Guides / 0x0acc…5fa5
⚠ Exploit

Why is 0x0acc…5fa5 flagged?

0x0acc0e5faa09cb1976237c3a9af3d3d4b2f35fa5 · View on explorer ↗
Quick answer

This address is flagged in public scam/exploit label data as Exploit — linked to a smart-contract exploit — an address used to drain funds from a vulnerable DeFi protocol. Its Hopchain label comes from the source list's own name for it: “bZx PrivKey Exploiter 2” on bsc-mainnet. If it shows up as a connection on a wallet you're checking, don't interact with it, sign anything it prompts, or visit any site linked to it.

Also flagged as “bZx PrivKey Exploiter 2” on matic-mainnet.
What Hopchain observed
Flagged on (source label data) matic-mainnet, bsc-mainnet
Most active chains (live data) eth-mainnet, matic-mainnet
First activity observed Nov 5, 2021
Last activity observed 1 year ago
Transactions observed 63
Distinct connections observed 22
A few addresses this wallet has sent to, found in the eth-mainnet transaction history Hopchain pulled (not a complete list — just the first 3 found):
0x967bb5…737e31 Nov 13, 2021
0x74487e…5254d4 Nov 5, 2021
0xeb3ec6…8ddbcc Nov 5, 2021
Seen sending: ETH — based on a small sample of its own recent outgoing transactions, not exhaustive.
Don't
  • Interact with this address, or sign any transaction it prompts
  • Visit a site linked in a token or message associated with it
  • Try to "recover" or move on tokens it sent you by following its instructions
  • Assume a familiar-looking name or logo means it's legitimate
Do
  • Ignore unsolicited tokens or dust sent from it — it's safe to just leave them
  • Check your wallet's token approvals and revoke anything you don't recognize
  • Double-check a project's real official URL before connecting a wallet
  • See the full connection graph if you want to trace it further
See the full analysis for this address

Interactive connection graph, all connections, and CSV export — free, no signup.

Analyze 0x0acc…5fa5 →

Frequently asked

Is it dangerous just to receive tokens from a flagged address?
Receiving alone doesn't put your wallet at risk. The danger comes from interacting back — don't visit any site linked in the token's name or metadata, and don't sign anything it prompts, including a "claim" or "approve" transaction.

Why does Hopchain flag this specific address?
It's cross-referenced against verified public phishing/exploit/heist/scam label data (see how it works). Coverage isn't complete for every chain — Ethereum mainnet and Base aren't covered by this particular source yet, a known, disclosed gap.

What if I already approved this address to spend a token?
Open your wallet's connected-apps or approvals view (or a revocation tool) and revoke it. An approval only lets a contract move funds you granted it access to — revoking it removes that permission.