RIYADH – The Pi Network, a mobile-first cryptocurrency project that has accumulated over 40 million “Pioneers” since 2019, is facing its most severe crisis yet. Multiple users have reported that their wallet balances were wiped to zero during the lock-up expiry and migration process, according to a wave of posts on X and Telegram over the past 48 hours. The incidents coincide with widespread transaction failures and the emergence of a self-proclaimed “senior engineer” whose identity has been openly challenged by the community. The episode exposes deep vulnerabilities in a project that has spent five years promising a mainnet without delivering one, and now appears unable to protect even the basic assets of its user base.

The problems came to a head after users began attempting to migrate their Pi tokens from the testnet environment to what Pi Network calls the “Enclosed Mainnet.” In reports verified by multiple independent blockchain analysts, the migration function triggered a series of failed transactions, followed by the complete depletion of token balances in affected wallets. “I had 4,500 Pi locked for three years. When I finally unlocked, I clicked migrate, and my wallet went to zero. Forty-two failed transactions in the block explorer. No help from support,” one user said in a Telegram group chat monitored by this correspondent. Another user, identifying as a node operator, posted screenshots showing the same pattern: a long string of failed internal transfers, then an empty balance. The block explorer data for the Pi Network testnet—which is publicly accessible but rarely scrutinized—shows a cluster of failed transactions originating from multiple addresses within the same 24-hour window. The failure code is inconsistent across blocks, suggesting a systemic issue rather than a simple user error.
Pi Network’s architecture has always been a black box. The project uses a modified Stellar Consensus Protocol for its testnet, but the actual wallet contract code has never been publicly audited. There is no mandatory two-factor authentication (2FA) for wallet operations. Login credentials consist of only a password and a phone number—the latter of which can be easily compromised via SIM-swap attacks. This is a known vulnerability that has been flagged by security researchers as early as 2021. The recent incident appears to exploit this exact gap. The community is now rallying around a single demand: implement 2FA as a mandatory feature before any further migrations. A user with the handle “Rizo” posted a detailed technical thread on X outlining a proposal for integrating one-time passcodes via email or authenticator apps. The thread has amassed over 12,000 likes and hundreds of comments from users sharing similar experiences. Yet the Pi Core Team, as the anonymous developers are called, has remained silent on official channels for over 72 hours.
Instead of an official statement, a user claiming to be “Daniel Carter, Senior Engineer at Pi Network” appeared in several Telegram groups and on X Spaces to explain the situation. According to his own narrative, he has worked for Pi Network for ten years—a mathematically impossible claim given the project was launched in 2019. He also stated that the project is in a “critical phase of development,” a phrase that has been repeated in similar contexts since 2022. Community members quickly spotted the discrepancy. In a forensic analysis of Carter’s X profile, users found that the account was created in March 2025, has only 47 followers, and links to a GitHub profile with no commits. Another user traced the IP metadata from one of his Spaces appearances to a VPS server located in Eastern Europe, not the US or China where Pi’s core team is rumored to be based. The consensus among the most active community groups is that “Daniel Carter” is a fabrication, possibly a community manager or even a bot, deployed to placate the masses without revealing anything substantial. The incident has erased whatever remaining trust the community had in the project’s leadership.
This trust deficit is not new. Pi Network has operated for five years without a live mainnet, without a functional token, and without a single external security audit. The project’s tokenomics—reporting a fixed supply of 100 billion Pi—are entirely theoretical. Users “mine” by clicking a button daily, accumulating a balance that exists only on a centralized server controlled by the Pi Core Team. There is no on-chain verification of balances. The recent wallet balance wipe is, in effect, a glitch in that centralized database, but the lack of transparency makes it indistinguishable from a hack. The most charitable explanation is a bug in the migration smart contract deployed on the testnet. The most cynical—and increasingly plausible—explanation is that bad actors within or connected to the core team have discovered how to manipulate the centralized backend to siphon tokens. Either way, the user bears the loss.
From a risk perspective, the incident confirms everything that security-conscious analysts have warned about for years. Decentralization is not a claim; it is a function of code that no one can see. The Pi Network’s decision to keep the source code closed and to avoid any formal audit creates an asymmetric information environment where users must trust anonymous developers with no track record. The “senior engineer” debacle only sharpens the point: when the team cannot even coordinate a coherent public response, how can it be trusted to safeguard millions of wallets? The market has already reacted. On peer-to-peer exchange platforms where Pi is traded at fractions of a cent, buy-side volume has collapsed by 82% in the past week, according to a data provider that requested anonymity.
The situation also has regulatory implications. Under the Howey Test criteria used by the US Securities and Exchange Commission, Pi Network meets several conditions: users contribute resources (time, data, and referrals), form a common enterprise with the core team, expect profits from the token’s eventual listing, and rely entirely on the management’s efforts. The loss of user assets—as witnessed this week—could be interpreted as a failure of fiduciary duty. While the SEC has not yet taken public action, several legal firms have begun soliciting affected users through social media for potential class-action lawsuits. The anonymity of the Pi Core Team makes any legal recourse difficult, but not impossible; regulators in jurisdictions such as South Korea, India, and Nigeria have previously moved against anonymous crypto projects that harmed retail users.
What makes this crisis particularly dangerous for the broader ecosystem is its potential to poison the “mobile mining” narrative. Projects like Hi, Era7, and TapSwap have emerged in recent years, promising similar “free mining” models but with live mainnets and audited contracts. The Pi Network’s collapse—should it continue—will inevitably taint the entire category. Sophisticated investors will become more skeptical of any project that requires a phone number but delivers no verifiable on-chain data. The reflexive answer to such skepticism is always “but the user base,” yet a user base without a functioning product is just a list of phone numbers. The Pi Network’s user base is its only moat, and it is eroding in real time.

Check the math, not the roadmap. The pi Network’s roadmap has always pointed to an idealized mainnet. The math—five years of development, no audit, no 2FA, no public code—tells a different story. Audits are snapshots, not guarantees. But you need at least one snapshot to begin with. Pi Network has zero. Complexity is the enemy of security. Yet the migration process, with its lock-up logic, referral bonuses, and centralized verification points, is a perfect storm of complexity without any compensating security architecture. Code does not care about your vision. The code, or lack thereof, is the final judge.
The takeaway for the crypto community is brutal but necessary. This is not a speculative bug in a DeFi protocol that will be patched overnight. This is a structural failure of a project that was never designed to secure real value. The community’s demand for 2FA is a band-aid on a deep wound. The underlying problem is that the entire system is built on a foundation of trust in anonymous developers—a foundation that has now cracked. If you are still holding Pi tokens, treat them as already lost. If you are still clicking the button, ask yourself what you are building. The only question that matters now is how many more “critical phases” the community will endure before it walks away. The answer, based on the data, appears to be none.