CAT: Hack / Wallet Drainer · REPORTED 17 September 2026

0x27BF94251be3e2B1275629A399037Aa2321eE98F scam

A hack / wallet drainer scam report.

Narrative evidence

What happened

A hack / wallet drainer scam involving cryptocurrency was reported on 17 September 2026. **Incident Type:** Cryptocurrency wallet compromise / Unauthorized transfer of digital assets **Blockchain:** Ethereum Mainnet **Victim Wallet:** 0x27BF94251be3e2B1275629A399037Aa2321eE98F **Suspected Attacker Wallet:** 0x8a75DB261FFeeE40ac53195E43a9dB4CEc9617E6 ### Summary My Ethereum wallet was compromised without my authorization. Digital assets were transferred from my wallet to an address that I believe is controlled by the attacker. The affected wallet contained ERC-20 tokens, including K9 Finance (KNINE). I did not authorize the unauthorized transfers. After the compromise, I attempted to send a very small amount of ETH to the affected wallet in order to pay the gas fee for transferring the remaining KNINE tokens to another wallet that I control. The ETH was automatically transferred out of the compromised wallet shortly after it arrived, indicating that the wallet may still be actively monitored by an automated process or attacker-controlled bot. ### Remaining Asset The compromised wallet currently contains/contained approximately: **42,223,222 KNINE** Token contract: **0x91fbb2503ac69702061f1ac6885759fc853e6eae** I have not intentionally authorized the attacker to access or transfer these assets. ### Known Attacker Address The address currently believed to be associated with the unauthorized transfers is: **0x8a75DB261FFeeE40ac53195E43a9dB4CEc9617E6** One of the transactions I identified shows approximately: **0.0000112842319976 ETH** being transferred from the compromised wallet to the suspected attacker address: **Transaction Hash:** 0x1ff0865f541825e59713d253bb60b0b536de85c1c225bf5d5afa8709689fa53e The transaction was confirmed on Ethereum Mainnet. ### Suspected Cause I had not intentionally connected this wallet to a decentralized application for several months before the incident. Shortly before the compromise, on **September 5, 2026**, I installed a Chrome extension called **"Doblaj"**. My wallet was compromised on approximately **September 7, 2026**. I cannot independently confirm that Doblaj caused the compromise, so I am reporting this only as a possible lead for investigation. I have since removed the browser extensions that were installed at the time of the incident. ### Important Evidence I can provide: - Ethereum transaction hashes - Victim wallet address - Suspected attacker address - Token contract address - Screenshots from MetaMask - Timeline of the unauthorized transfers - Information regarding the browser extension installed shortly before the incident - Evidence showing that ETH deposited into the compromised wallet was subsequently transferred away without my authorization ### Request I am requesting that this address and the associated transactions be investigated and flagged as potentially related to an unauthorized cryptocurrency theft. If possible, I would also appreciate information regarding: 1. Whether the suspected attacker address has previously been reported. 2. Whether the stolen assets have been transferred to a known centralized exchange or other identifiable service. 3. Whether the transaction trail can be associated with other known scam/theft addresses. 4. Whether this case can be escalated or made available to appropriate law-enforcement investigators if the funds eventually reach an identifiable service. I understand that blockchain transactions are generally irreversible. My objective is to document the theft, identify the movement of the stolen assets, and maximize the possibility of recovery or intervention if the funds reach a regulated or identifiable entity. I confirm that the unauthorized transactions described above were not initiated or authorized by me. Wallet addresses linked to this report: ethereum: 0x27BF94251be3e2B1275629A399037Aa2321eE98F, 0x8a75DB261FFeeE40ac53195E43a9dB4CEc9617E6, 0x91fbb2503ac69702061f1ac6885759fc853e6eae Do not send money or cryptocurrency to anyone connected to this report. If you have already paid, contact your bank or exchange and report the incident to your national fraud authority.

Community warning

How to protect yourself from hack / wallet drainer scams

  • Never send money, gift cards or crypto to anyone you have not independently verified.
  • Search the business name, website, email and phone number here before paying.
  • Be wary of urgency, secrecy, upfront fees and “too good to be true” prices.
  • If you have paid, contact your bank or card issuer immediately to dispute the charge.
  • Report to Action Fraud (UK), the FTC (US) or your national authority, and add your occurrence above.

Community comments (0)

Have you dealt with this business? Share what you know to help others.

  • No comments yet. Be the first to add context to this report.

More hack / wallet drainer scams

View category

Seen something suspicious?

REPORT A SCAM

scam-i.uk

A free, public scam intelligence database. Search, browse and report fraud to protect others.

Disclaimer: scam-i.uk is an informational resource that aggregates and republishes user-submitted and publicly available scam reports. Reports reflect the personal experiences and opinions of the individuals who submitted them and have not been independently verified by scam-i.uk. Inclusion of a business, website, email address, phone number or individual in this database does not constitute an accusation, finding or determination of wrongdoing by scam-i.uk. Nothing on this site is legal, financial or professional advice. If you believe you are the victim of fraud, contact your bank, local police and the relevant national reporting body (e.g. Action Fraud in the UK or the FTC in the US). See our full Disclaimer, Terms of Service and Privacy Policy.

© 2026 scam-i.uk · All rights reserved