Logo Oficial MASTR MASTR
Menú
Leer la publicación

Phishing, ataques y privacidad

GMGN wallet-draining reports: the October 2025 account

Between October 25 and 28, 2025, hundreds of users who connected their wallets to a major Solana and BNB Smart Chain trading and analytics platform, reported their funds disappearing in real time.

Original en X ↗

Las publicaciones originales están en inglés. La navegación está disponible en siete idiomas.

01

Original en X ↗

The #GMGN Wallet Draining Incident, Full Breakdown here.

Between October 25 and 28, 2025, hundreds of users who connected their wallets to https://t.co/8Hm7fNwp53, a major Solana and BNB Smart Chain trading and analytics platform, reported their funds disappearing in real time.

Screenshots, Solscan links, and BscScan transactions flooded X.

Losses ranged from $20,000 to more than $300,000 per wallet.

Despite the chaos, #GMGN itself was never hacked.

What actually happened was probably a coordinated MEV (Miner Extractable Value) exploitation wave executed by automated trading bots. These bots front-ran legitimate user trades through GMGN’s transaction API and forced connected wallets to purchase honeypot tokens that trapped funds permanently.

🔺 Timeline of Events

October 27, early morning:
First victims appear on X. Wallets show a sudden sequence of sells followed by automatic buys into honeypots. Only wallets connected to GMGN were affected.

October 27, evening:
GMGN posts an official statement through @gmgnai:

> “GMGN is safe. There are no security issues. Please avoid false rumors and phishing links.”

October 27, late night:
Co-founder Haze (@haze_gmgn) acknowledges the incident and promises:

> “If GMGN is even one percent responsible, we will provide one hundred percent compensation.”

October 28, morning:
GMGN confirms the issue was external MEV activity, not a hack.

> “Seven hundred twenty-nine affected transactions were reimbursed automatically. No user action required.”

Independent crypto outlets later verified that refunds were completed within forty-eight hours.

🔺 How the Exploit Worked

The attackers did not steal seed phrases or private keys. Instead, they exploited the live wallet connection used for trading on GMGN.

Step by step, the attack unfolded as follows:

1. Bots monitored GMGN’s public transaction queue through its API.

2. They front-ran trades by executing malicious versions milliseconds before legitimate ones.

3. The connected wallet, still authorized, sold its holdings and automatically bought honeypot tokens created by the attackers.

4. The purchased honeypots locked the funds, making them unrecoverable.

The pattern was identical across all confirmed victims.

A frequently recurring honeypot contract address was
9xWwNMJmeZK6VgKo8Gb9uGQFFxSqMEAKUXxLPZXHnHEP verified on Solscan.

🔺 Verified Victims and On-Chain Proof

More than thirty victims publicly shared proof between October 27 and 28, including screenshots and transaction hashes.

Some victims;
@CryptoDOOM5 $130,000
@nftkeano48 BNB (~$28,000)
@bluexxix (for @rob02643673_rob)$300,000
@mementoken$20,000
@0xC4ss~$50,000

All cases show the same forensic footprint: rapid selling of holdings followed by automatic honeypot purchases.

Funds were not transferred out but trapped inside the contracts.

🔺Suspected Attackers

Analysts traced the activity to two hot wallets:

0x662c9fabbe452aa294fdf5bf2303caa26f6bd148

0xF13, which launched several honeypot contracts reported by @gotWickd

These addresses were active across BNB Smart Chain and Solana, launching coordinated fake tokens during a thirteen-hour window.

Some community analysts, such as @zacktradezCF, noted trading patterns suggesting Chinese MEV clusters, but no link to GMGN’s internal team was found.

🔺Official GMGN Responses

@gmgnai (October 27):
> “GMGN is safe. There are no security issues. Rumors of a hack are false.”

Haze (October 27, late):
> “We take this seriously. If GMGN bears even one percent of responsibility, we will compensate one hundred percent.”

@gmgnai (October 28):
> “All seven hundred twenty-nine affected transactions were reimbursed automatically. Users do not need to take any action.”

Media outlets including Crypto Economy and BitcoinEthereumNews confirmed the reimbursements within two days.

🔺Important Key Findings

GMGN’s internal security audit found no vulnerabilities in the platform code or backend systems.

The incident was entirely external, caused by coordinated MEV bots exploiting trade timing and connected wallet sessions.

It revealed a deeper issue within decentralized trading infrastructure.

When wallets remain connected to platforms with active APIs, they are vulnerable to external MEV manipulation even if the platform itself is secure.

🔺 Phishing Confusion

The recent MEV wave happened entirely on-chain through the legitimate GMGN interface, not through imitation domains or malware.

GMGN continues to warn users:

> “Never click on ads. Never share your private keys. The official bot will never ask for your seed phrase.”

🔺Security Recommendations from $MASTR

1. Revoke all token approvals after trading.

2. Disconnect your wallet immediately after using any decentralized exchange.

3. Do not interact with promoted or trending token lists.

4. Use burner wallets for copy trading or testing.

5. Verify updates only through @gmgnai or the official website https://t.co/0F52aLbVT3.

🔺 $MASTR Summary

The GMGN wallet draining event was not a hack but a coordinated MEV exploitation wave that hijacked connected wallets and forced them into honeypot trades.

A total of seven hundred twenty-nine transactions were affected across BNB Smart Chain and Solana.

All users received full reimbursement, and GMGN’s audit found no breach of internal systems.

More than one million dollars in cumulative losses were temporarily drained before being refunded.
The attackers remain unidentified.

The conclusion is simple:
Even secure platforms can become gateways for MEV exploitation when users leave wallets connected.

Connected does not mean safe.

If you have more information, feel free to add it.

Thanks for reading.

- by $MASTR

02

Original en X ↗

Our work here takes time.
We’re trying to be a counterforce to the usual CT noise, and we do all of this alongside jobs and family.

That’s why we’re deeply grateful for your support.

Check our links in the bio. Thank you. https://t.co/NloA58JocU

Cuentas mencionadas

Encuentra las menciones de una cuenta de X en las publicaciones seleccionadas. Una mención no es una acusación ni una recomendación.

@gmgnai · @haze_gmgn · @cryptodoom5 · @nftkeano48 · @bluexxix · @rob02643673_rob · @mementoken · @0xc4ss · @gotwickd · @zacktradezcf

Investigaciones relacionadas

Phishing, ataques y privacidad

Privacy, surveillance and control

A discussion of surveillance, data collection and the relationship between privacy and personal autonomy.

Artículos originales4 min
MASTR

Apoya la investigación independiente

Las investigaciones, las pruebas originales y las guías son de acceso libre. Las donaciones voluntarias ayudan a financiar la investigación y a mantener disponibles las herramientas de MASTR.

Abrir billetera