Security · Unconfirmed
The Wallets Emptied. The Company Has Said Nothing
More than 600 wallets were drained on Friday and the proceeds now sit in one address holding 1,147 ETH. All of that is verifiable on-chain. Whose money it was, and how it left, is not — and GoMining has not said a word.
On Friday, the on-chain monitoring account Specter flagged a coordinated drain: more than 600 Ethereum wallets emptied in a short window, the proceeds swapped, bridged across several chains, and consolidated into a single address. CoinGape reported the combined loss at roughly $2.8 million, with about $2.79 million of it coming from one service address tagged on-chain as belonging to GoMining, a bitcoin mining-as-a-service platform.
That is a serious allegation, and the honest way to handle it is to separate what a stranger can verify from what is currently being inferred. So we checked the address.
What the chain actually shows
The destination wallet is 0xa7372Fa49da5e52cf31f35cCE517C4768FeD4704. As of Saturday it held 1,147.942342439328546979 ETH — $2,818,806.86 at the $2,455.53 price Etherscan was quoting at the time. That figure matches the reported haul closely enough to treat the address identification as sound.
Three further details from the overview are worth stating, because they are checkable and nobody has published them.
First, the address is new. Etherscan shows it funded roughly 21 hours before we looked, by 0x240cDA79…B5519D2FF, with its first outbound transaction about an hour later. This is not a long-lived wallet that happened to receive stolen funds; it was stood up for the occasion and then did a great deal of work very quickly.
Second, the inbound flow includes transfers routed through NEAR Intents, a cross-chain settlement layer. That is independent corroboration of the "swapped and bridged across multiple chains" description in the original report — you can see the cross-chain leg arrive rather than take it on faith.
Third, and most interesting: Etherscan lists the address as an authority "Delegated to: MetaMask: EIP-7702 Delegator." In plain terms, the attacker's collection wallet is running as a smart account under EIP-7702, the upgrade that lets an ordinary Ethereum address temporarily execute contract code. That is a useful thing to have if you need to batch hundreds of token transfers efficiently.
It is also, we should say clearly, not evidence of how the victims were drained. EIP-7702 has been abused in exactly that direction this year — tricking a user into signing a delegation that authorises a sweeper contract against their own account — and it would be easy, and wrong, to slide from "the attacker's wallet uses 7702" to "the victims were 7702-phished." The delegation we can see is on the destination, not the sources. It tells you something about the attacker's tooling and nothing yet about the entry point.
Established, and not
| Claim | Status | Basis |
|---|---|---|
| ~1,147 ETH sits in one new address | Verified | Etherscan, checked Sep 5 |
| Funds arrived cross-chain | Verified | Inbound via NEAR Intents |
| 600+ wallets drained in one operation | Reported | Specter, via CoinGape |
| The victims are GoMining users | Inferred | Shared GMT holding history — clustering, not proof |
| GoMining itself was breached | Unestablished | No statement from the company |
| How the wallets were compromised | Unknown | No post-mortem, no forensic report |
The link to GoMining is a cluster, not a confession
Here is the weak joint in the story, and both outlets covering it were careful to say so. The 600-plus drained wallets were associated with GoMining because most of them had previously held GMT, the platform's token. CoinGabbar's write-up states the caveat directly: the connection rests on on-chain clues rather than a confirmed forensic report, and holding GMT alone does not establish platform affiliation for every address.
That caveat is doing more work than it looks. "These wallets all held the same token" is compatible with a platform breach. It is equally compatible with a phishing campaign that targeted a token's holder list — which is a public list, on a public chain, available to anyone who wants to build one. Those two scenarios have very different implications for anyone still holding funds on the platform, and the available evidence does not distinguish between them.
What has happened instead is that the gap has been filled by everyone except the company. CoinGape reports that Bitget suspended GOMINING deposits and withdrawals on its Ethereum network on September 5, citing "wallet maintenance" — a phrase that is either routine or the most conspicuous euphemism of the week, and readers have no way to tell which. A GoMining ambassador account posted on X that withdrawals were blocked and that GMT had sold off, arguing the platform was large enough to absorb the hit. That is community color from an affiliated account, not guidance, and it should not be read as one.
Silence is a decision
It has now been more than a day. GoMining has not confirmed an incident, denied one, told users whether to move funds, or said whether the tagged service wallet was in fact theirs.
There are legitimate reasons a company goes quiet after an event like this. Incident response is genuinely chaotic in the first hours; saying "we were hacked" before you know that is its own kind of harm; lawyers and insurers get a vote. This desk has argued before, over the Aquifer exploit, that a company attaching a confident root-cause label to something it does not yet understand is worse than one that admits it is still looking.
But the space between those two positions is not empty, and that is what is being missed here. "We are aware of reports, we are investigating, here is what users should do in the meantime" costs nothing, commits to no root cause, and is the single most useful thing a platform can publish while it still knows nothing. Its absence does not tell us the company was breached. It tells us that the people best placed to say whether users should be worried have chosen, so far, not to.
Meanwhile the money is not hiding. It is sitting in one address, in the open, doing nothing — 1,147 ETH that anyone can watch, waiting for its next move.
The Take
Read the modality in these stories, because it is where the meaning lives. "A wallet tagged as GoMining lost $2.79 million" is verifiable and we verified it. "GoMining was hacked" is a different sentence, and as of this writing nobody — not Specter, not CoinGape, not this desk — is in a position to write it. The distinction is not pedantry when a token's price and thousands of people's decisions about whether to withdraw are riding on it. If you hold assets on the platform, the absence of an official statement is itself the operative fact: act on your own risk tolerance rather than waiting to be told, and be aware that a drain of publicly-listed token holders is exactly the moment when "support" will contact you with a recovery offer. It will not be support.