Members of the Pi Community neighborhood are elevating alarms over a rising rip-off technique that has already resulted in tens of millions of Pi tokens being drained from person wallets.
The scheme exploits the community’s cost request function and the inherent transparency of blockchain knowledge. It prompts the Pi Core Staff to quickly disable cost requests as losses mount.
Sponsored
Sponsored
Pioneers Warn of Rip-off Technique Resulting in Pi Being Drained from Wallets
Based on a number of neighborhood alerts circulated on X (previously Twitter), scammers can scan the Pi blockchain to establish pockets addresses and think about their Pi balances.
As soon as a pockets with a large stability is recognized, the attacker sends a cost request on to the holder. If the recipient clicks “approve,” the Pi is transferred immediately to the scammer’s pockets and can’t be recovered.
Neighborhood account Pi OpenMainnet 2025 warned that the mechanism is commonly misunderstood as a technical flaw.
“Beforehand, individuals known as this a ‘system vulnerability,’ however actually, it’s not a vulnerability in any respect,” the put up acknowledged. “That is precisely how the pockets is designed to work. The one means you’ll lose your Pi cash is in case you personally approve the transaction.”
The identical message emphasised that the risk lies in social engineering moderately than protocol failure. Scammers could disguise requests to seem authentic or impersonate trusted contacts, rising the probability that customers approve transfers with out verifying them.
A Rip-off at Scale
Blockchain monitoring shared by the neighborhood factors to a single pockets handle as a significant hub for the exercise.
Sponsored
Sponsored
The handle—GCD3SZ3TFJAESWFZFROZZHNRM5KWFO25TVNR6EMLWNYL47V5A72HBWXP—has been accused of stealing between 700,000 and 800,000 Pi per 30 days. Based on experiences, cumulative losses now exceed 4.4 million Pi.
Information shared by Pi Community Replace exhibits constant month-to-month inflows to the handle:
- Roughly 877,900 Pi in July 2025
- 743,000 Pi in August
- 757,000 Pi in September
- 563,000 Pi in October
- 622,700 Pi in November, and
- Over 838,000 Pi in December.
The figures counsel a coordinated and sustained operation moderately than remoted incidents, with December’s spike indicating accelerating exercise.
Sponsored
Sponsored
The size of the theft has heightened concern amongst Pioneers, a lot of whom are new to on-chain transactions. As such, they might be unfamiliar with the dangers of approving unsolicited requests.
Pi Staff Disables Fee Requests
In response, the Pi Staff has quickly suspended the “ship cost request” function. Neighborhood notices point out the transfer was taken after rip-off exercise intensified.
“At present, the Pi group has suspended all these requests (probably as a result of the scams have gotten uncontrolled),” stated Pi Community Alerts in a put up.
Nevertheless, the suspension is described as a stopgap measure moderately than a everlasting repair. The function could also be re-enabled as soon as extra safeguards or person protections are assessed.
Till then, neighborhood steerage is unequivocal. The community advises customers to not settle for or approve any cost requests despatched to their wallets, no matter who seems to be the sender.
Sponsored
Sponsored
Warnings stress that scammers could pose as buddies, relations, and even official Pi accounts.
The incident highlights a broader problem for blockchain networks: placing a stability between transparency and usefulness, whereas sustaining person safety.
Whereas the Pi protocol capabilities as supposed, the episode highlights how simply social engineering can exploit commonplace options to create assault vectors.
As cost requests stay disabled at 12 months’s finish, Pi Community’s PI Coin was buying and selling for $0.20381, up by nearly 1% within the final 24 hours.
In the meantime, Pi neighborhood members proceed to trace suspicious wallets and amplify safety warnings. They urge vigilance as scams grow to be extra refined and widespread.