TLDR
A broad, low?value exploit has drained hundreds of user wallets across multiple EVM chains; no single wallet provider has been confirmed as the root cause yet, per investigators alerts and coverage of the incident here.
- Losses are roughly $107,000 so far, usually under $2,000 per wallet, and ongoing per a market report.
- Most affected networks include Ethereum, BNB Chain, and Base, by share of drained funds per a recap.
- Funds appear consolidated to a suspicious address flagged by researchers; the entry vector remains unconfirmed per an early brief.
Deep Dive
1. Scale And Amount
Investigators report a cross?chain pattern of small, automated drains targeting many wallets, commonly sub?$2,000 per address, with cumulative losses near $107,000 and rising as the incident continues per a market update and a news recap here. This many small drips approach delays detection and amplifies total impact as new victims are identified.
Even if your balances are modest, systematic drainer activity can still target you, so proactive checks matter.
2. Networks Affected
Coverage clusters the losses primarily on Ethereum (ETH), BNB Chain (BNB), and Base, with Ethereum shouldering the largest share, followed by BNB Chain and Base per a detailed breakdown. Additional EVM networks have seen smaller but similar patterns, reinforcing that this is multi?chain rather than a single?chain compromise per a follow?up.
A shared EVM attack path is plausible, so protection steps should be applied across your EVM wallets, not just on one chain.
3. Root Cause And Indicators
The entry vector is unconfirmed. Some researchers pointed to potential phishing (a spoofed MetaMask email) as a possible delivery path, but this has not been proven, and reports emphasize that the root cause remains unknown per a news brief. Investigators also flagged an aggregation address receiving stolen funds, evidence of a coordinated operation, while stopping short of naming a specific wallet provider as the source issue per an early brief. Some outlets note this wave follows a separate Trust Wallet browser?extension incident from late December, but a direct link to the current drains is not confirmed per a recap.
Treat the cause as unknown for now. Practical defenses include reviewing token approvals, avoiding unfamiliar signing prompts, and moving funds if any suspicious activity appears.
Conclusion
This is a broad, low?value, cross?chain draining campaign with no confirmed single wallet provider at fault. The clearest patterns are the small?per?wallet losses, multi?chain reach, and fund consolidation to a flagged address. Until a root cause is verified, vigilance around approvals and phishing vectors is the most effective immediate defense.
