CryptoReal
CASE FILE — Oct 31, 2023

New Router Contract Lets Attackers Drain Unibot Users for $640K

Users of the Telegram trading bot Unibot woke up on October 31, 2023 to reports that a newly deployed router contract had been exploited, draining at least $640,000 from wallets that had granted the contract token approvals.

Security firm Peckshield flagged the activity first. About an hour later, the Unibot team responded, saying the router had been paused and framing the situation as contained:

We experienced a token approval exploit from our new router and have paused our router to contain the issue.

Any funds lost due to the bug on our new router will be compensated. Your keys and wallets are safe.

That reassurance proved premature. Copycat attackers deployed cloned versions of the exploit contract and kept draining funds (more reports) even after the official statement went out, since any wallet that had approved the new router remained exposed regardless of the pause. Critics questioned why users weren't immediately told to revoke their approvals rather than being told the issue was handled.

01How the exploit worked

The router in question — deployed the previous Saturday and never verified on Etherscan — contained a flaw letting an attacker insert an unauthorized transferFrom() call, pulling approved tokens straight out of user wallets. Anyone who had granted the router an approval and had not revoked it was at risk.

Analysts at BlockSec pointed to the likely root cause:

Sums referenced in this case file

As the code is not open-sourced, we suspect that there is a lack of input validation of the function 0xb2bd16ab in the 0x126c contract, which allows an arbitrary call. Therefore, an attacker could invoke 'transferFrom' to transfer out tokens approved to the contract.

Beosin published a diagram breaking down the vulnerable code.

The address tied to the original attacker is 0x413e4fb75c300b92fec12d7c44e4c0b4faab4d04, which moved 355 ETH (about $640,000) into Tornado Cash and then went quiet. Copycat exploiters using cloned contracts kept the attack going afterward. An example transaction shows the mechanism in action.

Affected users are advised to revoke approvals for the router contract at 0x126c9FbaB3A2FCA24eDfd17322E71a5e36E91865.

02A familiar pattern

The mechanics here mirror an incident that hit Maestro, another Telegram trading bot, for roughly $500,000 the week before. Maestro's response at the time was fast and transparent, and the team even refunded users beyond their actual losses. Given how similar the Unibot exploit is, it is notable that the team apparently didn't audit its new router for the same class of bug in the aftermath of Maestro's incident.

Some statements from the Unibot team afterward appeared to downplay the severity, which may have contributed to additional losses as copycat contracts continued operating. Trading volume tied to the incident suggests any promised refunds could carry a meaningful price tag. One reaction summed up the mood succinctly.

03The broader lesson

Telegram trading bots, much like the SocialFi projects that boomed and then imploded, tend to trade security for convenience. No private keys were compromised in this case, but handing a closed-source project standing approval over your wallet carries exactly the kind of risk users are regularly cautioned about. Alongside recent incidents at LastPass and StarsArena, this episode is another reminder that convenience-driven UX choices can come with a real cost. Whether the lesson sticks is another question.

Trading botUnibot
Investigation alerts

Get new scam files the moment we publish them — usually 2–3 emails a week.

Enter a valid email address.

No spam, unsubscribe anytime. We never sell your data. Crypto assets are volatile and high-risk; nothing here is financial advice.

You're on the list. Watch your inbox for the next scam file.