官方的 MASTR 标志 MASTR
菜单
阅读文章

链上调查

Dormant Ethereum wallets: the April 2026 drain trail

A wallet labelled by Etherscan as Fake_Phishing2831105 has been receiving funds from many addresses and rapidly moving them through swaps and cross chain infrastructure.

Original publication · 30 Apr 2026. Figures, claims and opinions reflect the original publication date.

原文为英语,导航提供七种语言。

01

查看 X 原帖 ↗

Ethereum Dormant Wallet Drain, April 30, 2026

A wallet labelled by Etherscan as Fake_Phishing2831105 has been receiving funds from many addresses and rapidly moving them through swaps and cross chain infrastructure.

The address is:

0xA707034429c8E4E01df056C0CbCf478F0FBeFAd7

Etherscan currently marks it as Phish / Hack and warns that reports link the address to a phishing scam.

The address shows 591 transactions, a remaining ETH balance of only about 0.0016 ETH, and a major outgoing move of 324.741 ETH into the THORChain Router v4.1.1 on April 30, 2026.

That single transaction alone was worth about $733,000 at the time shown by Etherscan.

The important part is the pattern.

This does not currently look like a normal smart contract exploit.

It does not look like the usual approval drain where victims recently connected to a malicious site and signed token permissions.

The visible pattern is simpler: ETH is being moved out of many wallets, aggregated into one labelled malicious address, then swapped or bridged out quickly.

Etherscan shows direct incoming transfers, smaller outgoing transfers, swaps through routers such as Magpie, and the large THORChain deposit.

That points to one likely explanation: compromised private keys or seed phrases.

If the attacker can sign directly from the victim wallet, no new approval is needed.
No fresh wallet connection is needed.
No warning popup is needed.
The attacker already has the key, signs the transaction, drains the ETH, aggregates the funds, and moves them out.

The community is describing many of the affected wallets as old or dormant Ethereum wallets, some reportedly inactive for years.

That part still needs careful verification wallet by wallet, but the broader risk model is clear: this is probably not a new Ethereum protocol bug.

It looks much more like an old key compromise surfacing at scale, possibly from leaked seed phrases, old wallet software, weak key generation, abandoned backups, breached databases, or compromised machines from years ago.

The laundering path is also visible.

The drainer collected funds, made smaller transfers, interacted with swap infrastructure, and then pushed 324.741 ETH through THORChain. The THORChain transaction succeeded, and the transaction memo shows an outbound Bitcoin destination, meaning the ETH was not simply parked. It was actively moved cross chain.

This matters because old wallets are often treated as harmless.
People forget them. They leave small ETH balances, old airdrops, NFTs, wrapped assets, LP tokens, or historical holdings sitting there for years.

But an old wallet is not safe just because it has been quiet. If the private key was leaked years ago, the attacker can wait forever and drain it whenever it becomes worthwhile.

Dear follower:

Check every old Ethereum address you have ever used. Not just your main wallet. Not just wallets with visible ETH. Check the dusty ones too.

If anything valuable remains in an old wallet, move it to a brand new wallet generated on a secure hardware device.

Do not reuse old seed phrases.
Do not migrate funds into another wallet derived from the same old seed.
Treat any wallet from an old machine, old browser extension, old cloud backup, or old mnemonic storage habit as potentially compromised.

At this stage, there is no confirmed public evidence that Ethereum itself was exploited.

The chain is doing exactly what it is designed to do: accepting valid signatures. The problem is that someone appears to have obtained the keys.

We will see. I can't proof it yet.

But remember:
On chain, there is no customer support, no password reset, no reversal, and no mercy.

If the key is gone, the wallet is gone.

Attachment to the original X post
Attachment to the original X post 查看完整尺寸图片 ↗
Attachment to the original X post
Attachment to the original X post 查看完整尺寸图片 ↗
Attachment to the original X post
Attachment to the original X post 查看完整尺寸图片 ↗
Attachment to the original X post
Attachment to the original X post 查看完整尺寸图片 ↗

来源与原帖

MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包