Blockchain investigator ZachXBT said on Telegram that an attacker is targeting wallets across multiple EVM-based networks. Instead of emptying wallets in large moves, the activity is centered on taking less than $2,000 from each wallet. The sums are relatively small. That makes the campaign harder to spot early, while the combined losses can build quickly.
Matching transfer patterns appear on several EVM networks
On-chain data suggests the activity is not isolated to one chain. Similar transfer patterns have been observed across multiple networks, pointing either to a shared security weakness or a vulnerability on the user side. The exact entry point is still unknown, and there is no public confirmation on whether the spread is happening through applications, contracts, or underlying infrastructure.
ZachXBT also shared a suspicious address with the public: 0xAc2e5153170278e24667a580baEa056ad8Bf9bFB. The wallet is believed to be linked to the attack. Even so, there is still no concrete information on the identity of the attacker, and no confirmed indication of an organized group behind the activity.
Security losses remained elevated in December 2025
The incident follows a heavy month for crypto security breaches. Blockchain security firm PeckShield reported about 26 major attacks in December 2025, with total losses reaching $76 million. That was down 60% from the $194.27 million reported in November, but the broader security risk remained in place.
One of the most notable cases from the previous month involved Trust Wallet. A flaw in a specific version of its browser extension, discovered during the Christmas holiday period, led to losses of around $7 million. The company said it had started a compensation process for affected users.
Trust Wallet extension was temporarily disabled on Chrome
Trust Wallet CEO Eowyn Chen said a technical issue led to the extension being temporarily disabled on the Chrome Web Store. According to Chen, a new update now allows verification codes to be transmitted directly through the extension. For the latest multi-network wallet drain, the public facts remain limited: the attack is active across chains, the transfer pattern is unusually discreet, and the initial attack vector has not been identified.

