LootBot Wallet Drain Exposed: What the 2026 Airdrop Bot Incident Reveals

Some LootBot users opened old farming wallets in September and found the balances gone. The transactions were real, but the explanation was not immediately clear.

That uncertainty matters. If you used a bot-created wallet, the useful question now is what its history can tell you, and what you can still protect.

Illustrative LootBot-style wallet dashboard with historical farming wallets and empty balances

Overview

What investigators could see on-chain

On-chain researcher Bitquery examined a cluster of Ethereum wallets swept in early September 2026. Its report identified 2,442 wallets in the observed set.

Of those, 557 had a detectable history of payments associated with LootBot. Bitquery found that 277 of those payer wallets appeared in the swept group.

The destination collected about 259 ETH before most of that value moved onward. These figures describe a particular analysis at a particular time.

They do not establish a total across every network or every user. Nor does a matching transaction history, on its own, identify whoever controlled the receiving wallet.

Why old bot wallets can remain exposed

LootBot helped users automate airdrop-related activity with wallets created for the service. According to its documentation, private keys were stored encrypted and available to users.

That design creates a simple but uncomfortable question: could anyone besides the owner obtain a usable key, directly or through a security failure?

A private key is not a login session you can revoke after the fact. A copied key can sign transactions whenever funds remain at its address.

The illustration above shows the kind of dashboard a worried user might revisit. It is not a screenshot of a specific victim account.

What remains unproven

The public on-chain record shows transfers. It does not prove who acquired the keys, how they were obtained, or whether the service operator was involved.

That distinction keeps this from being a fair claim that LootBot itself was a scam. It is a documented wallet-drain incident with unresolved attribution.

For someone deciding what to do next, the practical points are narrower:

  • Identify every wallet generated or imported through the bot.
  • Check each address on the correct chain, not just the Ethereum mainnet view.
  • Move remaining assets to a newly created wallet with a fresh key.
  • Preserve transaction links and account records before closing anything.

How the LootBot Wallet Drain Unfolded

Step 1: Users created wallets for airdrop farming

Airdrop farmers often separate experimental activity from their main savings. A bot-created wallet can make that process feel convenient, especially across many campaigns.

That convenience changes the trust arrangement. The wallet may be yours in the sense that you can export its key, but creation and storage involved another system.

Many users also leave a little ETH in these wallets for gas. Months later, a forgotten wallet may still hold tokens, native coins, or claim rights.

A wallet with no visible balance on one app may still contain assets on another network. That is why a narrow dashboard check can miss exposure.

Step 2: Key custody created a lasting risk

LootBot’s published description said the service held encrypted private keys. Encryption is meaningful protection, but it does not make an exposed key impossible.

The public evidence does not show whether keys were leaked, decrypted, phished from users, or accessed through some other route.

What matters operationally is that the address can be controlled by anyone with its private key. A website logout cannot change the address’s cryptographic owner.

Revoking a token approval is useful for allowance-based attacks, but it cannot stop a thief who already possesses the wallet’s signing key.

Step 3: Many wallets were swept toward common destinations

Bitquery traced transfers from the affected addresses into a collecting address. A large portion of the ETH then moved again to another address.

A chain of transfers can reveal timing, routing, and value. It is not a photograph of the person pressing the buttons.

Researchers also found that some identified LootBot payers were not among the wallets swept. That means exposure was not uniform across the observed payer group.

Someone whose wallet was untouched should not assume it is safe forever. Someone whose wallet was emptied should not assume every transaction has the same cause.

Step 4: The investigation left important gaps

The reported numbers centered on Ethereum. Other networks and token types can be harder to summarize without complete indexing and a reliable wallet list.

A transaction into a suspected destination is strong evidence of movement. It says less about whether a particular individual lost access through the bot.

Some users may have exported their keys to other tools. Others may have approved risky contracts. Both possibilities complicate a simple blame story.

This is why the responsible conclusion is a security warning, not an accusation against a named company or a promise that a single exploit has been proven.

Illustrative on-chain transaction activity panel showing multiple wallet outflows, not actual measured case data

How to Check Whether Your Wallet Was Affected

Start with addresses, not screenshots

Find the exact public address for each LootBot-created or imported wallet you used. Search that address in a reputable explorer for each relevant network.

Look for transfers you did not authorize. Compare their timestamps with your own activity, including any automated farming tasks that were still running.

Transaction hashes are better evidence than a dashboard balance. They show the contract, token, destination, block, and fee recorded on-chain.

The image above is a visual guide to this review, not a measured chart from the incident. Use actual explorer data for decisions.

Separate a key theft from a bad approval

A wallet drained through a malicious token allowance can sometimes be protected by revoking that approval before further assets arrive.

By contrast, a copied private key makes the entire address unsafe. The attacker can sign directly, even after allowances are revoked.

If you cannot distinguish the two confidently, treat the old wallet as compromised. Move anything salvageable to an entirely fresh seed phrase.

Do not paste the old seed phrase into a supposed recovery portal. Many search results and replies to public complaints lead to secondary theft.

Keep a careful record of the scope

Make a small inventory of addresses, networks, balances, unfamiliar transactions, and services that touched each wallet. This reduces frantic repeat checking.

Export transaction links and screenshots from explorers, but do not share private keys or seed phrases with anyone helping you investigate.

If an exchange received stolen assets, record the destination and contact its abuse team through an official channel. Recovery is uncertain, but good records matter.

Do not pay a person who claims they can reverse an Ethereum transfer for an upfront fee. Confirmed transactions are not undone by customer support.

What to Do If You Used a LootBot Wallet

  1. List every related address. Include wallets created for campaigns and any personal wallets you imported. Check Ethereum and other chains you actually used.
  2. Inspect transactions from a trusted explorer. Save hashes for any unexplained outbound transfer. Note the token, amount, destination, and time before drawing conclusions.
  3. Create a clean wallet on a trusted device. Generate a new seed phrase in a reputable wallet or hardware wallet. Do not reuse the exposed phrase or import the old private key.
  4. Transfer remaining assets carefully. Send a small test amount where practical, then move tokens and native coins. Assume the old address is permanently unsafe if its key may have escaped.
  5. Review contract permissions. Revoke suspicious allowances on any other wallet that interacted with questionable sites. This is additional hygiene, not a cure for a copied private key.
  6. Check devices and accounts. If you installed unofficial bot software or entered a seed phrase on a website, scan the device with Malwarebytes and review browser extensions.
  7. Reduce repeat exposure. AdGuard can help block malicious landing pages and ads, but it cannot secure a key already copied. Bookmark legitimate services directly.
  8. Report with evidence, not secrets. Contact the service and any receiving exchange using official channels. Share public transaction links, never your recovery phrase.

What This Incident Says About Bot-Managed Wallets

Automation tools can save time, but wallet ownership deserves its own review. Ask where keys are generated, whether they leave your device, and who can decrypt them.

A written promise that keys are encrypted is not the same as independently verified custody. It also does not tell you what happened during this incident.

Keep experimental wallets small and isolated. Empty them when a campaign ends rather than leaving gas money and tokens in an address you rarely inspect.

For meaningful holdings, use a wallet whose private key never entered a bot. Separate operational convenience from long-term storage.

Be suspicious of any direct message offering a special claims link, emergency migration site, or guaranteed asset recovery. Distress creates a second opening for thieves.

Finally, avoid turning an unresolved investigation into a definitive accusation. Stronger security habits do not depend on knowing the culprit’s name.

Reading the Evidence Without Overreading It

The public blockchain is detailed, but it does not label every wallet with its human owner. Analysts build clusters from transaction behavior and known addresses.

That is why the 557 payer figure is a subset identifiable from the available data. Other LootBot users may not have left the same detectable payment trail.

The 277 swept payer wallets are also not a clean victim total. One person may control multiple wallets, and ownership cannot be inferred from counts alone.

Similarly, 259 ETH reaching a collector is a movement figure. It is not automatically the net loss of a particular platform’s users.

The transfer onward to another address could reflect laundering, consolidation, or another purpose. The chain shows movement, not motive.

These distinctions may feel academic when your own wallet is empty. They matter because false certainty sends people toward the wrong remedy.

If a private key was exposed, spending time revoking allowances on that same address may not stop the next direct transfer.

If only an allowance was abused, a fresh key is still prudent, but reviewing contract interactions can show where the permission came from.

Ask a qualified analyst to review transaction hashes if substantial value is involved. Give them public addresses and signed transaction records, not seed phrases.

Keep the timeline of your own wallet separate from headlines about the wider cluster. Your exposure might have a different cause.

How to Avoid a Second Wallet-Drain Scam

Public complaints attract people offering recovery. Some pretend to be investigators, exchange staff, or wallet support agents.

They may ask you to connect a wallet to a “verification” site. That can create a new approval risk while you are focused on the old incident.

Others request a seed phrase so they can trace stolen coins. A seed phrase is never needed to examine public transfers.

A screenshot of a balance or explorer page is enough for an initial discussion. Redact personal account details that do not help the investigation.

Watch for messages promising that funds are already frozen and can be released after a fee. Blockchain recovery is not a routine support workflow.

Use the official domain for any service you contact. Search ads can imitate help desks just as social media accounts can imitate staff.

If funds moved to a centralized exchange, report the destination and transaction hash through that exchange’s genuine abuse channel.

The exchange may ask for identity documentation or a police report. Submit such information only inside its authenticated support process.

Record each case number and response. Even if recovery is not possible, a clean evidence trail helps prevent duplicate or contradictory reports.

Finally, keep future airdrop activity away from your main holdings. A small operational wallet limits what an unforeseen key failure can expose.

If you are moving several tokens, confirm each one arrived in the new wallet before abandoning the old address. Network selection mistakes are hard to undo.

Write the new recovery phrase offline and verify it before moving significant value. An emergency migration should not create a second preventable loss.

Frequently Asked Questions

Was LootBot itself proven to steal users’ money?

No public evidence cited here identifies the person or group behind the transfers. The on-chain clustering supports a wallet-drain incident, not a proven operator attribution.

How many wallets were affected?

Bitquery identified 2,442 swept Ethereum wallets in its analysis, including 277 with detectable LootBot payment histories. Those are research counts, not a global total.

Does disconnecting LootBot protect an old wallet?

Disconnecting can end an application session, but it does not invalidate a copied private key. A new wallet with a new seed phrase is safer.

Will revoking approvals save the address?

Revoking allowances helps if a malicious contract has spending permission. It cannot prevent direct transactions signed with a stolen private key.

Can the stolen ETH be recovered?

Blockchain transfers are generally irreversible. An exchange or law-enforcement investigation may occasionally trace or freeze funds, but no third party can guarantee recovery.

Should I stop using every airdrop bot?

Not every bot is malicious. Treat key custody as a separate risk, use small dedicated wallets, and avoid storing assets long term in automation wallets.

The Bottom Line

The LootBot-linked wallet drain is a real on-chain security incident. Its public evidence does not establish who obtained the keys or whether the service operator caused it.

If you used a related wallet, focus on what you can verify: your addresses, actual transfers, and a safe move to newly generated keys.

10 Rules to Avoid Online Scams

Here are 10 practical safety rules to help you avoid malware, online shopping scams, crypto scams, and other online fraud. Each tip includes a quick “if you already got hit” action.

  1. Stop and verify before you click, log in, download, or pay.

    warning sign

    Most scams win by creating urgency. Verify using a trusted method: type the website address yourself, use the official app, or call a known number (not the one in the message).

    If you already clicked: close the page, do not enter passwords, and run a malware scan.

  2. Keep your operating system, browser, and apps updated.

    updates guide

    Updates patch security holes used by malware and malicious ads. Turn on automatic updates where possible.

    If you saw a scary “update now” pop-up: close it and update only through your device settings or the official app store.

  3. Use layered protection: antivirus plus an ad blocker.

    shield guide

    Antivirus helps block malware. An ad blocker reduces scam redirects, phishing pages, and malvertising.

    If your browser is acting weird: remove unknown extensions, reset the browser, then run a full scan.

  4. Install apps, software, and extensions only from official sources.

    install guide

    Avoid cracked software, “keygens,” and random downloads. During installs, choose Custom/Advanced and decline bundled offers you do not recognize.

    If you already installed something suspicious: uninstall it, restart, and scan again.

  5. Treat links and attachments as untrusted by default.

    cursor sign

    Phishing often impersonates delivery services, banks, and popular brands. If it is unexpected, do not open attachments or log in through the message.

    If you entered credentials: change the password immediately and enable 2FA.

  6. Shop safely: research the store, then pay with protection.

    trojan horse

    Be cautious with brand-new stores, “closing sale” stories, and prices that make no sense. Prefer credit cards or PayPal for dispute options. Avoid wire transfers, gift cards, and crypto payments.

    If you already paid: contact your card issuer or PayPal quickly to dispute the transaction.

  7. Crypto rule: never pay a “fee” to withdraw or recover money.

    lock sign

    Common patterns include fake profits, then “tax,” “gas,” or “verification” fees. Another is a “recovery agent” who demands upfront crypto.

    If you already sent crypto: stop paying, save evidence (wallet addresses, TXIDs, chats), and report the scam to the platform used.

  8. Secure your accounts with unique passwords and 2FA (start with email).

    lock sign

    Use a password manager and unique passwords for every account. Enable 2FA using an authenticator app when possible.

    If you suspect an account takeover: change passwords, sign out of all devices, and review recent logins and recovery settings.

  9. Back up important files and keep one backup offline.

    backup sign

    Backups protect you from ransomware and device failure. Keep at least one backup on an external drive that is not always connected.

    If you suspect infection: do not connect backup drives until the system is clean.

  10. If you think you are a victim: stop losses, document evidence, and escalate fast.

    warning sign

    Move quickly. Speed matters for disputes, account recovery, and limiting damage.

    • Stop payments and contact: do not send more money or respond to the scammer.
    • Call your bank or card issuer: block transactions, replace the card if needed, and start a dispute or chargeback.
    • Secure your email first: change the email password, enable 2FA, and remove unfamiliar recovery options.
    • Secure other accounts: change passwords, enable 2FA, and log out of all sessions.
    • Scan your device: remove suspicious apps or extensions, then run a full malware scan.
    • Save evidence: screenshots, emails, order pages, tracking pages, wallet addresses, TXIDs, and chat logs.
    • Report it: to the payment provider, marketplace, social platform, exchange, or wallet service involved.

These rules are intentionally simple. Most online losses happen when decisions are rushed. Slow down, verify independently, and use payment methods and account controls that give you recourse.

Comment on this post

Previous

Flare Voting Rewards Scam Exposed: The Fake FLR Vote That Drains Wallets

Next

Bank Card Pickup Scam: Fake Fraud Calls Send a Courier to Your Front Door