On-chain investigator ZachXBT says a coordinated exploit targeting EVM wallets is still active, with hundreds of wallet addresses already affected across multiple blockchains. The attackers appear to be focusing on wallets with relatively small balances, often holding less than $2,000 in crypto. Individual losses have generally been limited. The total keeps climbing.
At the time of publication, confirmed stolen funds had exceeded $107,000. The root cause of the attack has not been identified yet. ZachXBT warned that the situation could become more severe if the issue remains unresolved.
Ethereum, BNB Chain and Base account for most losses
ZachXBT also shared public keys tied to addresses involved in the exploit. On-chain data shows the stolen funds were concentrated on several major networks, led by Ethereum at 51%, followed by BNB Chain at 24% and Base at 8%. The rest was spread across other EVM-compatible chains.
The pattern points to a cross-chain wallet-draining campaign rather than an isolated incident on a single network. By targeting lower-balance wallets, attackers may be reducing visibility while continuing to build aggregate losses.
Nansen connects the drain pattern to an earlier Trust Wallet case
Analysis from Nansen’s AI linked the recent wallet drains to an earlier incident involving the Trust Wallet browser extension, a breach that resulted in more than $7 million in stolen user funds.
That Trust Wallet incident reportedly began on December 25, 2025 and involved seed phrase manipulation. Investigators said the vulnerability was tied to deliberate actions associated with an internal compromise affecting Chrome extension version 2.68. The issue has since been fixed, but reports indicate some users may still be affected. ZachXBT repeated earlier warnings about the Trust Wallet exploit, and multiple users have confirmed that their funds were stolen during that episode.
Recent crypto security incidents keep piling up
The report also points to a broader rise in hacks and suspicious activity across crypto platforms in recent weeks. As part of remediation tied to a $3.9 million exploit in late December 2025, the Flow Foundation flagged unusual exchange activity involving a single account that moved a large volume of FLOW tokens to an exchange, converted part of the funds to Bitcoin, and withdrew millions within hours.
In a separate case, Unleash Protocol confirmed a breach on December 30 that led to about $4 million in stolen user funds after an attacker gained administrative control of its multisig wallet and approved unauthorized changes.
ZachXBT has also been involved in several other prominent investigations. The report notes that on December 10, he tracked 3,670 ETH, worth about $11.19 million at the time, moving into a wallet linked to Danny Khan shortly after Khan’s arrest in Dubai over alleged cybercrime-related offenses.

