In the early hours of August 16, 2026, WinLEW's monitoring reported an unusual pattern: the same wallet signing in over and over, and then, in short bursts, a run of wallets that had never been seen before.

None of it looked like people using the site.

What was observed

Three things stood out, all of them visible in the live log as they happened:

  • repeated wallet-only sessions from the same wallet in quick succession
  • bursts of newly created wallets signing in for the first time
  • the two patterns repeating over roughly forty minutes

A wallet-only session is the lightest form of access WinLEW offers. It lets someone connect and look around without linking a Discord account, and deliberately unlocks nothing that pays out. That distinction turned out to matter.

What was done

The activity was watched in real time rather than discovered afterwards. While it was ongoing, the bot was taken offline so that changes could be made without racing whoever was generating the wallets, and the logs and on-chain evidence were preserved before anything was modified.

The Mole Guard — WinLEW's own monitoring bot — was the tool used throughout the response, both to see the pattern and to check it against records afterwards.

What was not reached

This is the part worth stating plainly, because it is the part that was checked rather than assumed. Every wallet involved was compared against WinLEW's own records:

  • No funds were taken.
  • None of the wallets reached the faucet claim system.
  • None of them appeared in faucet registrations.
  • Nothing was paid out to any of them.

Signing in cost the project nothing. The systems that move tokens sit behind separate checks, and those checks held.

What changed afterwards

The response did not stop at "nothing was taken." Several protections were strengthened in the days that followed:

  • Wallet verification now measures how long an identity has existed, not merely that it exists.
  • Every path that releases tokens — faucet, rewards and game payouts alike — now passes through a single shared block list. One of them previously did not.
  • Bursts of anonymous sign-ins are now detected automatically rather than by someone happening to watch the channel.
  • Every automated refusal now tells the person how to appeal it, because these checks can be wrong about real people.

The investigation continued after the immediate response, including tracing the on-chain funding relationships between the wallets involved. That work is ongoing.

What we are not saying

WinLEW is not naming anyone, and is not calling this an attack by a named party. What is established is a pattern of automated wallet creation and sign-ins. Intent is not something a log can prove, and we would rather publish less than publish something we cannot stand behind.

We are also not publishing the specific thresholds, timings or configuration involved in detection. Those details would help the next attempt more than they would help anyone reading this.

Why this is published at all

Nothing was lost, so nothing obliged us to write this. We are publishing it because a project that only reports its good days is not being transparent — it is marketing. The record should show what happened and how it was handled, including the part where a gap was found in the payout checks and closed.