Glass Ledger
GoMining Hack: A Mining Custody Self-Check
A September 2026 drain tied to GoMining raises a real question: does your mining reward actually pay you directly? Run this checklist to find out.
On September 4, 2026, on-chain monitors flagged a coordinated drain touching more than 600 wallets tied to GoMining, a platform that markets itself as a Bitcoin mining and rewards app built around NFT miners, a native GMT token, and products like Simple Earn and Instant Funds. The wallets involved shared one thing in common: a history of holding GMT. Roughly $2.8 million was swapped and bridged across chains before settling into about 1,147 ETH, a pattern researchers associate with deliberate laundering rather than an accident. Bitget followed on September 5 by pausing GOMINING-ETH deposits and withdrawals, citing "wallet maintenance." As of this writing, GoMining itself has not confirmed the incident as a protocol exploit, so the details remain unsettled. This GoMining hack custody checklist is not about piling on one platform while the facts are still developing. It is about a question every miner should be able to answer regardless of how this particular story resolves: when your mining reward is created, who actually holds it before it reaches you?
What Actually Happened in the GoMining Drain, As Far As Anyone Can Confirm
Strip away the token ticker and the app branding, and the reported pattern is a familiar one. Value tied to a mining platform's ecosystem token moved out of hundreds of wallets in a short window, got bridged across networks to slow tracing, and landed in a single pool of ETH. Whether the root cause turns out to be a smart contract bug, a compromised key, or something else entirely, the practical lesson for a reader does not depend on which it was. It depends on whether your own mining reward ever had to pass through a platform's custody at all before you controlled it.
Why "Mining Platform" Doesn't Automatically Mean Non-Custodial
A lot of mining products use language that sounds self-directed while quietly running a custodial layer underneath. An NFT that represents a share of hashpower, a token that accrues mining yield, a dashboard balance you have to withdraw: each of these is a promise that someone else is holding value on your behalf until you ask for it back. That is a legitimate business model, and plenty of platforms disclose it clearly. But it is a fundamentally different arrangement from a pool where the coinbase transaction (the transaction that mints and pays out a new block's reward) is built to send funds straight to an address only you hold the private key for, with nothing sitting in a pool-side balance in between.
The Self-Custody Checklist
Run your own mining setup, or any mining platform you use, through these questions honestly:
- Does the coinbase transaction that pays a found block send funds directly to an address you generated and control, with no intermediate pool balance?
- Could you verify that payout transaction yourself, independently, before or as soon as a block is found, rather than trusting a dashboard number?
- Does using the platform require holding a separate token, credit, or NFT that represents your mining reward instead of the reward itself?
- Is there ever a "withdraw" button standing between you and funds a block reward already produced?
- If the platform disappeared tomorrow, would your mined coins already be sitting in a wallet you control, unaffected?
If You Answered No to Any of These
If any answer came back "no," that is not automatically a scam, but it is custodial risk you are carrying, whether or not the platform calls itself decentralized. The fix is not to panic about every mining product that uses a token. It is to separate, in your own head, what is a genuine non-custodial payout from what is a balance someone else is managing for you, and to size your exposure to the second kind accordingly.
If you answered yes to all five, you are already mining in a model where a coinbase transaction does the one job that matters: it pays your own address directly, in the same transaction that creates the reward. That is the design NexusPool uses for solo mining across Bitcoin, Litecoin, Dogecoin, and Bitcoin Cash: nothing is held in a pool-side balance, so there is nothing to "withdraw" and nothing that can be frozen or drained on the pool's side because it was never there. NexusPool also publishes signed, offline-checkable receipts for custody and work, called Glass Ledger, and a Payout Preflight tool that reconstructs and checks a coinbase transaction byte for byte before a block is even found, so you are not taking the payout structure on faith. You can read more about how the pool is built on NexusPool's about page.
None of this changes the math of solo mining itself. Difficulty relative to your own hashrate sets your odds of finding a block, identical for every miner on a given chain, and no pool, custody model, or verification tool changes that arithmetic. This post is not investment advice, is not a claim that any particular platform is fraudulent, and is not a claim that NexusPool's software is open source; only the facts above about its coinbase and receipt design are stated as such. For the fuller picture on the GoMining situation as it develops, see CoinGape's reporting on the wallet drain.
Trust nothing. Verify where your own mining reward actually goes.