Victim Loses $800K in Airdrop Scam Amid EigenLayer X Account Hack

Airdrop eigenlayer Hack
The EigenLayer-fronted airdrop scam campaign is still ongoing, despite intervention attempts.
Last updated:
Junior Content Creator
Junior Content Creator
Harvey Hunter
About Author

Harvey Hunter is a Junior Content Creator at Cryptonews.com. With a background in Computer Science, IT, and Mathematics, he seamlessly transitioned from tech geek to crypto journalist.

Last updated:
Why Trust Cryptonews
Cryptonews has covered the cryptocurrency industry topics since 2017, aiming to provide informative insights to our readers. Our journalists and analysts have extensive experience in market analysis and blockchain technologies. We strive to maintain high editorial standards, focusing on factual accuracy and balanced reporting across all areas - from cryptocurrencies and blockchain projects to industry events, products, and technological developments. Our ongoing presence in the industry reflects our commitment to delivering relevant information in the evolving world of digital assets. Read more about Cryptonews

EigenLayer’s X account, the second-biggest protocol on Ethereum, was hacked on October 18 to front an airdrop scam. One victim’s wallet was drained of over $800,000 in crypto.

In an X post, EigenLayer Labs highlighted an ongoing compromise of the “@EigenLayer” account handle.

Pseudonymous on-chain investigator ZachXBT initially warned users about the malicious airdrop link, cautioning them not to interact with any links in a Telegram post.

Security analyst Scam Sniffer reported that the scam apparently fleeced at least one unsuspecting victim out of at least $800,000 in cryptocurrencies.

While no account recovery has been reportedso far, the fraudulent posts are actively being taken down.

EigenLayer Hacker Runs Airdrop Scam Campaign

Despite intervention attempts, the account continues to post malicious links, urging users to engage with “reminders” and “final calls” for the supposed reallocation of EIGEN tokens from EigenLayer’s Season 2 airdrop.

The claim period for Season 2 of EigenLayer’s stakeholder airdrop ended last month, however.

The hacker’s X posts are almost indistinguishable from EigenLayer’s typical post format, even tying themselves into threads containing fake EigenLayer blog entries to mask the scheme.

Fraudulent airdrop scam post. Source: EigenLayer / X.
Fraudulent Airdrop Scam Post. Source: EigenLayer / X.

However, ZachXBT noted a key differentiator: EigenLayer’s official blog URL is “blog.eigenlayer.xyz,” whereas the malicious link redirects users to “blog.eigenfoundation.org.”

Upon arrival, the scam site prompts users to enter the supposed airdrop and connect their wallet address to “claim EIGEN.”

This is a common tactic among scammers: tricking users into handing over account access to run a wallet drainer scam, which cleans any connected wallets of their cryptocurrencies.

Exploring further, users can navigate a close recreation of the EigenLayer website and various blog posts, all funneling back to the airdrop scam in an elaborate rouse.

Fraudulent blog posts. Source: blog.eigenlayer.xyz.

EigenLayer has advised users to be cautious and double-check URLs, noting that they would provide further updates once the account is secured.

In the cryptocurrency industry, hacking verified social media accounts to promote fraudulent websites or scam coins is a common practice. It’s crucial to stay vigilant against such attacks.

EigenLayer Becomes Prime Scam Target

This attack adds to what seems to be a pattern as EigenLayer becomes a ripe target for scammers, marking the second compromise since the beginning of October.

In an October 4 X post, the EigenLayer team highlighted an investigation concerning “unapproved selling activity” from a wallet address. The address in question sold about 1.6 million $EIGEN tokens, worth approximately $5.7 million.

The following day, EigenLayer posted a community update crediting the incident to a hack. They revealed that a malicious attacker compromised an email thread involving an investor’s token transfer into custody.

While tokens were stolen through a hack, the EigenLayer team assured the community that the hack was an “isolated” incident and did not affect its broader ecosystem.

They emphasized that the compromise was unrelated to any on-chain functionality and added that there is no known vulnerability in the protocol or token contracts.

More Articles

Blockchain News
SEC to Host 4 Additional Crypto Roundtables as Regulatory Approach Shifts
Julia Smith
Julia Smith
2025-03-26 20:30:29
Press Releases
The Next Evolution of the Pepe Meme Coin: MIND of Pepe – A Crypto AI Token with 100x Potential?
2025-03-26 19:35:35
Crypto News in numbers
editors
Authors List + 66 More
2M+
Active Monthly Users Around the World
250+
Guides and Reviews Articles
8
Years on the Market
70
International Team Authors