Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    Ethereum’s Staking War Why EIP-8361 Has DeFi Leaders Fighting Back
    Ethereum’s Staking War: Why EIP-8361 Has DeFi Leaders Fighting Back
    Nothing Is 100% Safe in Crypto Bitcoin’s Coldcard Exploit and Growing Security Crisis 
    Nothing Is 100% Safe in Crypto: Bitcoin’s Coldcard Exploit and Growing Security Crisis 
    From BitMEX to Leap Wallet 100+ Crypto Projects Have Shut Down in H1 2026
    From BitMEX to Leap Wallet: 100+ Crypto Projects Have Shut Down in H1 2026
    July Crypto Stock Breakdown Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped
    July Crypto Stock Breakdown: Why MSTR, BMNR Held Gains as IREN, WULF, RIOT, ABTC Dropped
    What Happens If the CLARITY Act Does Not Pass?
    What Happens If the CLARITY Act Does Not Pass?
  • Opinion
    OpinionShow More
    The Architecture of Trust Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
    The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
    The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation
    One P2P Trade, Months of Limbo Why Innocent Indian Crypto Users Keep Paying the Price
    One P2P Trade, Months of Limbo: Why Innocent Indian Crypto Users Keep Paying the Price
    CLARITY Act The Bill Exists, the Deal Does Not, Trump Has to Wait
    CLARITY Act: The Bill Exists, the Deal Does Not, Trump Has to Wait
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
    The Execution Gap: Why the Next Breakthrough in Financial AI is Human Behavior
  • Learn
    • Explained
    • How To
    • Insights
  • Videos
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Videos
  • Glossary
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Market News

Crypto Trader Drained of $200K in Telegram Bot Linked Crypto Hack

The two drained wallets were originally generated via the SIGMA Telegram trading bot, then imported into GMGN and Rabby Wallet.

Written By Dhara Chavda
Published 2026-05-11·Updated 3 months ago
Make The Crypto Times preferred on GoogleGoogle
Crypto Trader Drained of $200K in Telegram Bot Linked Crypto Hack
Trader loses $200K in Telegram bot-linked crypto hack
Show AI Summary
Attackers compromised private keys to drain over $200,000 across three chains
Two wallets were emptied in a manual 10-30 minute operation using direct signing control
The incident implicates the SIGMA Telegram bot as the common origin of the compromised wallets

Prominent crypto trader and X personality Unihax0r (@0xUnihax0r) was drained of more than $200,000 in a multi-chain attack on May 11, 2026, in what on-chain investigators have identified as a private key compromise—not a smart contract exploit or malicious token approval.

“Just got drained or hacked for more than 200k. Sick to my stomach,” Unihax0r wrote on X around 01:53 UTC, sharing the attacker’s wallet address (0xF7cFFC27732a5C9c4E2D592F3E33435F8dDb019A) and requesting community help tracing the funds.

Just got drained or hacked for more than 200k. Sick to my stomach

This is the wallet where the money went:
0xF7cFFC27732a5C9c4E2D592F3E33435F8dDb019A

Any help to track the money would be appreciated

— Unihax0r (@0xUnihax0r) May 11, 2026

The incident has reignited a fierce debate about the security risks of Telegram-based trading bots — the infrastructure that an estimated hundreds of thousands of crypto traders rely on daily for on-chain execution.

The Attack: Manual, Methodical, Multi-Chain

On-chain analyst reveals a manual drain executed over a roughly 10–30 minute window between approximately 00:37 and 00:56 UTC. Two wallets were emptied across three chains: Ethereum, Base, and BSC.

The bulk of the losses came from approximately $125,000 in $POD tokens on Base and $21,000 in $FHE on BSC, along with ETH and smaller positions including $SAT1. The attacker was thorough enough to dust the Ethereum wallet with a small amount of ETH to sweep remnant token balances—a hallmark of an experienced operator with full signing control.

Critically, this was not a malicious approval drain or a smart contract exploit. The attacker had direct private key access, enabling them to sign transactions natively across all three chains without needing any on-chain permissions.

The SIGMA Connection

The two compromised wallets share a common origin: both were originally generated or imported via the SIGMA Telegram bot, a multi-chain trading bot that supports Ethereum, BSC, Base, Solana, Avalanche, and other networks through a single Telegram interface.

Unihax0r confirmed that the wallets were subsequently imported into GMGN (a Telegram-based trading and analytics bot) and Rabby Wallet (a browser-based wallet). Other wallets on Rabby and Jupiter that were not generated through SIGMA remained untouched — a detail that has focused community attention on the SIGMA workflow as the likely compromise point.

The suspected attack vectors, according to community on-chain observers, include Telegram-based phishing — particularly malicious CAPTCHA bots that appear when interacting with SIGMA — as well as potential malware or infostealer infections, device compromise, malicious browser extensions, or a fake GMGN workflow. Unihax0r reported no suspicious Telegram sessions on his account.

Funds Likely Unrecoverable

The stolen assets were moved to the attacker’s externally owned account (EOA). On-chain traces suggest mixing and tumbling attempts are already underway, with the majority of funds sitting in attacker-controlled addresses primarily on Base. Community members and fraud tracking accounts have offered further tracing assistance, but recovery prospects are considered low.

All compromised wallets have been flagged as fully compromised, and Unihax0r has been advised to migrate to entirely new wallets.

The Telegram Bot Security Problem

The incident spotlights a structural vulnerability in the Telegram trading bot ecosystem that security researchers have flagged throughout 2026. When users generate wallets through Telegram bots, the private keys are created and — in many cases — stored within the bot’s infrastructure. Unlike hardware wallets where keys never leave the device, Telegram bot wallets rely on the security of the bot provider, the user’s Telegram account, and every intermediary the keys pass through.

The attack surface is wide. Malicious CAPTCHA bots—designed to look like legitimate verification steps within Telegram trading channels—have become a common phishing vector in 2026. When a user interacts with a fake CAPTCHA, the bot can harvest session tokens, inject clipboard-replacing malware, or in some cases directly exfiltrate private keys stored in the Telegram environment.

Security firm Hacken has noted that most Telegram trading bots are closed-source and unaudited, and some explicitly disclaim responsibility for unauthorized access to user accounts in their terms of service. The absence of end-to-end encryption in Telegram bot interactions exposes an additional layer of risk.

DEXTools’ 2026 safety guide for Telegram bots is blunt on the core risk: “Bots get hacked. Extract profits daily.” The recommendation to use burner wallets with only active trading capital — never storing significant holdings — is widely considered best practice but frequently ignored by traders seeking the convenience of a unified multi-chain interface.

A Familiar Pattern in 2026

The Unihax0r drain joins a growing list of high-profile individual wallet compromises in 2026. In December 2025, a crypto whale lost $27.3 million after a multi-signature wallet was compromised via a leaked private key. In March 2026, BONK.fun was hit after attackers hijacked a team account and deployed a wallet drainer on the site’s domain. And just last week, the Grok/Bankr exploit demonstrated how even indirect key exposure—through AI agent intermediaries—can result in six-figure losses.

The incident drew widespread reactions on Crypto Twitter, ranging from sympathy to pointed irony over the “Haxor got hacked” dynamic—and, more constructively, renewed warnings about the fundamental trade-off at the heart of Telegram bot trading: speed and convenience vs. custodial risk.

Also Read: BONK.fun Hack Exposes Users to Wallet Drainer Threat

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News

TAGGED:Crypto HackCrypto Trading
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link

Latest News

The Architecture of Trust Same Routes, New Risks in Global Tokenisation
The Architecture of Trust: Same Routes, New Risks in Global Tokenisation
Bybit Sues North Korea Over $1.5B Hack; Freezes Assets
Bybit Sues North Korea Over $1.5B Hack, Secures Court-Ordered Asset Freeze
U.S. Senate Moves CLARITY Act Forward as September Vote Comes Into View
U.S. Senate Moves CLARITY Act Forward as September Vote Comes Into View
From Trusted Vendor to Insider Job Coinkite CTO Now Linked to $110M Coldcard Hack Code
From Trusted Vendor to Insider Job? Coinkite CTO Now Linked to $110M Coldcard Hack Code
The Architecture of Trust What 4,000 Years of Trade Teach Us About RWA Tokenisation
The Architecture of Trust: What 4,000 Years of Trade Teach Us About RWA Tokenisation

Find Us on Socials

You may also like

Privacy-First Coldcard Maker Suspends Data Deletion as Legal Proceedings Loom

Privacy-First Coldcard Maker Suspends Data Deletion as Legal Proceedings Loom

CFTC Chair Pushes US Crypto Innovation Over Global Consensus

CFTC Chair Pushes US Crypto Innovation Over Global Consensus

BONK Crashes to 3-Year Low as Upbit Delists Solana Memecoin Over $20M Hack

BONK Crashes to 3-Year Low as Upbit Delists Solana Memecoin Over $20M Hack

Cathie Wood's ARK Invest Buys $22.5M Block Stock, Sells Bullish (BLSH) & Trims SpaceX

Cathie Wood’s ARK Invest Buys $22.5M Block Stock, Sells Bullish (BLSH) & Trims SpaceX

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Videos
Glossary

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information