Offizielles MASTR Logo MASTR
Menü
Beitrag lesen

Onchain-Untersuchungen

Dormant Ethereum wallets: the April 2026 drain trail

A wallet labelled by Etherscan as Fake_Phishing2831105 has been receiving funds from many addresses and rapidly moving them through swaps and cross chain infrastructure.

Original auf X ↗

Original publication · 30 Apr 2026. Figures, claims and opinions reflect the original publication date.

Die Originalbeiträge sind auf Englisch. Die Navigation ist in sieben Sprachen verfügbar.

01

Original auf X ↗

Ethereum Dormant Wallet Drain, April 30, 2026

A wallet labelled by Etherscan as Fake_Phishing2831105 has been receiving funds from many addresses and rapidly moving them through swaps and cross chain infrastructure.

The address is:

0xA707034429c8E4E01df056C0CbCf478F0FBeFAd7

Etherscan currently marks it as Phish / Hack and warns that reports link the address to a phishing scam.

The address shows 591 transactions, a remaining ETH balance of only about 0.0016 ETH, and a major outgoing move of 324.741 ETH into the THORChain Router v4.1.1 on April 30, 2026.

That single transaction alone was worth about $733,000 at the time shown by Etherscan.

The important part is the pattern.

This does not currently look like a normal smart contract exploit.

It does not look like the usual approval drain where victims recently connected to a malicious site and signed token permissions.

The visible pattern is simpler: ETH is being moved out of many wallets, aggregated into one labelled malicious address, then swapped or bridged out quickly.

Etherscan shows direct incoming transfers, smaller outgoing transfers, swaps through routers such as Magpie, and the large THORChain deposit.

That points to one likely explanation: compromised private keys or seed phrases.

If the attacker can sign directly from the victim wallet, no new approval is needed.
No fresh wallet connection is needed.
No warning popup is needed.
The attacker already has the key, signs the transaction, drains the ETH, aggregates the funds, and moves them out.

The community is describing many of the affected wallets as old or dormant Ethereum wallets, some reportedly inactive for years.

That part still needs careful verification wallet by wallet, but the broader risk model is clear: this is probably not a new Ethereum protocol bug.

It looks much more like an old key compromise surfacing at scale, possibly from leaked seed phrases, old wallet software, weak key generation, abandoned backups, breached databases, or compromised machines from years ago.

The laundering path is also visible.

The drainer collected funds, made smaller transfers, interacted with swap infrastructure, and then pushed 324.741 ETH through THORChain. The THORChain transaction succeeded, and the transaction memo shows an outbound Bitcoin destination, meaning the ETH was not simply parked. It was actively moved cross chain.

This matters because old wallets are often treated as harmless.
People forget them. They leave small ETH balances, old airdrops, NFTs, wrapped assets, LP tokens, or historical holdings sitting there for years.

But an old wallet is not safe just because it has been quiet. If the private key was leaked years ago, the attacker can wait forever and drain it whenever it becomes worthwhile.

Dear follower:

Check every old Ethereum address you have ever used. Not just your main wallet. Not just wallets with visible ETH. Check the dusty ones too.

If anything valuable remains in an old wallet, move it to a brand new wallet generated on a secure hardware device.

Do not reuse old seed phrases.
Do not migrate funds into another wallet derived from the same old seed.
Treat any wallet from an old machine, old browser extension, old cloud backup, or old mnemonic storage habit as potentially compromised.

At this stage, there is no confirmed public evidence that Ethereum itself was exploited.

The chain is doing exactly what it is designed to do: accepting valid signatures. The problem is that someone appears to have obtained the keys.

We will see. I can't proof it yet.

But remember:
On chain, there is no customer support, no password reset, no reversal, and no mercy.

If the key is gone, the wallet is gone.

Attachment to the original X post
Attachment to the original X post Bild in voller Grösse öffnen ↗
Attachment to the original X post
Attachment to the original X post Bild in voller Grösse öffnen ↗
Attachment to the original X post
Attachment to the original X post Bild in voller Grösse öffnen ↗
Attachment to the original X post
Attachment to the original X post Bild in voller Grösse öffnen ↗

Quellen und Originalbeiträge

MASTR

Unabhängige Recherche unterstützen

Die Untersuchungen, Originalbelege und Anleitungen hier sind frei zugänglich. Freiwillige Spenden finanzieren die Recherche mit und helfen, die MASTR-Tools weiterhin anzubieten.

Wallet öffnen