Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
  • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
DeFi News

EVM Wallet Draining Continues Amid Browser Security Concerns

EVM wallets face automated attacks, draining millions across chains as browser and third-party vulnerabilities leave users’ funds at risk.

Written By:
Kenrodgers Fabian

Reviewed By:
Gopal Solanky

Last updated: January 2, 2026 1:04 PM
Published January 2, 2026 1:04 PM
Share
Last updated: January 2, 2026 1:04 PM
Published January 2, 2026 1:04 PM
EVM Wallet Draining Continues Amid Browser Security Concerns

Key Highlights

  • EVM wallets face automated attacks, draining small amounts from hundreds of users, with total losses surpassing $107K and rising rapidly.
  • Browser and third-party wallet flaws leave users exposed, highlighting urgent risks in Chrome extensions and Magic Labs login systems.
  • Phishing scams and ICO exploits continue, with stolen funds often laundered via SOL and nested services, showing coordinated attack sophistication.

Crypto wallets on several Ethereum Virtual Machine (EVM) chains are under attack, and hundreds of users are losing funds. Blockchain investigator ZachXBT warned on Telegram that each wallet is losing less than $2,000, but the total stolen amount has so far exceeded $107,000, as of latest data. 

Victims have reported that funds suddenly disappeared, without incremental withdrawals, which indicates a very focused and automated attack. The vulnerability used is still unknown, thus leaving users and developers in the dark.

The attack has influenced wallets belonging to high-profile projects. Megamus.hl reported on X that his wallet, holding MegaETH allocations, was compromised. “My EVM wallet got hacked today. Luckily I had already moved most of my funds out,” the victim posted on X. He pointed out that his MegaETH allocation is exposed and that the MegaETH team is searching for solutions. 

My EVM wallet got hacked today. Luckily I had already moved most of my funds out, so the damage wasn’t catastrophic.
What really scares me is this: This is the same wallet that received my MegaETH allocation.
I’ve already reached out to @0xAlexjultz and he helped flag my case. He… pic.twitter.com/tsKVkn3Jlm

— Megamus.hl (@0xMegamus) December 30, 2025

Browser extension vulnerabilities raise alarm

This wave of attacks follows Trust Wallet’s confirmation of a security incident on December 26, affecting a Chrome browser extension version. ZachXBT estimates attackers drained more than $6.77 million from users’ wallets through similar breaches. 

The timing also coincides with Trust Wallet’s recent update rollout, suggesting a vulnerability in the extension’s new code. Users reported sudden fund transfers, often seeing balances vanish within minutes. Many victims did not notice gradual withdrawals, indicating automated exploit scripts targeting multiple wallets.

Further threats were posed by the decentralized prediction platform Polymarket due to a breach via a third-party log-in vendor named Magic Labs. Users who logged in using the Magic Labs system had their wallet balances drained without it affecting either their devices or mail addresses. 

Polymarket confirmed the issue and stated, “We recently identified and resolved a security issue affecting a small number of users. The issue was caused by a vulnerability introduced by a third-party authentication provider.”

Phishing scams and ICO exploits

Phishing campaigns continue to plague the crypto ecosystem. SpecterAnalyst in a post on X highlighted Solana-based scams involving omnerausd and Shade_L2 ICOs. Victims lost wallet permissions and had funds siphoned into attacker-controlled addresses. 

A quick look into omnerausd (@ColeJacksonUS) and @Shade_L2 ICO scam, where victims were also drained while claiming the ICO tokens

This appears to be part of an ongoing Solana phishing scam (SolPhish) that has been active for some time on the Solana blockchain. The attack relies… pic.twitter.com/Wm5MYo0dlE

— Specter (@SpecterAnalyst) January 1, 2026

In a case, $200,000 that had been deposited into an ICO wallet was found to have originated from an address that had previously been associated with thefts amounting to $300,000. The stolen money had been mainly converted to SOL, with nested services used for trading and money laundering.

High-profile hacks highlight persistent threats

After the common wallets, prominent hacks just keep rolling. An alleged U.S. government wallet was plundered of some $20 million, which included seized 2016 Bitfinex hack cash, as of early July reporting by Arkham Intelligence.

The assailant began the process of exchanging the stablecoins for ETH, likely for money laundering via addresses known for money laundering. Such occurrences remind one that, despite the security measures employed, funds are still vulnerable to attacks.

Also Read: Iran Offers Advanced Weapons for Crypto to Bypass Global Sanctions

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:Crypto HackEthereum (ETH)
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Fabian is Crypto Journalist at The Crypto Times
By Kenrodgers Fabian
Follow:
Kenrodgers Fabian is a Content Writer with over 3 years of experience in crypto news, data analysis, and IT. With a degree in Health Records and Information Technology, he brings a structured and analytical approach to digital reporting. Kenrodgers focuses on delivering accurate, informative content that helps readers stay updated on the latest trends in crypto and emerging technologies.
Gopal Solanky - Crypto Research Analyst at The Crypto Times
By Gopal Solanky Sr. Crypto Journalist
Follow:
Gopal Solanky is a Research Analyst and Reporter with over 5 years of experience in DeFi, blockchain, crypto, IT, and financial markets. With a Bachelor's in Computer Applications, he brings a strong technical foundation to his analysis and reporting. Gopal focuses on breaking down complex topics for both seasoned investors and curious readers. His work has been referenced by publications like Business Insider and Vulture.com, highlighting his contributions to industry stories around topics like Huwak Tuah Memecoin and the FTX collapse.

Latest News

Crypto Stocks Surge in April Galaxy, MARA, Riot, & Coinbase
Crypto Stocks Surge in April: Galaxy, MARA, Riot, & Coinbase
Czech Central Bank Governor Backs Bitcoin Reserves at Bitcoin 2026
Czech Central Bank Governor Backs Bitcoin Reserves at Bitcoin 2026
WLFI Partnered With Crypto Project Linked to Alleged Scam Network
WLFI Partnered With Crypto Project Linked to Alleged Scam Network
Polymarket Rejects Breach Claims Amid 300K Record Leak Reports
Polymarket Rejects Breach Claims Amid 300K Record Leak Reports
Ostium Labs Unveils Institutional-Backed Onchain Trading System
Ostium Labs Unveils Institutional-Backed Onchain Trading System

Find Us on Socials

You may also like

How Hackers Hijacked Robinhood’s Legitimate Emails Using Gmail Dot Aliases

How Hackers Hijacked Robinhood’s Legitimate Emails Using Gmail Dot Aliases

Compound DAO Proposes Up to 3,000 ETH for DeFi United Recovery Push

Compound DAO Proposes Up to 3,000 ETH for DeFi United Recovery Push

DeFi United Targets $71M Recovery From Aave in rsETH Backing Plan

DeFi United Targets $71M Recovery From Aave in rsETH Backing Plan

ZetaChain Halts Cross-Chain Activity After GatewayEVM Smart Contract Exploit

ZetaChain Halts Cross-Chain Activity After GatewayEVM Smart Contract Exploit

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information