Some LootBot users opened old farming wallets in September and found the balances gone. The transactions were real, but the explanation was not immediately clear.
That uncertainty matters. If you used a bot-created wallet, the useful question now is what its history can tell you, and what you can still protect.

Overview
What investigators could see on-chain
On-chain researcher Bitquery examined a cluster of Ethereum wallets swept in early September 2026. Its report identified 2,442 wallets in the observed set.
Of those, 557 had a detectable history of payments associated with LootBot. Bitquery found that 277 of those payer wallets appeared in the swept group.
The destination collected about 259 ETH before most of that value moved onward. These figures describe a particular analysis at a particular time.
They do not establish a total across every network or every user. Nor does a matching transaction history, on its own, identify whoever controlled the receiving wallet.
Why old bot wallets can remain exposed
LootBot helped users automate airdrop-related activity with wallets created for the service. According to its documentation, private keys were stored encrypted and available to users.
That design creates a simple but uncomfortable question: could anyone besides the owner obtain a usable key, directly or through a security failure?
A private key is not a login session you can revoke after the fact. A copied key can sign transactions whenever funds remain at its address.
The illustration above shows the kind of dashboard a worried user might revisit. It is not a screenshot of a specific victim account.
What remains unproven
The public on-chain record shows transfers. It does not prove who acquired the keys, how they were obtained, or whether the service operator was involved.
That distinction keeps this from being a fair claim that LootBot itself was a scam. It is a documented wallet-drain incident with unresolved attribution.
For someone deciding what to do next, the practical points are narrower:
- Identify every wallet generated or imported through the bot.
- Check each address on the correct chain, not just the Ethereum mainnet view.
- Move remaining assets to a newly created wallet with a fresh key.
- Preserve transaction links and account records before closing anything.
How the LootBot Wallet Drain Unfolded
Step 1: Users created wallets for airdrop farming
Airdrop farmers often separate experimental activity from their main savings. A bot-created wallet can make that process feel convenient, especially across many campaigns.
That convenience changes the trust arrangement. The wallet may be yours in the sense that you can export its key, but creation and storage involved another system.
Many users also leave a little ETH in these wallets for gas. Months later, a forgotten wallet may still hold tokens, native coins, or claim rights.
A wallet with no visible balance on one app may still contain assets on another network. That is why a narrow dashboard check can miss exposure.
Step 2: Key custody created a lasting risk
LootBot’s published description said the service held encrypted private keys. Encryption is meaningful protection, but it does not make an exposed key impossible.
The public evidence does not show whether keys were leaked, decrypted, phished from users, or accessed through some other route.
What matters operationally is that the address can be controlled by anyone with its private key. A website logout cannot change the address’s cryptographic owner.
Revoking a token approval is useful for allowance-based attacks, but it cannot stop a thief who already possesses the wallet’s signing key.
Step 3: Many wallets were swept toward common destinations
Bitquery traced transfers from the affected addresses into a collecting address. A large portion of the ETH then moved again to another address.
A chain of transfers can reveal timing, routing, and value. It is not a photograph of the person pressing the buttons.
Researchers also found that some identified LootBot payers were not among the wallets swept. That means exposure was not uniform across the observed payer group.
Someone whose wallet was untouched should not assume it is safe forever. Someone whose wallet was emptied should not assume every transaction has the same cause.
Step 4: The investigation left important gaps
The reported numbers centered on Ethereum. Other networks and token types can be harder to summarize without complete indexing and a reliable wallet list.
A transaction into a suspected destination is strong evidence of movement. It says less about whether a particular individual lost access through the bot.
Some users may have exported their keys to other tools. Others may have approved risky contracts. Both possibilities complicate a simple blame story.
This is why the responsible conclusion is a security warning, not an accusation against a named company or a promise that a single exploit has been proven.

How to Check Whether Your Wallet Was Affected
Start with addresses, not screenshots
Find the exact public address for each LootBot-created or imported wallet you used. Search that address in a reputable explorer for each relevant network.
Look for transfers you did not authorize. Compare their timestamps with your own activity, including any automated farming tasks that were still running.
Transaction hashes are better evidence than a dashboard balance. They show the contract, token, destination, block, and fee recorded on-chain.
The image above is a visual guide to this review, not a measured chart from the incident. Use actual explorer data for decisions.
Separate a key theft from a bad approval
A wallet drained through a malicious token allowance can sometimes be protected by revoking that approval before further assets arrive.
By contrast, a copied private key makes the entire address unsafe. The attacker can sign directly, even after allowances are revoked.
If you cannot distinguish the two confidently, treat the old wallet as compromised. Move anything salvageable to an entirely fresh seed phrase.
Do not paste the old seed phrase into a supposed recovery portal. Many search results and replies to public complaints lead to secondary theft.
Keep a careful record of the scope
Make a small inventory of addresses, networks, balances, unfamiliar transactions, and services that touched each wallet. This reduces frantic repeat checking.
Export transaction links and screenshots from explorers, but do not share private keys or seed phrases with anyone helping you investigate.
If an exchange received stolen assets, record the destination and contact its abuse team through an official channel. Recovery is uncertain, but good records matter.
Do not pay a person who claims they can reverse an Ethereum transfer for an upfront fee. Confirmed transactions are not undone by customer support.
What to Do If You Used a LootBot Wallet
- List every related address. Include wallets created for campaigns and any personal wallets you imported. Check Ethereum and other chains you actually used.
- Inspect transactions from a trusted explorer. Save hashes for any unexplained outbound transfer. Note the token, amount, destination, and time before drawing conclusions.
- Create a clean wallet on a trusted device. Generate a new seed phrase in a reputable wallet or hardware wallet. Do not reuse the exposed phrase or import the old private key.
- Transfer remaining assets carefully. Send a small test amount where practical, then move tokens and native coins. Assume the old address is permanently unsafe if its key may have escaped.
- Review contract permissions. Revoke suspicious allowances on any other wallet that interacted with questionable sites. This is additional hygiene, not a cure for a copied private key.
- Check devices and accounts. If you installed unofficial bot software or entered a seed phrase on a website, scan the device with Malwarebytes and review browser extensions.
- Reduce repeat exposure. AdGuard can help block malicious landing pages and ads, but it cannot secure a key already copied. Bookmark legitimate services directly.
- Report with evidence, not secrets. Contact the service and any receiving exchange using official channels. Share public transaction links, never your recovery phrase.
What This Incident Says About Bot-Managed Wallets
Automation tools can save time, but wallet ownership deserves its own review. Ask where keys are generated, whether they leave your device, and who can decrypt them.
A written promise that keys are encrypted is not the same as independently verified custody. It also does not tell you what happened during this incident.
Keep experimental wallets small and isolated. Empty them when a campaign ends rather than leaving gas money and tokens in an address you rarely inspect.
For meaningful holdings, use a wallet whose private key never entered a bot. Separate operational convenience from long-term storage.
Be suspicious of any direct message offering a special claims link, emergency migration site, or guaranteed asset recovery. Distress creates a second opening for thieves.
Finally, avoid turning an unresolved investigation into a definitive accusation. Stronger security habits do not depend on knowing the culprit’s name.
Reading the Evidence Without Overreading It
The public blockchain is detailed, but it does not label every wallet with its human owner. Analysts build clusters from transaction behavior and known addresses.
That is why the 557 payer figure is a subset identifiable from the available data. Other LootBot users may not have left the same detectable payment trail.
The 277 swept payer wallets are also not a clean victim total. One person may control multiple wallets, and ownership cannot be inferred from counts alone.
Similarly, 259 ETH reaching a collector is a movement figure. It is not automatically the net loss of a particular platform’s users.
The transfer onward to another address could reflect laundering, consolidation, or another purpose. The chain shows movement, not motive.
These distinctions may feel academic when your own wallet is empty. They matter because false certainty sends people toward the wrong remedy.
If a private key was exposed, spending time revoking allowances on that same address may not stop the next direct transfer.
If only an allowance was abused, a fresh key is still prudent, but reviewing contract interactions can show where the permission came from.
Ask a qualified analyst to review transaction hashes if substantial value is involved. Give them public addresses and signed transaction records, not seed phrases.
Keep the timeline of your own wallet separate from headlines about the wider cluster. Your exposure might have a different cause.
How to Avoid a Second Wallet-Drain Scam
Public complaints attract people offering recovery. Some pretend to be investigators, exchange staff, or wallet support agents.
They may ask you to connect a wallet to a “verification” site. That can create a new approval risk while you are focused on the old incident.
Others request a seed phrase so they can trace stolen coins. A seed phrase is never needed to examine public transfers.
A screenshot of a balance or explorer page is enough for an initial discussion. Redact personal account details that do not help the investigation.
Watch for messages promising that funds are already frozen and can be released after a fee. Blockchain recovery is not a routine support workflow.
Use the official domain for any service you contact. Search ads can imitate help desks just as social media accounts can imitate staff.
If funds moved to a centralized exchange, report the destination and transaction hash through that exchange’s genuine abuse channel.
The exchange may ask for identity documentation or a police report. Submit such information only inside its authenticated support process.
Record each case number and response. Even if recovery is not possible, a clean evidence trail helps prevent duplicate or contradictory reports.
Finally, keep future airdrop activity away from your main holdings. A small operational wallet limits what an unforeseen key failure can expose.
If you are moving several tokens, confirm each one arrived in the new wallet before abandoning the old address. Network selection mistakes are hard to undo.
Write the new recovery phrase offline and verify it before moving significant value. An emergency migration should not create a second preventable loss.
Frequently Asked Questions
Was LootBot itself proven to steal users’ money?
No public evidence cited here identifies the person or group behind the transfers. The on-chain clustering supports a wallet-drain incident, not a proven operator attribution.
How many wallets were affected?
Bitquery identified 2,442 swept Ethereum wallets in its analysis, including 277 with detectable LootBot payment histories. Those are research counts, not a global total.
Does disconnecting LootBot protect an old wallet?
Disconnecting can end an application session, but it does not invalidate a copied private key. A new wallet with a new seed phrase is safer.
Will revoking approvals save the address?
Revoking allowances helps if a malicious contract has spending permission. It cannot prevent direct transactions signed with a stolen private key.
Can the stolen ETH be recovered?
Blockchain transfers are generally irreversible. An exchange or law-enforcement investigation may occasionally trace or freeze funds, but no third party can guarantee recovery.
Should I stop using every airdrop bot?
Not every bot is malicious. Treat key custody as a separate risk, use small dedicated wallets, and avoid storing assets long term in automation wallets.
The Bottom Line
The LootBot-linked wallet drain is a real on-chain security incident. Its public evidence does not establish who obtained the keys or whether the service operator caused it.
If you used a related wallet, focus on what you can verify: your addresses, actual transfers, and a safe move to newly generated keys.