View Reports

Submitted: 4 hours ago

Profile

Guest

Pig Butchering Scam

A Telegram user named 'Kitty Roaring' (with a verification badge) claimed to run an AI-based trading service — an AI-trading pig-butchering scam. In July 2025, I sent 1,000 USDC to the crypto address 0x1221e434ce9cc02b264531ff6d0c15603408b136 on the Ethereum network. The scammer later demanded a 10% advance 'commission fee' before any withdrawal and then ghosted me. This is a pig-butchering / advance-fee fraud scam.

ETH | 0x1221e434ce9cc02b264531ff6d0c15603408b136

Submitted: 6 hours ago

Profile

Guest

Other Hacking Scam

My Mac was infected with a malware trojan distributed through pirated technical software. The malware exfiltrated the private keys of the Ethereum wallets I manage with the Rabby browser extension, which were stored in plain text on the same machine. In the evening of 22 September 2026 the attacker used those keys to drain every wallet I controlled, moving all the funds into a single consolidation address created earlier the same day. Part of the stolen assets was converted through an instant-exchange service and sent back as ETH to that same consolidation address. The malware was later detected and quarantined by antivirus but not removed, and is preserved on the machine. I have filed a criminal complaint with the Italian police, addressed to the Public Prosecutor's Office in Milan, and the case is being handled together with the SEAL 911 incident response team, which has already flagged the consolidation address to its compliance partners.

ETH | 0xaBFc9DB87880486E630D89ADb90147B47ACf4F90

Submitted: 10 hours ago

Profile

Guest

Impersonation Scam

I was following up on an Internet Money.io wallet login and thought I was dealing with an honest person, who had assisted me previously and never gave any indication that he was part of any kind of scam. I couldn't log into the internet money wallet app that had a significant amount of crypto. The wallet app wasn't allowing me to access my account (which had never happened previously) so I was panicking for help. In the process of trying to troubleshoot the issue, I put in seed phrases for my Internet Money wallet and my MetaMask wallet. Shortly thereafter, my accounts started to get drained.

ETH | 0x8152cdbdE1C264af5AC526e6Bf6a51c6f9A887f4
URL | http://imchannel.app

Submitted: 23 hours ago

Profile

Guest

Phishing Scam

No soy la víctima. Reporto un drain por phishing / approval maliciosa (estilo Medusa) en Ethereum. Víctima: 0x143B5D7E1A11B5dC301D97A51264EB73dD5A37EC Pérdida: ~27,23 rsETH (token Kelp 0xA1290d69c65A6Fe4DF752f95823fae25cB99e5A7) Approval: 0x9aa80a5bfd20271394f9d9e52be55cf014c80d2d0a4d8d70991b555ad739453a Spender / transferFrom: 0xf826927bf2B78EadEB1D8b045115f409E6D9c3dc Drains: - Ene 2024: 0x9a43518cdc6f051b2f02877d52911a2b8cb092a2d18667f81518ea8c54945f99 - Ene 2024: 0x62ea10f67071f8e97e03c74d8be87c29270397767057a1045325b1b4a9e6ece5 - Abr 2024: 0x9066289fa7c41c753912bf57dabdadef9d320ecdcb04f39eb98e24ba19b5f38f → receptor 0xFa7575CaA049e5cFD96a2783da2C85663f0Da817 (label Medusa Drainer 1) Swap Balancer: 0xf3bad1b29f02c6b96f1d518c599a29ba57bdcaa75a8be8917563d4428edd099b Peel: 0x674d4fcBEE75d9D64F30d23D27F9238aCd22E3Ac y 0xB14e80A817Ab25F144e4A02B47Eb610053EAce4E Cashout TradeOgre 1 0x4648451b5F87FF8F0F7D622bD40574bb97E25980 Txs cashout 28/04/2024: 0x7335d3e86afae92dbb21597c596e0491b915de01e44f358fece59a419f642fa2 0x2ffdd5f291822a26c1cc8238964adc583316a29749bff80074eb2a44ef3bfac0 Tx posterior 03/02/2025 0xe6ed51fcdced08f7b676313bcae1ce72b48d11d7c03ab8a931fd82c460e55c00: split USDC 20/80 a 0xFa7575… y 0x7Ab8C59Db7b959Bb8C3481d5b9836dfbc939AF21 (otra víctima). No se afirma mismo operador como hecho. Pido flag de las addresses listadas (no la víctima) y escalado de los depósitos TradeOgre de abril 2024 vía autoridades. Nombres de OSINT = solo alegaciones.

ETH | 0xf826927bf2B78EadEB1D8b045115f409E6D9c3dc
ETH | 0xFa7575CaA049e5cFD96a2783da2C85663f0Da817
ETH | 0xddddf47fDe0b9F2185eD15ff68Aa3AfC0D677150
ETH | 0x5A7575A7f18d931DA0833387890b397d371a1Ee3
ETH | 0x674d4fcBEE75d9D64F30d23D27F9238aCd22E3Ac
ETH | 0xB14e80A817Ab25F144e4A02B47Eb610053EAce4E
ETH | 0x7Ab8C59Db7b959Bb8C3481d5b9836dfbc939AF21
ETH | 0x4648451b5F87FF8F0F7D622bD40574bb97E25980
ETH | 0x5E38AD84A902078D61Ca8D3BEbd378bC0e32C422
ETH | 0x143B5D7E1A11B5dC301D97A51264EB73dD5A37EC

Submitted: 1 day ago

Profile

Guest

Phishing Scam

On 25 April 2024 my Ethereum wallet 0x143B5D7E1A11B5dC301D97A51264EB73dD5A37EC was drained of 26.21 rsETH (plus 1.02 rsETH on 29 January 2024; 27.13 rsETH in total, approx. USD 85,000 at the time) through a malicious token approval I signed on a phishing site impersonating the $WEN token claim. ScamSniffer identified the tool as the Medusa drainer. Theft transactions: 0x9066289fa7c41c753912bf57dabdadef9d320ecdcb04f39eb98e24ba19b5f38f, 0x9a43518cdc6f051b2f02877d52911a2b8cb092a2d18667f81518ea8c54945f99, 0x62ea10f67071f8e97e03c74d8be87c29270397767057a1045325b1b4a9e6ece5. The funds went to 0xFa7575CaA049e5cFD96a2783da2C85663f0Da817. TradeOgre froze part of the proceeds and returned 10 ETH to me in May 2024 after a police report (Mossos d'Esquadra, Catalonia, May 2024). About 17 ETH remains unrecovered. New evidence: transaction 0xe6ed51fcdced08f7b676313bcae1ce72b48d11d7c03ab8a931fd82c460e55c00 (3 February 2025) drained another victim and split the proceeds 20/80 between the wallet that received my funds (0xFa7575…) and 0x7ab8c59db7b959bb8c3481d5b9836dfbc939af21. In a public investigation dated 20 March 2025, blockchain investigator ZachXBT identified 0x7ab8… as a phishing-drainer fee address belonging to a trader he named as William Parker (formerly Alistair Packover), a British national previously convicted in Finland (2023) and the UK (2010), with funds at 0x51d99A4022a55CAd07a3c958F0600d8bb0B39921. Both wallets were paid from the same theft transaction, which links them to the same phishing operation. I request that these addresses be flagged, and that any funds reaching regulated exchanges be frozen pending investigation.

ETH | 0xFa7575CaA049e5cFD96a2783da2C85663f0Da817

Submitted: 1 day ago

Profile

Guest

Fake Project Investment Scam

BitradeX is a fraudulent "AI trading bot" investment platform operating as a Ponzi/pyramid scheme. Users buy fixed-term "AiBot" plans; early "profits" are withdrawable to build trust. On May 7, 2026 I deposited 11,999.13 USDT (ERC-20) to the BitradeX deposit address 0xa0903a068Ed85B2B794b0CF738a89eaa142B1aD8 (tx 0xb0080e8391483c28e08062871ad37e3399307aebc3dd2cc78763d0a3a7a4959f). In late August 2026 the platform froze all withdrawals citing an "update"; on Sep 15, 2026 the bot stopped, spot balances vanished and principal was locked. The platform now only offers to convert balances into an internal, non-withdrawable token (USDX), or to "unlock" funds by requiring more deposits and recruiting new referral investors - its official notice ties daily unlocking to "new investment principal from direct/indirect referrals", confirming a pyramid structure. On-chain, deposits are swept within seconds to the collector wallet 0xb8001c3ec9aa1985f6c747e25c28324e4a361ec1, which aggregates funds from many victims. The deposit address is labelled "Cobo. User" on the OKX explorer and was funded by "Cobo: Deposit Funder 2" (Etherscan). A police report has been filed in Brazil.

ETH | 0xa0903a068Ed85B2B794b0CF738a89eaa142B1aD8
ETH | 0xb8001c3ec9aa1985f6c747e25c28324e4a361ec1
URL | bitradex.ai

Submitted: 1 day ago

Profile

Guest

Contract Exploit

My Ethereum wallet was compromised through a malicious smart contract delegation (EIP-7702 authorization), not a direct theft of my private key. I believe I was tricked into signing a malicious authorization — likely disguised as a token "claim," wallet "verification," or airdrop signature request on a phishing site — around September 3, 2026. I do not recall the exact site, as the delegation sat dormant afterward without any obvious signs of compromise. This delegation gave a smart contract deployed by the attacker (address ending in ...517E7DE9A) standing authority to execute transactions from my wallet without needing my private key or further approval from me. On September 23, 2026, once my wallet accumulated a real USDT balance, the attacker used this pre-existing delegation to execute a transfer directly from my wallet to their own address, moving 5,132.86 USDT (approximately $5,131 USD) out in a single transaction, using a Multicall/"Aggregate" method routed through my wallet's delegated contract. I did not authorize or initiate this specific transfer — it executed automatically once funds were present, as a result of the delegation set up weeks earlier. The stolen funds (5,283.89 USDT and 150 USDC total, including funds apparently taken from other victims) are, as of this report, still sitting unmoved in the attacker's wallet and have not yet been sent to an exchange or mixer.

ETH | 0xf95E2D2803e1D934E29e133693f325b15665CF2a
ETH | 0xC7D0FCA2A2aD6BaCdCBA48e7EF2723a517E7DE9A
ETH | 0x49Cec3B4007E8e00f21C3acE4d3595DaeB7e45e8

Submitted: 1 day ago

Profile

Guest

Phishing Scam

Active multi-chain wallet-drainer phishing operation. governance-deed.estate is a clone of the legitimate deed.estate, running a fake "$DEED Rewards Date" governance-vote lure ("Register & Begin Voting"). It is one of 122+ domains (Flare/Firelight/Hyperliquid/Injective/OKX-vote/ether.fi "Vote on the Rewards Date" clones since 2026-07-28) that all load an EtherHiding wallet-drainer from the loader host pinky-goat.digital. The drainer's host pointer is stored and rotated every 30 minutes in an Arbitrum contract (0x967530969F5e5c94E0dC7247e9355e62e0ED65B2, owned by 0x1a906403a6f5F0352984865565Aa4dF18111b385). Victims connect a wallet and sign an approve/Permit2; the drainer pulls their tokens, splitting ~80% to the operator and ~20% to fee-sink 0xb0d9064875C70dd289d31bD8e13eAaBC0Cc84E06. Proceeds consolidate at 0x5db95fa0f6694ba8ad2077e507b2fd01d3eff858 and treasury 0x57fAC2a74B61245c6d221c99DFBE82d0260AF98e, then cash out via Relay and Butter Network (BSC to Tron USDT, tagged as an OKX Web3 Wallet route) and via Avalanche wallet 0x768a33dfa628cc8f320791e929184c16f64a22a7. Four of these wallets already carry HashDit "Fake_Phishing" tags on Etherscan/Snowtrace. Traced Ethereum victim losses so far ~$63k across 53 wallets.

ETH | 0x967530969F5e5c94E0dC7247e9355e62e0ED65B2
ETH | 0x1a906403a6f5F0352984865565Aa4dF18111b385
ETH | 0xb0d9064875C70dd289d31bD8e13eAaBC0Cc84E06
ETH | 0x5db95fa0f6694ba8ad2077e507b2fd01d3eff858
ETH | 0x57fAC2a74B61245c6d221c99DFBE82d0260AF98e
ETH | 0x768a33dfa628cc8f320791e929184c16f64a22a7
URL | governance-deed.estate
URL | pinky-goat.digital