SIGMA Bot
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·3MXXjk…qh4VSummary
SIGMA is a multi-chain Telegram trading bot operating at sigma.win that supports Ethereum, BSC, Base, Solana, Avalanche, and other networks. On May 11, 2026, a crypto trader known as Unihax0r suffered a private key compromise draining over $200,000 across Ethereum, Base, and BSC, with both affected wallets traceable exclusively to SIGMA's wallet generation infrastructure. SIGMA has published no post-mortem, security advisory, or public statement in response to the incident as of late May 2026.
Connected Entities
1 entitiesTimeline(7 events)
19 September 2024
Banana Gun Telegram bot exploited via Telegram message oracle vulnerability; approximately $3 million drained from 11 users. Bot issued post-mortem and reimbursed all affected users — establishing an industry precedent SIGMA has not followed.
CoinTelegraph13 January 2026
Polycule, a Telegram trading bot on Polymarket, hacked for approximately $230,000.
KuCoin News11 May 2026
Between 00:37 and 00:56 UTC, attacker drains over $200,000 from two wallets belonging to trader Unihax0r across Ethereum, Base, and BSC. Both wallets were created exclusively through SIGMA. Attack confirmed as private key compromise, not a smart contract exploit.
CryptoTimes11 May 2026
At 01:53 UTC, Unihax0r posts publicly on X: 'Just got drained or hacked for more than 200k. Sick to my stomach.' Shares attacker wallet address 0xF7cFFC27732a5C9c4E2D592F3E33435F8dDb019A.
CryptoTimes11 May 2026
On-chain analyst @k0braca1 publicly states the attack bears hallmarks of private key leakage with full signing control across chains, ruling out malicious approvals.
Crypto Economy11 May 2026
Multiple crypto news outlets including CryptoTimes, CryptoNews.net, MEXC News, Crypto Economy, and Cryptopolitan publish coverage of the incident, all noting SIGMA's silence.
CryptoNews.net31 May 2026
As of this date, SIGMA has issued no public statement, post-mortem, security advisory, or acknowledgment of the incident across any documented channel.
AVOID.NET investigation (confirmed via multi-source search)Decision Log
- hash: AoAfWrWcUXYgHmhE1yZUEJAAgvCVBKNveYAMqgD2M9QF
- hash: 5cqsq8jj3LAE6deCKKRVLoLDyw5Qz9ThktLKaosZJ3jH
- hash: 9rkTMqm9zieC8JWeQupVzvuuF2LVDHqkhF7jiHVKjFt8
- hash: 5K2WrNSfubmDYqyJeiHh4bTvRFZRMQMYonGPDgvnnjaY
- hash: DwvzD63fFvEbTy3bNcn9FunuFmLSZDUkU2G3yK4ECouR
- hash: APJCQM25i9d2ZeYAe6A6wgxccELVFGy3esaC3T82LU74
- hash: 7qRa75rKDFqh62zuUu6rYCFsMgcTQmX5o1sZhsi4xzDo
This investigation is cryptographically anchored to the Solana blockchain (7 events). 16 of 18 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 5/31/2026, 7:24:48 AM
last updated: 7/27/2026, 4:51:31 PM
avoid.net — verified advice for a post-truth world