Bitget App
Trade smarter
Buy cryptoMarketsTradeFuturesEarnSquareMore
Bitcoin bots drain compromised wallet in RBF fee war

Bitcoin bots drain compromised wallet in RBF fee war

CointelegraphCointelegraph2026/01/17 21:45
By:Cointelegraph

Greedy bots have launched an RBF transaction war over Bitcoin sent to a compromised wallet, according to a post from X.

The bots tried to empty the wallet after it detected the deposited funds. The compromised wallet’s private key is a transaction identifier (txid). Specifically, it’s the coinbase txid of block 924,982.

Bots exploit exposed private key

On-chain data shows that Bitcoin bots drained funds from the compromised wallet within minutes.

The SegWit wallet received 0.00020305 BTC through two transactions. However, it ended up with a zero balance and no unspent outputs left. Every incoming BTC transfer was quickly spent by bots.

The first transaction sent 0.00018209 BTC to the address. At the same timestamp, the funds were spent out in a separate transaction with a fee rate of 12.8 sat/vB. The spending speed indicates an automated sweep.

The second deposit added 0.00002096 BTC. The funds were again removed almost immediately. The bot paid 4.80 sat/vB then sent 0.00001572 BTC to an external address.

Bots continuously monitor Bitcoin’s mempool for deposits sent to wallets derived from weak or publicly known private keys. A bitcoin mempool is a waiting area for unconfirmed transactions.

Once funds appear, the bots already control the private key and can instantly sign withdrawal transactions.

.uce132e2d61fe10773a1d55fd7b1e70ce { padding:0px; margin: 0; padding-top:1em!important; padding-bottom:1em!important; width:100%; display: block; font-weight:bold; background-color:#eaeaea; border:0!important; border-left:4px solid #3498DB!important; box-shadow: 0 1px 2px rgba(0, 0, 0, 0.17); -moz-box-shadow: 0 1px 2px rgba(0, 0, 0, 0.17); -o-box-shadow: 0 1px 2px rgba(0, 0, 0, 0.17); -webkit-box-shadow: 0 1px 2px rgba(0, 0, 0, 0.17); text-decoration:none; } .uce132e2d61fe10773a1d55fd7b1e70ce:active, .uce132e2d61fe10773a1d55fd7b1e70ce:hover { opacity: 1; transition: opacity 250ms; webkit-transition: opacity 250ms; text-decoration:none; } .uce132e2d61fe10773a1d55fd7b1e70ce { transition: background-color 250ms; webkit-transition: background-color 250ms; opacity: 1; transition: opacity 250ms; webkit-transition: opacity 250ms; } .uce132e2d61fe10773a1d55fd7b1e70ce .ctaText { font-weight:bold; color:#464646; text-decoration:none; font-size: 16px; } .uce132e2d61fe10773a1d55fd7b1e70ce .postTitle { color:#000000; text-decoration: underline!important; font-size: 16px; } .uce132e2d61fe10773a1d55fd7b1e70ce:hover .postTitle { text-decoration: underline!important; }
See also  Saylor’s Bitcoin gamble to deliver $14 billion profit in Q2, defies Wall Street doubts

Bots instantly send replace-by-fee (RBF) transactions to compete by raising fees for miners to approve a withdrawal.

An RBF or replace by fee, is a node policy that allows bots to replace an unconfirmed transaction with a new transaction that pays a higher fee to miners.

On-chain fee data shows sudden jumps in satoshi-per-byte (sat/vB) rates. This indicates transactions being replaced with higher-fee versions.

Only one transaction ultimately confirms, while competing versions are dropped or replaced.

Bitcoin bots drain compromised wallet in RBF fee war image 0 The balance history of the compromised BTC wallet. Source: mempool.space.

Watching greedy bots send more aggressive RBF transactions can be somewhat entertaining.

“Sometimes I send small transactions to compromised wallets, just to see the beauty in this automated RBFs,” said Brevsolution on X.

But some people send larger amounts to compromised wallets, and the reason is unclear. “I’d really like to know why that happens,” said Ottosch on X. Such transactions could be a mistake from the sender’s side.

In November, $70,000 was carelessly sent to a wallet linked to a predictable private key. Brevsolution explained that bots react instantly and use RBF to reduce transactions down to one satoshi. This causes the bots to pay almost 100% of the deposited BTC in fees.

Bitcoin private keys could be compromised

Weak private keys and seed phrases could be hacked. They are predictable like easy passwords.

.u66a7b9cedb1238604a018f237b4d9a43 { padding:0px; margin: 0; padding-top:1em!important; padding-bottom:1em!important; width:100%; display: block; font-weight:bold; background-color:#eaeaea; border:0!important; border-left:4px solid #3498DB!important; box-shadow: 0 1px 2px rgba(0, 0, 0, 0.17); -moz-box-shadow: 0 1px 2px rgba(0, 0, 0, 0.17); -o-box-shadow: 0 1px 2px rgba(0, 0, 0, 0.17); -webkit-box-shadow: 0 1px 2px rgba(0, 0, 0, 0.17); text-decoration:none; } .u66a7b9cedb1238604a018f237b4d9a43:active, .u66a7b9cedb1238604a018f237b4d9a43:hover { opacity: 1; transition: opacity 250ms; webkit-transition: opacity 250ms; text-decoration:none; } .u66a7b9cedb1238604a018f237b4d9a43 { transition: background-color 250ms; webkit-transition: background-color 250ms; opacity: 1; transition: opacity 250ms; webkit-transition: opacity 250ms; } .u66a7b9cedb1238604a018f237b4d9a43 .ctaText { font-weight:bold; color:#464646; text-decoration:none; font-size: 16px; } .u66a7b9cedb1238604a018f237b4d9a43 .postTitle { color:#000000; text-decoration: underline!important; font-size: 16px; } .u66a7b9cedb1238604a018f237b4d9a43:hover .postTitle { text-decoration: underline!important; }
See also  Bitcoin dips to $63K as Fed holds interest rates steady

Storing the private key securely is essential to protect BTC. Exposing it or any other related data often leads to quick theft by hackers.

Using a txid to hash a private key does not provide enough entropy to secure the private keys.

Bitcoin private keys are just numbers. It is possible to derive a public address and private keys from block hashes and transaction IDs (txids).

Any txid or block hash is a valid 256-bit number and can technically be used as a private key.

Bots exploit this by precomputing addresses from known public data. Then they watch those addresses forever and drain them instantly.

If you're reading this, you’re already ahead. Stay there with our newsletter.

0
0

Disclaimer: The content of this article solely reflects the author's opinion and does not represent the platform in any capacity. This article is not intended to serve as a reference for making investment decisions.

PoolX: Earn new token airdrops
Lock your assets and earn 10%+ APR
Lock now!
© 2025 Bitget