UPDATE 2 — Expanded GitHub / Telegram / HFT Fund-Flow OSINT EvidenceThis thread has been updated with a larger public OSINT archive and YouTube evidence series covering the reported
Soldrift / Hodlwarden / @devbeast5775 GitHub–Telegram identity cluster.
The concern is not only a failed trading-bot deal or a simple Telegram scam.
The stronger risk model is a possible
long-term GitHub trust-trap and financial-asset harvesting framework.
The reported pattern includes:
- 80+ GitHub repositories and forked / MVP-level source-code projects used to build developer credibility.
- 1k+ GitHub visibility / potential customer reach.
- Professional-looking Solana / Pump.fun / HFT / arbitrage / trading-bot branding.
- Telegram contact paths leading potential buyers into private tool sales.
- Possible exposure to malicious code, backdoors, malware, .env leakage, private-key leakage, RPC / GRPC token exposure, exchange API exposure, VPS/root-access abuse, and wallet-drain risk.
- Post-incident wallet-flow and HFT / arbitrage / exchange-linked fund-flow leads requiring AML, compliance, and law-enforcement review.
Important clarification:
This is not a final legal conclusion against any exchange, employee, or third party.
Any KuCoin-linked, HFT-linked, API-linked, or exchange-linked flow should be treated as an
OSINT / AML review lead requiring independent verification by compliance teams, blockchain investigators, and law-enforcement partners.
The visible account may be only the front-facing layer. The broader concern is a possible organized cyber-enabled financial-harvesting structure using GitHub credibility, Telegram support paths, private Solana tools, wallet access, and exchange-linked fund-flow routes.
Updated public OSINT archive:https://soldrift-devbeast5775-warning.github.io/solana-scam-osint-report/Secondary mirror archive:https://soldrift-devbeast5775-warning.github.io/soldrift-devbeast5775-scam-warning/YouTube OSINT evidence videos:Search keywords:Soldrift scam warning, Hodlwarden scam warning, devbeast5775 Telegram, Soldrift GitHub, Hodlwarden GitHub, GitHub Telegram scam, Solana bot scam, Pump.fun bundler scam, Solana wallet drain, backdoored trading bot, private key exposure, .env exposure, GRPC_TOKEN exposure, HFT fund-flow OSINT, KuCoin-linked wallet lead, Web3 OSINT evidence.
Safety warning:Never run unaudited Solana bots, Pump.fun bundlers, snipers, HFT tools, arbitrage bots, volume bots, wallet warmers, or wallet-management tools on funded servers.
Never expose private keys, seed phrases, .env files, RPC tokens, GRPC_TOKEN values, exchange API keys, wallet exports, local PC access, SSH access, or VPS/root access to unknown developers.
This material is provided for public safety, evidence preservation, platform-safety review, exchange compliance review, and cybercrime-reporting support.
No harassment, doxxing, threats, or retaliation is intended. All claims should be treated as OSINT leads requiring verification.
SCAM ALERT: Soldrift / @devbeast5775
Solana Wallet Drain, Backdoored Trading Bot, and KuCoin-Linked HFT / Arbitrage Flow
This is a public safety warning for Solana, Web3, HFT, MEV, arbitrage-bot, and crypto trading-bot users.
The developer using the name
Soldrift, associated with Telegram
@devbeast5775 and GitHub
soldrift, is linked to a reported Solana trading-bot scam involving suspicious wallet-drain behavior, VPS/server-access abuse, and fund flows requiring urgent review.
This report is based on victim experience, wallet activity, transaction evidence, suspicious fund movement, and technical risk indicators.
This post does
not encourage harassment, threats, doxxing, or personal attacks. Its purpose is to help users, exchanges, blockchain explorers, AML teams, and security researchers independently review the evidence and prevent further losses.
WARNINGDo not run unverified software from this developer.
Do not provide VPS root access, SSH access, deployment access, private keys, seed phrases, RPC keys, exchange API keys, wallet files, or .env files.
Any developer who requires unnecessary access to your server, wallet environment, private credentials, RPC keys, or exchange API keys should be treated as high risk.
1. REPORTED SCAM PATTERNThe actor using the name
Soldrift promotes custom Solana trading tools, including:
- Solana bundler tools
- HFT trading bots
- MEV / Jito backrun systems
- Arbitrage-bot infrastructure
- Custom VPS-based trading dashboards
The reported pattern appears to involve the following:
- The victim is offered a custom Solana HFT / MEV / arbitrage / bundler bot.
- The victim is encouraged to run private code, repositories, or server-side software.
- The victim may be asked to provide VPS, SSH, root, or deployment access under the excuse of performance optimization.
- The software environment may expose sensitive files such as private keys, RPC tokens, API keys, wallet files, and .env files.
- Victim-linked funds then appear to connect with active Solana wallet flows requiring exchange, explorer, and AML review.
2. WHY THIS CASE IS HIGH RISKThis is not a normal failed development job or a simple software dispute.
The concern is not only that one developer allegedly failed to deliver a tool. The concern is that the reported pattern involves trading-bot software, VPS / SSH / root access requests, possible exposure of private keys and environment files, suspicious wallet movement after the victim interaction, and a wallet cluster that appears to interact with larger HFT / arbitrage-style flows.
This does
not claim that KuCoin itself was hacked.
The concern is that victim-linked funds may have entered or interacted with a larger KuCoin-linked HFT / arbitrage / API-related flow. KuCoin compliance and AML teams should urgently review any related accounts, API keys, trading entities, deposits, withdrawals, order history, settlement activity, and withdrawal routes.
3. POSSIBLE LARGER OPERATION BEHIND THE FRONT-END ACTORThe scale and behavior of the HFT / arbitrage flow appear inconsistent with a small independent scammer acting alone.
This raises serious questions about whether
Soldrift is only the front-end recruiter, malicious developer, VPS-access operator, or credential-exfiltration point, while the actual liquidity operation may be controlled by a larger entity.
Possible structures requiring investigation include:
- External customer trading account
- API-based trading entity
- Third-party liquidity operator
- Market-making account
- Affiliate or partner account
- Employee-linked or insider-related account
- Organized wallet-drain and fund-routing operation
This is not a public accusation that any exchange employee or insider is involved.
However, the possibility should be investigated by KuCoin and relevant compliance teams because the victim-linked flow appears to reach beyond a simple isolated scam wallet.
Key concern:The victim funds do not appear to be simply sitting in an isolated scam wallet. They appear to be connected to an active Solana HFT / arbitrage operating flow with KuCoin-linked settlement or API-related activity.
4. ADDRESSES OF INTEREST FOR SECURITY REVIEWThe following Solana addresses are listed as addresses of interest based on observed or reported transaction flow.
They are provided for independent review, monitoring, and risk analysis by affected users, exchanges, blockchain explorers, AML teams, and security researchers.
Primary Address of Interest:EfwJn8cXCYhcGrsavxWSDbUFHPrCK9gvdCr6AVywFBPg
Solscan:
https://solscan.io/account/EfwJn8cXCYhcGrsavxWSDbUFHPrCK9gvdCr6AVywFBPgAdditional Addresses of Interest:GLoyGTsJiS3iDAV66NNsiRWkm1VU6H6UjaywmNdaxs4L
A8Scw8Yt85anFYzFjBiwcwZjsoDZSdicyNKpiFrCsZQm
E8RcJDs3SaBP2udWy6bD7576zJ3WitfbVh16vgeqoAgi
5cZWa1KZQnMPeXTHPRF8JSEPMhzRaHPeAoG1rPtiHGc
Solscan:
GLoyGTsJiS3iDAV66NNsiRWkm1VU6H6UjaywmNdaxs4LA8Scw8Yt85anFYzFjBiwcwZjsoDZSdicyNKpiFrCsZQmE8RcJDs3SaBP2udWy6bD7576zJ3WitfbVh16vgeqoAgi5cZWa1KZQnMPeXTHPRF8JSEPMhzRaHPeAoG1rPtiHGcThese addresses should be reviewed for possible links to suspicious fund movement, victim-reported losses, exchange deposit patterns, API-linked trading activity, arbitrage operations, or operational infrastructure.
5. TRANSACTION HASHES FOR INDEPENDENT REVIEWTX 1 — Initial Suspicious Flow33Jc35XrQwhFAZN93Gcsyi2a3Zb9ujgxNeSPcD2xUMzcQ3b18kqCUHHhUdzzAY5dNDgQHSfqFM7RshX7A4KvCnKW
Solscan:
TX 1TX 2 — Inter-Wallet Flow2Zm267N9eDAbvLX3WooJYmLc5YCkNKyBitV6CRn3HBApxEFHMc7tBuLtHXEcAjmjDhsDz3aBfEefK7HdKPuT8um7
Solscan:
TX 2TX 3 — Exchange / API-Linked Flow Requiring Review3beyL4Um4Wt9duWbCQrStySMdLF33k5QAP1h49VQkE6PTJaHtp36G3JGnTjmVDZ7RcY4z1v8C7ngnNnvHK9wkoqV
Solscan:
TX 3These transactions should be independently examined before any labeling, freezing, enforcement, or public attribution action is taken.
6. REQUESTED ACTIONKuCoin and relevant security teams should urgently preserve records, review related accounts, review API activity, investigate possible trading-entity connections, and apply temporary withdrawal-risk controls if supported by evidence.
7. PUBLIC OSINT REPORTFull public report:
Soldrift / devbeast5775 Public Safety NoticeFINAL WARNINGIf you are contacted by Telegram
@devbeast5775 or GitHub
soldrift, proceed with extreme caution.
Do not install software.
Do not provide server access.
Do not expose wallet credentials.
Do not share RPC keys or exchange API keys.
Do not run private trading-bot repositories without a full security audit.
Stay safe. Verify everything. Never expose your keys.