There is a serious attack and wallet draining in more than 3800 wallets already affected, which is connected to users who might have been said to have connected their wallet to “lootbot” (a project which they alleged connected to a Vietnamese scammer who has stolen millions of dollars through a presale).
It all started like a joke this afternoon on X when a user complained about his ETH wallet being emptied without any trace of how it happened, until it escalated to other chains and wallets of others.
Anyone who might have their wallet connected to LootBot should check if their tokens are safe and move them out if anything is left. I don’t buy that revoke advice; take action first and then think of anything else later, according to the tracker and who reported it, they said most chain under the eth layer have not yet been swept by the hacker so their might still be chance for some people to save money.
🚨 If you ever used @lootbot_ai , move your funds right now.
Someone has the private keys to wallets generated by LootBot and has been
draining them since 13:18 UTC on September 7. 252 ETH (~$620k) taken so far
from 3,825+ wallets across 9 chains. It is still running as I post this.
0x4e5df8422271690327c0348845b639196aB0081E
THIS IS A PRIVATE KEY COMPROMISE, NOT A PHISHING ATTACK.
1,967 wallets were swept on two or more chains. Five were swept on all seven.
Same address, different chains, minutes apart.
No approval, no signature, no malicious contract can do that—none of them.
can even move native ETH, let alone on seven chains at once. Only possession
of the key can. You didn't click anything. There was nothing to click.
https://x.com/somaxbt/status/2097297279921340482