Key Takeaways
Blockchain investigator ZachXBT has warned the crypto community about a growing and unexplained wallet-draining threat affecting multiple EVM-compatible blockchains.
The activity, which spans several networks that rely on the Ethereum Virtual Machine (EVM), has already resulted in unauthorized asset losses with funds siphoned in small amounts, typically under $2,000 per wallet, across numerous addresses, raising concerns about a potentially systemic vulnerability.
At the center of the incident is a suspicious Ethereum address that has been consistently receiving funds from unrelated victims:
Suspicious Address:
0xAc2e5153170278e24667a580baEa056ad8Bf9bFB
So far $107K has been drained from them with the theft total still increasing. However, the exact cause of the attacks remains unknown, but early analysis suggests that the exploit may involve permission abuses, malicious signature techniques, or a broader supply-chain compromise affecting wallet infrastructure.
On-chain data indicates a patterned and automated attack, rather than isolated user mistakes. Victims report assets being transferred out without intentional authorization, often shortly after routine interactions such as signing messages or interacting with decentralized applications.
This cross-chain behavior suggests the exploit targets shared EVM wallet mechanics, rather than a flaw in any single blockchain.
EVM wallets are cryptocurrency wallets designed to store, send, receive, and manage digital assets on EVM-compatible blockchains – networks that run on the EVM.
EVM-compatible chains share:
Because of this shared architecture, a single exploit vector can scale rapidly across the entire EVM ecosystem, impacting users on multiple networks simultaneously.
The following scenarios remain theoretical and have not been officially confirmed.
Users may have unknowingly approved malicious smart contracts, granting them unlimited access to tokens. Once permissions are in place, attackers can drain assets using transferFrom() without further interaction.
Typical Indicators
Some wallets allow users to sign off-chain messages that can later be used to authorize on-chain transfers. Deceptive signing prompts may trick users into approving asset movement without realizing it.
Typical Indicators
The most severe possibility is a compromise at the wallet or extension level. In such cases, attackers may gain access to private keys or seed phrases, enabling complete wallet takeover across all EVM chains.
Typical Indicators
The address 0xAc2e5153170278e24667a580baEa056ad8Bf9bFB appears to function as a central collection wallet. Its activity profile shows:
Tracking this address is crucial for understanding the full scope of the attack and identifying related infrastructure.
This incident underscores a persistent challenge in the crypto ecosystem: wallet-level security remains a critical attack surface.
Whether the final explanation involves permission abuse, signature manipulation, or a supply-chain breach, the impact highlights the systemic risks posed by shared EVM infrastructure.
The EVM chains risk refers to unauthorized wallet drains across multiple EVM-compatible blockchains, highlighted by blockchain investigator ZachXBT. The attacks appear coordinated, automated, and cross-chain, with funds flowing to a single suspicious address. No. The exact cause is still unknown. Current theories include token permission abuse, malicious signature exploits, or a supply-chain vulnerability affecting wallet software or browser extensions. EVM-compatible blockchains share the same transaction logic, wallet infrastructure, and permission standards. This means a single exploit vector can be reused across different networks, amplifying the impact. Users should move funds to a new wallet immediately, revoke all token approvals, avoid signing messages, audit wallet extensions, and remain alert for scam follow-ups pretending to offer compensation or support.