defiant.
- Impact spans multiple EVM networks, with Ethereum ~51%, BNB Chain ~24%, Base ~8% by theft share Finance Magnates.
- Root cause remains unclear; reports mention a MetaMask?spoof phishing angle and links to recent Trust Wallet extension issues Cointelegraph.
Deep Dive
1. Networks Affected
Wallets on several EVM chains were quietly drained, with Ethereum, BNB Chain, and Base showing the largest shares of stolen funds. Coverage indicates the campaign is broad and retail?focused rather than a single protocol breach Finance Magnates.
- Researchers report distribution roughly Ethereum ~51%, BNB ~24%, Base ~8%, with additional activity across other EVM networks Finance Magnates.
- Social alerts highlight the cross?chain nature and ongoing status of the campaign BanklessTimes post.
If you used multiple EVM networks recently, assume broad exposure and monitor activity across chains, not just on a single network.
2. Attack Pattern and Magnitude
The attacker targets many wallets for small sums, allowing the exploit to spread without immediate detection. Aggregate losses crossed ~$107,000%%CKPROTECTED2%%, with typical per?wallet losses under $2,000%%CKPROTECTED4%% The Defiant.
- Investigators emphasize low?value drains per wallet and growing cumulative impact Cointelegraph.
- Multiple posts corroborate the ongoing nature and retail focus of the drains Twitter roundup.
Small, repeated drains are hard to notice. Regularly review recent approvals and outgoing transfers to catch anomalies early.
3. Investigation Status
Root cause is still unconfirmed. A suspected aggregator address 0xAc2e9bFB has been flagged as collecting stolen funds, with speculation around phishing emails spoofing MetaMask and proximity to recent Trust Wallet extension issues The Block coverage via TradingView and Cointelegraph.
- The flagged receiver address aggregates small inflows from disparate victims The Block coverage via TradingView.
- Reports reference recent Trust Wallet browser?extension problems during the holidays that affected some users The Defiant.
With no confirmed exploit vector, treat unusual signature prompts, legacy approvals, and extension updates as potential risk points and increase caution.
Conclusion
Todays wallet drains appear to be a coordinated, low?value?per?wallet campaign across multiple EVM networks. The key links are broad chain coverage, small but numerous thefts, and a single aggregator address receiving funds. Until investigators confirm the root cause, prudent hygiene is to monitor approvals and recent transactions, and be skeptical of unexpected signing prompts on EVM dApps.
