On-chain monitoring flagged a coordinated drain of more than 600 wallets suspected of links to GoMining, the Bitcoin mining and rewards platform, with combined losses of approximately $2.8 million. The platform has not confirmed the incident, and the connection between the drained addresses and the company remains on-chain inference rather than official attribution.

The cluster was first flagged on September 4 by on-chain monitor Specter, according to reports from CoinGape and Coin Gabbar. Attackers moved quickly, swapping stolen tokens and bridging them across multiple networks before consolidating the proceeds into roughly 1,147 ETH — a laundering pattern that has become the standard exit route in this year's cluster exploits.

One Tagged Wallet Carried Almost the Entire Loss

The bulk of the damage came from a single service address tagged on-chain as belonging to GoMining, which lost approximately $2.79 million — nearly the whole haul in one transaction sequence. The flagged destination address, reported as 0xa73…4704, has been identified by trackers as the consolidation point of the initial drain.

The remaining losses were spread across the 600-plus other addresses. Most of those wallets share a history of holding GMT, GoMining's native token for mining allocation and ecosystem access, which is what allowed analysts to cluster them together. Holding GMT alone does not confirm platform affiliation for every address, and no company statement has established whether the affected wallets were user self-custody accounts, platform infrastructure, or both.

Bitget Suspends GOMINING Transfers

Exchange Bitget suspended GOMINING deposits and withdrawals against ETH on September 5 at 07:28 UTC+8, citing "wallet maintenance." The exchange did not connect the suspension to the drain, but the timing is consistent with containment measures exchanges apply while investigating wallet-side incidents. A GoMining ambassador account separately claimed on X that withdrawals were blocked and the GMT token had sold off — community commentary, not official guidance.

GoMining had not issued a public statement on the incident at the time of writing. Until it does, the episode remains an unconfirmed operational risk: a suspected compromise visible on-chain, with no root cause, victim accounting, or remediation plan published.

The 2026 Cluster-Drain Pattern Repeats

The incident fits a familiar 2026 sequence. Earlier this year, a mystery exploit drained hundreds of EVM wallets in a similarly coordinated sweep, and Humanity Protocol suffered a private-key compromise that triggered a sharp token crash. In each case, attackers consolidated stolen assets across swaps and bridges into ETH as rapidly as possible, slowing attribution while leaving a trail that analytics firms can still follow.

For users of platforms whose wallets carry a recognizable on-chain footprint — a tagged service address, a native-token holding history — the GoMining case is a reminder that clustering cuts both ways: the same heuristics investigators use to trace attackers can identify concentrated groups of victim wallets.

Affected users should watch for targeted phishing referencing the incident, rotate credentials tied to any GoMining-linked accounts, and treat any "compensation" offer arriving by direct message as fraudulent until proven otherwise through official channels.

TrustGrade tracks the security posture of platforms, protocols, and exchanges. Verified, registry-backed security scoring arrives with TrustGrade Code Scoring in December 2026.