SIGMA bot blamed as attacker drains $200K from trader’s wallets
A cryptocurrency trader lost $200,000 across three blockchains in May after attackers gained access to private keys generated through a Telegram trading bot called SIGMA, exposing a critical vulnerability in how retail traders manage wallet creation and key storage on centralized messaging platforms. The incident underscores why institutional investors should scrutinize the security infrastructure of third-party tools, particularly bots operating on platforms not designed for key management, before allocating capital or recommending them to clients.
- SIGMA Telegram bot created both drained wallets; other wallets not created by SIGMA remained untouched and uncompromised
- Attacker swept $125,000 in $POD tokens on Base and $21,000 in $FHE on BSC within 10-30 minutes across three chains
- On-chain analysis ruled out smart contract exploit, confirming private key compromise as the attack vector across Ethereum, Base, and BSC
- $200,000 total loss across Ethereum, Base, and Binance Smart Chain in single incident
- 10-30 minutes time window for attacker to drain all three blockchain networks simultaneously
- 3 chains compromised simultaneously despite wallets created through single Telegram bot
On May 11, crypto trader Unihax0r discovered that attackers had systematically drained two of his cryptocurrency wallets across Ethereum, Base, and Binance Smart Chain, totaling over $200,000 in losses.
The attack was methodical: the attacker gained access to private keys controlling wallets on multiple networks, then executed coordinated withdrawals of token positions within a 10-to-30-minute window. The largest theft involved $125,000 worth of $POD tokens held on Base, followed by $21,000 in $FHE on BSC, with additional losses in Ethereum-denominated assets.
On-chain forensics by analyst @k0braca1 confirmed the attacker had “full control over signing operations” across all three networks, a signature of private key compromise rather than a smart contract vulnerability or approval-based exploit.
SIGMA bot created both compromised wallets while other wallets remained secure
The critical detail connecting the breach to a single point of failure emerged when investigators cross-referenced wallet creation sources. Both drained wallets had been generated through SIGMA, a Telegram-based multichain trading bot that has gained adoption among retail traders seeking streamlined token swaps and portfolio management.
Unihax0r had later imported those same wallets into GMGN (another Telegram trading tool) and Rabby Wallet, a browser-based self-custody extension. However, wallets on Rabby and Jupiter that had not been created by SIGMA remained completely untouched, indicating the compromise was isolated to the SIGMA generation process or its key storage infrastructure.
This selective attack pattern is significant because it rules out broader device compromise, malware affecting the entire wallet ecosystem on the user’s system, or a breach of downstream platforms like Rabby or GMGN where the wallets were later imported.
The attacker did not attempt to access or move funds from non-SIGMA wallets, suggesting targeted knowledge of which keys originated from SIGMA’s infrastructure. Unihax0r confirmed to security researchers that his Telegram account showed no suspicious login sessions, which would have been the case if his Telegram credentials themselves had been compromised.
Community investigators have proposed several possible vectors for the private key leak, including phishing attacks via fake CAPTCHA bots mimicking SIGMA verification prompts, malware or infostealer mallets on the user’s device, browser extensions with malicious code, or direct compromise of SIGMA’s backend infrastructure.
None has been confirmed, but each points to a systemic weakness in how Telegram bots handle private key generation and storage.
Attacker sent gas fees to cover sweeping wallets across three networks
The execution of the attack revealed sophisticated operational planning.
The attacker first transferred a small amount of ETH to the victim’s Ethereum wallet to cover gas fees for token transfers, then systematically withdrew all balances across Ethereum, Base, and BSC. This preparation step, funding gas on the primary network before conducting sweeps, indicates the attacker understood multi-chain wallet structures and possessed detailed knowledge of the victim’s holdings across three separate networks.
On-chain monitoring firms have tracked the stolen assets to an externally owned account controlled by the attacker. Most funds remain sitting on Base, though investigators have noted the attacker has already begun mixing some tokens, likely using privacy-enhancing services or cross-chain bridges to obscure the transaction trail.
Blockchain forensics firms and fraud tracking accounts have offered to assist in tracing the funds, but recovery odds remain minimal once assets reach attacker-controlled wallets with no clear on-chain linkage to regulated exchanges or custodians.
Telegram bots represent structural weak point for key storage and wallet generation
The SIGMA incident is not an isolated event but rather the latest in a recurring pattern of losses tied to Telegram trading bot infrastructure. When users generate wallets through Telegram bots, private keys are created and stored within the bot’s server architecture, bypassing traditional hardware wallet or local key management best practices.
Security researchers from ForkLog have issued repeated warnings about this architectural flaw, noting that Telegram bots “could potentially lead to asset losses and are not safeguarded against hacker attacks.”
The vulnerability stems from a fundamental mismatch between Telegram’s design and cryptographic security requirements. Telegram is a messaging platform built for communication, not key custody. Bots running on Telegram operate in an environment designed for transient conversations, not persistent, encrypted key storage.
When a user’s private keys are generated and held server-side by a bot, rather than created and stored locally by the user or on a hardware device, the bot operator becomes a single point of failure.
A breach of the bot’s infrastructure, a phishing attack targeting users of the bot, a malicious insider, or a compromise of Telegram itself could expose thousands of users’ private keys simultaneously.
For institutional investors and advisors considering Telegram bots as a client onboarding tool or trading solution, the SIGMA incident should trigger a formal security review. The convenience of bot-based wallet creation comes at the cost of surrendering key custody to a third party operating on an unsuitable platform.
Unlike regulated custodians that maintain security audits, insurance coverage, and compliance frameworks, most Telegram bots operate with minimal transparency around their infrastructure, backup procedures, or breach response protocols.
Retail adoption of Telegram bots continues despite mounting security warnings
Despite recurring breaches and security warnings from researchers, Telegram bots remain widely used in retail crypto trading because they solve a real usability problem: they lower friction for new traders who lack technical knowledge or hardware wallet infrastructure.
A user can message a Telegram bot, receive a wallet address, fund it with a DEX or bridge transaction, and begin trading within minutes, all without downloading software or managing seed phrases. This ease of use has made bots attractive to a segment of traders for whom self-custody best practices feel burdensome or confusing.
However, ease of use and security are often in direct tension. The same architectural simplicity that makes Telegram bots appealing, centralized key generation and storage, passwordless access via Telegram sessions, seamless multi-chain wallet support, creates the vulnerabilities that enable attacks like the one that hit Unihax0r. Each convenience layer removes a security barrier.
The key open question for institutional players is whether Telegram-based trading solutions will face increased regulatory scrutiny or whether the market will simply continue to accept these breaches as a cost of using unregulated, convenience-focused tooling. Unihax0r’s $200,000 loss is one of many; determining whether this incident catalyzes broader industry standards for bot security, insurance requirements for Telegram-based wallet services, or regulatory intervention remains unresolved. Institutional investors should monitor whether SIGMA or similar bot platforms issue formal incident disclosures and remediation plans, or whether the incident simply fades from public memory as affected users disperse to other Telegram trading tools with identical architectural risks.
