first @feezybellz_ii sent a message no-one wants to see. His wallet was drained of all SOL. For some reason his Badge was untouched. We checked if there was a threshold for SOL transfers out, perhaps if we transfer just enough to make the transfer it would not be removed.
The script put together a transaction that had the compromised wallet sign as the authority/owner, but a separate wallet pays the transaction fees This way no funds went into the account to be drained. You can check it out here github.com/jskoiz/solana-tra…
My theory is that because @neukoai`s collection used @metaplex's newer core asset protocol rather than a typical ATA the drainer overlooked scanning for these types of accounts and his NFT was missed. developers.metaplex.com/core































