On-chain investigationLootBotEthereumKey compromise

LootBot hack: half of everyone who paid was drained in 31 hours.

Thousands of Ethereum wallets that had not moved in years were emptied over two days this month, about 20 a minute. We went looking for what they had in common, and found one product's customer list.

At a glance
LootBot is a Telegram bot that farms crypto airdrops for you. To do the farming it makes wallets on your behalf, and by its own documentation it keeps those wallets' private keys on its servers. On 7 September an address with no past started taking money out of them. It ran for 31 hours and finished with 259 ETH. We indexed every wallet it touched. Nine in ten of them were first funded in LootBot's opening year, and half of every wallet that ever paid LootBot on chain is in the drained set. What came out of each one was small. The median wallet lost about $26, and most of the money reached Ethereum from chains we cannot see, bridged home one swept wallet at a time.
49.7%
Of wallets that ever paid LootBot on chain were drained
92%
Of drained wallets first funded in LootBot's opening year
$26
Median taken per wallet on Ethereum
$627k
Moved to one address, still unmoved

01 · The wallet that woke up at 13:18

A new address, thousands of old ones, and 31 hours

At 13:18 UTC on 7 September, an Ethereum address received the first transaction of its life. It had no past. Nine hours later it was pulling money out of dormant wallets at about 20 a minute, and it kept going until the next evening.

The wallets it emptied had been asleep for a long time. The median one, the wallet sitting in the middle when you line them all up by how long they had been still, had not sent anything for close to three years. The quietest had not moved since the spring of 2022.

They had one thing in common, and it had nothing to do with tokens, exchanges or any website they had visited. The same Telegram bot made all of them. It is called

LootBot

, it farms crypto airdrops on your behalf, and to do that it holds the keys to the wallets it creates for you. Bitquery indexes every transaction on Ethereum, so we took every wallet the drainer touched, every wallet that ever paid LootBot, and compared the two sets against the full history of the chain. Tracing a wallet's counterparties this way is what our address APIs are built for.

One limit belongs up front. Four of the chains in this story are ones we do not index, so a little over half of the money is measured where it arrived rather than where it was taken. That gap turns out to matter, and we come back to it.

02 · Why an airdrop bot needs your key

The business that made these wallets

Airdrop farming is easy to describe. A new chain wants users, so it promises free tokens to whoever showed up early. People then use that chain as much as they can, from as many wallets as they can, hoping to qualify. The work itself is dull. Bridge some ETH, swap it, bridge it back, do it again next week from another wallet.

LootBot did the dull part. Its token first moved in July 2023, you talked to the bot inside Telegram, and its documentation says it made you "up to 10 farming wallets and 3 trading wallets" and sent the transactions itself. Reviews from the time priced it at $30 a month per wallet, or nothing at all in exchange for a fifth of whatever the airdrop paid out in the end. That second option matters later: a service that takes its cut from the airdrop has to be able to move your funds.

To send a transaction from a wallet, software needs that wallet's private key. LootBot's

own documentation

says it keeps them, "stored in an encrypted format using Advanced Encryption Standard". Another page in the same docs tells users that "you hold complete control over your fund as you will be given your private key after creating a new wallet". Both claims can be true together. You are handed a copy. The service keeps one as well.

A product that keeps the key is a custodian, whatever else it calls itself. That is the premise the rest of this rests on, and it comes from LootBot rather than from us.

03 · No signature, no approval, no contract

What the drain rules out

Most crypto theft works by permission. A site asks you to approve a token, you sign, and a contract uses that approval later to move what you approved. Wallet drainers, phishing pages and fake mint sites all live in that family. They share one trace in the data, which is a signature the victim made.

Native ETH sits outside it. No approval touches it. No contract can reach into a wallet and lift it. The only thing that moves ETH out of an address is a transaction signed by that address's own key.

The drainer moved native ETH out of 2,442 wallets. Whatever else is unclear here, whoever ran it was holding the keys. We reached the same conclusion by the same route on the Coldcard theft, where a hardware wallet leaked seeds instead of a server holding them.

04 · The wallets share a birthday

Nine in ten were first funded in the same eleven months

A wallet has no birthday in any formal sense. It does have a first transaction, the moment somebody funded it, and that is a date we can read for every address on the chain.

So we read it for all of them. If these were ordinary phishing victims, the dates would smear across the whole history of Ethereum, because ordinary victims are just people who happened to click a link. The dates do not smear. In June 2023, six of these wallets had been funded. In July, 608 were.

A product's signup curve, drawn from the wallets that got emptiedFirst funding date, monthly
Wallets the drainer emptied, by month first funded2,439 wallets6080Wallets that paid LootBot, by month first funded556 wallets192023-0123-0323-0523-0723-0923-1124-0124-0324-0524-07
Top: the 2,439 drained wallets that had any prior history, by the month they were first funded. Bottom: the 556 wallets that paid LootBot, measured the same way. Highlighted bars are July and August 2023. The drained wallets peak first and the paying wallets peak a month later, which is the order a subscription implies.

That curve does not decay like a breach. It decays like a product losing interest.

A shape can still be chance, so we ran the same test on a group already known to be LootBot's, the wallets that paid its fee. The lower panel is that group. Same wall in the summer of 2023, same decay through 2024, same death by the middle of that year. The paying wallets crest one month after the drained ones, which is the order the product implies. The wallet gets made. The fee gets paid after.

Read together, 92% of the drained wallets and 91% of the known LootBot payers were first funded inside the same eleven months.

05 · Half the paying customers

The test that needs no curve at all

There is a harder test. LootBot took payment on chain, at three known wallets, a fee contract and two that collected it. Every wallet that ever sent money to one of them is a LootBot customer we can name without guessing.

Once LootBot's own wallets are removed so the service cannot pay itself into the sample, there are 557 of them. The drained set contains 277.

The overlap
49.7% of every identifiable LootBot payer was emptied by one address inside 31 hours.
557
Wallets that ever paid LootBot on chain
277
Of them drained on 7-8 September
49.7%
Share of the known customer base

The figure runs one way only, and the other way is worth stating plainly. Those 277 wallets are 11% of all the drainer emptied on Ethereum. The rest never paid LootBot anything on chain, which is what a free tier taking its cut out of the airdrop rather than the wallet would produce.

06 · Two hours

The Ethereum sweep, and the nine hours of testing before it

The 31 hours are not spent evenly. Almost all of the Ethereum work happens in a single window overnight.

Wallets swept, and bridge payouts arriving, by hour7-8 September 2026, UTC
WALLETS SWEPT ON ETHEREUMBRIDGE PAYOUTS ARRIVING FROM OTHER CHAINS1279013:0016:0019:0022:0001:0004:0007:0010:0013:0016:0019:007 Sep8 Sep (UTC)2,390 wallets in two hours
Teal is wallets emptied on Ethereum. Amber is payments arriving from bridge solvers, each one the proceeds of a wallet swept on another chain. The Ethereum sweep runs from 23:00 to 01:00. Everything after it is money coming home from somewhere else.

Between 23:00 on 7 September and 01:00 the next morning, 2,390 wallets were emptied, peaking at 56 inside a single minute. Before that there are nine hours of a handful of wallets at a time, starting with five in the first hour. That reads as someone checking the keys work before they spend them.

After 01:00 the Ethereum wallets are all but finished, and the chart is carried by another source.

07 · What was actually taken

Nearly half the victims lost less than $25

A drain reported as $620,000 across several thousand wallets suggests a few hundred dollars from each. On Ethereum the spread is far more lopsided.

What each drained Ethereum wallet lost
Under $251,197 wallets
$25 to $1351,000 wallets
$135 to $2,500234 wallets
Over $2,50011 wallets

Nearly half the victims lost less than the price of a takeaway. The median wallet gave up about $26, the largest single loss was 4.2 ETH, and 11 wallets in total lost more than 1 ETH. Added together, all 2,442 Ethereum wallets produced 88 ETH.

No NFTs went anywhere. The collector never received one, and across the whole drained set a single wallet moved any, to an address with no part in this. Where a wallet held tokens, they were sold inside it and the ETH taken, so the token value is already counted in the figures above.

The drainer finished with 259 ETH. The other 171 ETH never came from an Ethereum wallet at all.

08 · The chains we can see, and the ones we cannot

Where the rest of the money came from

That 171 ETH arrived from nine wallets that belong to no person. Each has been running since December 2025, months before any of this. Each has moved several thousand ETH. One has paid out to more than 150,000 wallets across a quarter of a million transfers. These are bridge solvers, the machines that pay you on one chain when you deposit on another. We named them from their behaviour rather than from address labels, because none of the nine carries one.

They sent the drainer 4,876 separate payments and never got anything back. The median payment was worth about $15. No exchange sends 4,876 payouts that size to one customer. That is what wallets being swept one at a time on another chain looks like when the proceeds are bridged home.

Which other chain is the question, and the account that broke this drain answers it in a way we can check. It named nine chains, among them Base, Arbitrum, Optimism, Polygon and BNB Chain. We index all five. The drainer has never shown up on any of them.

Because a single private key produces the same address on every EVM chain, LootBot's paying wallets work as a probe anywhere. We ran it as a cross-chain query, one wallet set against five chains at once.

Chain we indexLootBot payers that moved native value after 7 Sep
Ethereum277 wallets drained, 88 ETH
Base1 wallet, about $150
ArbitrumNone
OptimismNone
PolygonNone
BNB ChainDrainer has no record on the chain

What is left is the chains LootBot named itself. Its documentation says the bot ran "on zkSync" first and would expand "through different EVM compatible chains (Polygon zkEVM, Linea, Scroll, Taiko…)". Those are the chains we do not index, and they are the most likely source of the bridged money. We are reading that from the shape of the payouts rather than from the chains, and it stays a guess until somebody indexes them.

That makes 259 ETH a floor rather than a total. It is what reached this address, and on Ethereum it is the whole of it: no second collector took money from these wallets, and the next busiest address the victims paid saw 10 of them. What we cannot see is whatever was sold or left sitting on the four chains we do not read. There is no honest way to put a number on that from here.

09 · The money has not moved

$627,000, one fresh address, and a poisoner eight minutes behind

Nothing here was laundered. At 16:54 on 8 September the drainer sent 252.21 ETH to a single wallet in two moves a minute apart. That wallet had been made minutes earlier and has since done nothing at all. No exchange deposit, no mixer, no bridge, no token, and no outbound transfer of any kind.

Still sitting there
0xC117DBC38766E408DEDC5EB8A64F6BA242015435
252.21 ETH
Received in two transactions
$627k
Value at the time
0
Outbound transfers since

Eight minutes after that money landed, a second party turned up. A new wallet began sending the drainer dust, three transfers worth a fraction of a cent. Its first three and its last six digits match the wallet now holding the money. It has touched nothing else in its life.

That is address poisoning, and we have

measured it across Ethereum before

. The trick is to slip a near-copy of an address into somebody's history, so the next time they paste an address out of it they paste yours. It is normally aimed at people who have money. This one is aimed at the person who took it. Following a wallet onward from here is a Coinpath job, and there is nowhere yet for it to lead.

10 · What the chain does not say

Where the keys lived, and who used them

Where the keys lived is on the record, put there by the service that kept them. Who used them is not, and nothing we found points at any person.

The wallet that deployed LootBot's fee contract has sent nothing since June 2024, and has never sent anything to the drainer. A product that stopped shipping and left a key database behind fits an outside breach as readily as anything worse, and a ledger does not record which. We also cannot say a database leaked, because that would happen on a server and servers do not write to the chain.

What the chain does support is narrower and still damaging. Several thousand wallets from one product's cohort were emptied by native transfers, which needs the keys. Half of that product's named payers are among them. The wallets had mostly been given up years ago by people who had moved on and had no reason to think anything still held the key. A drain that sits unnoticed for a day and a half is its own problem, and we have shown

how long one can go unflagged

.

11 · Method

What we ran, and what could have gone wrong

Every figure comes from Bitquery's own index of Ethereum, which covers the chain from 2015 to the hour of writing, plus our Base, Arbitrum, Optimism, Polygon and BNB Chain indexes for the checks that ruled those chains out. Victims are wallets that sent native ETH straight to the drainer in a transfer that went through. Bridge solvers were split out by how many transfers they sent, before any victim figure was worked out, because leaving them in inflates both the wallet count and the totals.

What could go wrongHow we handled it
Double counting the same transferNative ETH appears in our data as either a transaction or an internal call. We checked the two sets share no transaction hash before adding them.
Bridge payouts counted as victimsNine addresses sent 4,876 of the 7,343 inbound transfers. They predate the drain by nine months and pay out to six figures of counterparties. All victim figures exclude them.
A missing chain looks like a clean chainEvery exclusion was run against a live index with current data, and the same probe returns 277 hits on Ethereum, so a zero is a real zero.
Wallet age measured the wrong wayFirst measured on first outbound transfer, then redone on first funding, which is the earlier and better date. The cohort holds at 92% either way.
Reading intent from behaviourThe bridge solvers are identified from payout shape and counterparty counts, not from a label. The source chains behind them are inferred and flagged as inference.

The one number we cannot re-run is the link the original thread drew between victim wallet creation and LootBot signups. Signup data is not on chain. The cohort curve above is the on-chain stand-in for it, and it is measured rather than asserted.

12 · The record

The addresses behind the story

RoleAddress
The drainer0x4e5d…081e
Where the money sits0xC117…5435
The poisoner's lookalike0xC11B…5435
LootBot subscription contract0xcbec…f742
LootBot subscription wallet0x2413…853A
LootBot revenue wallet0xff5E…16B9
$LOOT token0xb478…2541

If you ever used LootBot, the wallets it made for you should be treated as burned on every chain, including the ones nothing has happened on yet. An empty balance today is no proof of safety.

Run it yourself

Ask these questions in plain English

Every number above came from queries anyone can run. The Bitquery MCP server puts the same index behind an AI assistant, so you can ask when a wallet was first funded, which addresses fed a collector, how long a set of wallets had been dormant, or whether an address exists on another chain, without writing the query yourself.

Date the first funding of any address set on EthereumSplit a collector's inflows into victims and infrastructureRun the same address across Base, Arbitrum, Optimism, Polygon and BNB ChainMeasure dormancy before a sweep for thousands of wallets at once
Explore Bitquery MCP Figures measured 9 September 2026 against Bitquery's Ethereum, Base, Arbitrum, Optimism, Polygon and BNB Chain indexes.