TLDR
Hundreds of self?custody EVM wallets across Ethereum, BNB Chain, Base, Arbitrum, and Polygon were quietly drained in small amounts, with no single wallet app definitively blamed yet per a media summary.
- Losses clustered on Ethereum, BNB Chain, and Base, while other EVM networks also saw cases per the report above.
- Investigators point to phishing emails spoofing MetaMask and malicious approvals as likely vectors per a CryptoSlate analysis.
- A separate, recent Trust Wallet browser?extension incident affected version 2.68 and led to multimillion losses per a CryptoPotato report.
Deep Dive
1. Chains Affected
The draining campaign hit wallets across multiple EVM networks, with reports citing Ethereum, BNB Chain, Base, Arbitrum, and Polygon among those impacted. Some coverage estimates Ethereum at the largest share of losses, followed by BNB Chain and Base per a Finance Magnates summary.
Investigators described an automated, wide?net operation that siphoned small amounts from many wallets, and flagged a suspected aggregator address 0xAc2e9bFB per a news update.
If you use EVM wallets on the networks above, review token approvals and recent signatures, and be extra cautious with any unfamiliar prompts.
2. Likely Vectors
Though the root cause remains unconfirmed, multiple reports point to phishing emails masquerading as MetaMask upgrade notices and drainer contracts exploiting broad token approvals per a CryptoSlate analysis and a Cointelegraph report.
This pattern fits an automated, permission?abuse approach that moves small sums to evade early detection across chains per the report above.
Avoid signing urgent upgrade or validation requests from unsolicited emails, and routinely revoke unneeded approvals.
3. Trust Wallet Context
Separate from the cross?chain drains, Trust Wallets Chrome extension version 2.68 was compromised in late December, leading to millions in losses before a patch and reimbursement efforts, per a CryptoPotato report.
Some coverage notes overlap in attacker addresses across incidents, but the cross?chain draining pattern is still under investigation per the report above.
If you used the affected extension version, rotate to a fresh wallet on a clean device and validate your extension version history.
Conclusion
The drains were cross?chain and low?value per wallet, suggesting an automated campaign exploiting approvals and phishing rather than a single app failure. Investigations continue, so vigilance on signatures and approvals matters most now.
Confidence: moderate because multiple credible reports agree on scope and vectors, but the precise root cause remains unconfirmed.
