官方的 MASTR 标志 MASTR
菜单
阅读文章

钓鱼攻击、漏洞与隐私

GMGN wallet-draining reports: the October 2025 account

Between October 25 and 28, 2025, hundreds of users who connected their wallets to a major Solana and BNB Smart Chain trading and analytics platform, reported their funds disappearing in real time.

原文为英语,导航提供七种语言。

01

查看 X 原帖 ↗

The #GMGN Wallet Draining Incident, Full Breakdown here.

Between October 25 and 28, 2025, hundreds of users who connected their wallets to https://t.co/8Hm7fNwp53, a major Solana and BNB Smart Chain trading and analytics platform, reported their funds disappearing in real time.

Screenshots, Solscan links, and BscScan transactions flooded X.

Losses ranged from $20,000 to more than $300,000 per wallet.

Despite the chaos, #GMGN itself was never hacked.

What actually happened was probably a coordinated MEV (Miner Extractable Value) exploitation wave executed by automated trading bots. These bots front-ran legitimate user trades through GMGN’s transaction API and forced connected wallets to purchase honeypot tokens that trapped funds permanently.

🔺 Timeline of Events

October 27, early morning:
First victims appear on X. Wallets show a sudden sequence of sells followed by automatic buys into honeypots. Only wallets connected to GMGN were affected.

October 27, evening:
GMGN posts an official statement through @gmgnai:

> “GMGN is safe. There are no security issues. Please avoid false rumors and phishing links.”

October 27, late night:
Co-founder Haze (@haze_gmgn) acknowledges the incident and promises:

> “If GMGN is even one percent responsible, we will provide one hundred percent compensation.”

October 28, morning:
GMGN confirms the issue was external MEV activity, not a hack.

> “Seven hundred twenty-nine affected transactions were reimbursed automatically. No user action required.”

Independent crypto outlets later verified that refunds were completed within forty-eight hours.

🔺 How the Exploit Worked

The attackers did not steal seed phrases or private keys. Instead, they exploited the live wallet connection used for trading on GMGN.

Step by step, the attack unfolded as follows:

1. Bots monitored GMGN’s public transaction queue through its API.

2. They front-ran trades by executing malicious versions milliseconds before legitimate ones.

3. The connected wallet, still authorized, sold its holdings and automatically bought honeypot tokens created by the attackers.

4. The purchased honeypots locked the funds, making them unrecoverable.

The pattern was identical across all confirmed victims.

A frequently recurring honeypot contract address was
9xWwNMJmeZK6VgKo8Gb9uGQFFxSqMEAKUXxLPZXHnHEP verified on Solscan.

🔺 Verified Victims and On-Chain Proof

More than thirty victims publicly shared proof between October 27 and 28, including screenshots and transaction hashes.

Some victims;
@CryptoDOOM5 $130,000
@nftkeano48 BNB (~$28,000)
@bluexxix (for @rob02643673_rob)$300,000
@mementoken$20,000
@0xC4ss~$50,000

All cases show the same forensic footprint: rapid selling of holdings followed by automatic honeypot purchases.

Funds were not transferred out but trapped inside the contracts.

🔺Suspected Attackers

Analysts traced the activity to two hot wallets:

0x662c9fabbe452aa294fdf5bf2303caa26f6bd148

0xF13, which launched several honeypot contracts reported by @gotWickd

These addresses were active across BNB Smart Chain and Solana, launching coordinated fake tokens during a thirteen-hour window.

Some community analysts, such as @zacktradezCF, noted trading patterns suggesting Chinese MEV clusters, but no link to GMGN’s internal team was found.

🔺Official GMGN Responses

@gmgnai (October 27):
> “GMGN is safe. There are no security issues. Rumors of a hack are false.”

Haze (October 27, late):
> “We take this seriously. If GMGN bears even one percent of responsibility, we will compensate one hundred percent.”

@gmgnai (October 28):
> “All seven hundred twenty-nine affected transactions were reimbursed automatically. Users do not need to take any action.”

Media outlets including Crypto Economy and BitcoinEthereumNews confirmed the reimbursements within two days.

🔺Important Key Findings

GMGN’s internal security audit found no vulnerabilities in the platform code or backend systems.

The incident was entirely external, caused by coordinated MEV bots exploiting trade timing and connected wallet sessions.

It revealed a deeper issue within decentralized trading infrastructure.

When wallets remain connected to platforms with active APIs, they are vulnerable to external MEV manipulation even if the platform itself is secure.

🔺 Phishing Confusion

The recent MEV wave happened entirely on-chain through the legitimate GMGN interface, not through imitation domains or malware.

GMGN continues to warn users:

> “Never click on ads. Never share your private keys. The official bot will never ask for your seed phrase.”

🔺Security Recommendations from $MASTR

1. Revoke all token approvals after trading.

2. Disconnect your wallet immediately after using any decentralized exchange.

3. Do not interact with promoted or trending token lists.

4. Use burner wallets for copy trading or testing.

5. Verify updates only through @gmgnai or the official website https://t.co/0F52aLbVT3.

🔺 $MASTR Summary

The GMGN wallet draining event was not a hack but a coordinated MEV exploitation wave that hijacked connected wallets and forced them into honeypot trades.

A total of seven hundred twenty-nine transactions were affected across BNB Smart Chain and Solana.

All users received full reimbursement, and GMGN’s audit found no breach of internal systems.

More than one million dollars in cumulative losses were temporarily drained before being refunded.
The attackers remain unidentified.

The conclusion is simple:
Even secure platforms can become gateways for MEV exploitation when users leave wallets connected.

Connected does not mean safe.

If you have more information, feel free to add it.

Thanks for reading.

- by $MASTR

02

查看 X 原帖 ↗

Our work here takes time.
We’re trying to be a counterforce to the usual CT noise, and we do all of this alongside jobs and family.

That’s why we’re deeply grateful for your support.

Check our links in the bio. Thank you. https://t.co/NloA58JocU

提及的账号

查找所选文章中提及的 X 账号。被提及不代表受到指控或获得推荐。

@gmgnai · @haze_gmgn · @cryptodoom5 · @nftkeano48 · @bluexxix · @rob02643673_rob · @mementoken · @0xc4ss · @gotwickd · @zacktradezcf

相关研究

钓鱼攻击、漏洞与隐私

Privacy, surveillance and control

A discussion of surveillance, data collection and the relationship between privacy and personal autonomy.

原创文章4 min
MASTR

支持独立研究

这里的调查、原始证据和指南均可免费阅读。自愿捐赠帮助支付研究成本,让 MASTR 能够继续提供工具。

打开钱包