SIGMA bot blamed as attacker drains $200K from trader's wallets

Source Cryptopolitan

Crypto trader and X personality Unihax0r lost +$200,000 on May 11 after someone drained two of his wallets across Ethereum, Base, and BSC. On-chain analysts think it was a private key leak linked to a Telegram trading bot.

“Just got drained or hacked for more than 200k. Sick to my stomach,” Unihax0r posted on X. He shared the attacker’s wallet address and asked people to help trace the funds.

Attacker swept three chains in under an hour

This wasn’t a smart contract exploit since there’s no malicious token approval.

On-chain analyst @k0braca1 looked at the transactions right after it happened and said it looked like a private key leak. The attacker “had full control over signing operations across multiple chains: Ethereum, Base and BSC.”

The drain took somewhere between 10 and 30 minutes. The biggest chunks were about $125,000 in $POD tokens on Base and $21,000 in $FHE on BSC, plus ETH and smaller positions. The attacker even sent a bit of ETH to the Ethereum wallet first to cover gas for sweeping the remaining token balances.

SIGMA bot was the common thread

Both crypto wallets that got drained were created via a Telegram multichain trading bot called SIGMA. Unihax0r imported those wallets into GMGN, which is another Telegram trading tool, and Rabby Wallet.

Other wallets on Rabby and Jupiter were not drained since the SIGMA bot did not create them. This means that the SIGMA trading bot is the probable cause of this attack.

Investigators in the community have come up with a few ideas about what caused the theft of secret keys:

  • Telegram phishing through fake CAPTCHA bots that pop up when you use SIGMA.
  • Malware or infostealer infections.
  • Device compromise.
  • Malicious browser extensions.

Unihax0r said he checked his Telegram account and found no suspicious sessions, per Crypto Times.

The stolen crypto went to an externally owned account that the attacker controls.

The stolen crypto was transferred to an external wallet owned by the attacker. On-chain data shows the stolen tokens are already being mixed by the attacker.

Most of the assets are still sitting in the attacker’s wallets on Base. Community members and fraud tracking accounts have offered to help trace funds, but the odds of getting the money back are low.

Telegram bots are a structural weak point

Crypto losses connected to Telegram trading bots keep piling up. When a user generates wallets through Telegram bots, the private keys get created and stored within the bot’s infrastructure.

Security researchers from ForkLog warned about using Telegram bots to trade crypto. They explained that Telegarm bots “could potentially lead to asset losses and are not safeguarded against hacker attacks.”

Telegram bot scams have been ramping up. Web3 anti-scam platform ScamSniffer said Telegram group malware scams jumped by 2,000% between November 2024 and January 2025. Attackers use fake verification bots and phony group invitations to push malware that can access wallets and browser data.

Last September, Banana Gun, which is one of the most active Telegram trading bots, had 36 wallets exploited for 536 ETH. That was ~$1.9 million at the time. The bot went offline after that.

If you're reading this, you’re already ahead. Stay there with our newsletter.

Disclaimer: For information purposes only. Past performance is not indicative of future results.
placeholder
Why Analysts Believe Ethereum Can Reach $15,000 This CycleEthereum is trading just above $2,330, a price that, on the monthly chart, is sitting just above within a long accumulation zone. However, recent market dynamics show that Ethereum is destined for
Author  NewsBTC
19 hours ago
Ethereum is trading just above $2,330, a price that, on the monthly chart, is sitting just above within a long accumulation zone. However, recent market dynamics show that Ethereum is destined for
placeholder
Altcoin Trading Volume Shoots Up: Is The Altseason Upon Us Again?Following the recent uptick in altcoin prices, conversations about the potential start of an altseason are gaining significant momentum. Interestingly, recent on-chain data about the rising altcoin
Author  NewsBTC
19 hours ago
Following the recent uptick in altcoin prices, conversations about the potential start of an altseason are gaining significant momentum. Interestingly, recent on-chain data about the rising altcoin
placeholder
Alphabet briefly topped Nvidia in after-hours trading after a massive Google Cloud deal tied to AnthropicAlphabet (GOOGL) briefly climbed above Nvidia (NVDA) in after-hours trading this week, giving Google a short stay at the very top of the stock market. That is a serious turn for a company many investors were ready to punish when the AI boom first made chatbots look like a direct threat to search ads. The...
Author  Cryptopolitan
19 hours ago
Alphabet (GOOGL) briefly climbed above Nvidia (NVDA) in after-hours trading this week, giving Google a short stay at the very top of the stock market. That is a serious turn for a company many investors were ready to punish when the AI boom first made chatbots look like a direct threat to search ads. The...
placeholder
Iran sends response to U.S. ceasefire proposal as oil and crypto markets watch closelyIran has delivered its response to a U.S. ceasefire proposal through Pakistani mediators. This development adds a new layer of uncertainty for global markets. The proposal was designed to reopen the Strait of Hormuz and restart discussions on Iran’s nuclear program, reports The Guardian. After the response was passed to Pakistan, it was forwarded to...
Author  Cryptopolitan
19 hours ago
Iran has delivered its response to a U.S. ceasefire proposal through Pakistani mediators. This development adds a new layer of uncertainty for global markets. The proposal was designed to reopen the Strait of Hormuz and restart discussions on Iran’s nuclear program, reports The Guardian. After the response was passed to Pakistan, it was forwarded to...
placeholder
XRP Is Flashing a Reversal Signal That Preceded Its Last 126% RallyXRP (XRP) has climbed 5.7% over the past month, underperforming all other top-five large-cap assets except stablecoins. The modest rise also falters against sharper rallies in Zcash (ZEC), Toncoin (TO
Author  Beincrypto
19 hours ago
XRP (XRP) has climbed 5.7% over the past month, underperforming all other top-five large-cap assets except stablecoins. The modest rise also falters against sharper rallies in Zcash (ZEC), Toncoin (TO
goTop
quote