Incident case file
Sign in to watchUnihax0r — SIGMA Telegram Bot Private Key Compromise
0 views
Estimated loss
Victims identified
Investigation
Facts and investigation
Attacker: 0xF7cFFC27732a5C9c4E2D592F3E33435F8dDb019A
Timeline: On May 11, 2026 around 01:53 UTC (alert time), crypto trader @0xUnihax0r publicly reported that two of his wallets had been drained between approximately 00:37 and 00:56 UTC. Total loss exceeded $200,000, including ~$125K in $POD on Base, ~$21K in $FHE on BSC, plus ETH and various smaller positions. The attacker EOA was identified as 0xF7cFFC27732a5C9c4E2D592F3E33435F8dDb019A, which dust-swept the victim's ETH wallet — a signature of an experienced operator. Both compromised wallets had been generated via the SIGMA Telegram multichain trading bot before being imported into GMGN and Rabby Wallet; wallets not created via SIGMA on the same setup were untouched. GoPlus Security and on-chain analyst @k0braca1 confirmed the compromise as a private key leak (no malicious approvals or phishing signatures). Possible vectors discussed by the victim and analysts include phishing fake CAPTCHA on Telegram, infostealer malware, device compromise, malicious browser extensions, or a fake GMGN workflow — but Unihax0r reported no suspicious Telegram sessions. Recovery prospects are low as the funds entered mixing flows shortly after the drain.
Sources and coverage
- Articlecryptotimes.iohttps://www.cryptotimes.io/2026/05/11/crypto-trader-drained-of-200k-in-telegram-bot-linked-crypto-hack/
- Articlecryptopolitan.comhttps://www.cryptopolitan.com/crypto-trader-loses-200k-telegram-bot/
- Articlecrypto-economy.comhttps://crypto-economy.com/crypto-trader-loses-200k-after-telegram-bot-allegedly-exposes-private-keys/
Victim testimonies
No testimonies yet.
+ Add my testimony → (coming soon)