HomeDossiersAngel Drainer: Theft of over $25 million in crypto assets in 2024...

Angel Drainer: Theft of over $25 million in crypto assets in 2024 using malicious contract approvals

Seven Primary Phishing Vectors Deployed by Angel Drainer in Early 2024

20 Serious Questions Answered

  1. What is Angel Drainer? A malicious script used to steal cryptocurrency via unapproved contract signatures.
  2. How much did Angel Drainer steal in 2024? The group stole over $25 million from 35, 000 wallets.
  3. When did Angel Drainer upgrade to AngelX? The developers launched the AngelX version on August 31, 2024.
  4. Which new blockchains did AngelX target? The toolkit targeted The Open Network and Tron.
  5. What number of malicious applications did AngelX deploy? Security researchers found over 300 malicious decentralized applications deployed by the system.
  6. What is the Safe Vault exploit? Attackers used Etherscan verified Safe contracts to deceive users into signing malicious transactions.
  7. How much was stolen in the February 2024 Safe Vault attack? The group stole $403, 000 from 128 wallets.
  8. What is Permit2 phishing? A tactic where victims sign off chain messages that grant attackers token spending permissions.
  9. How does the drainer bypass BlockAid? The script generates unmarked contract addresses when a victim wallet balance exceeds a specific threshold.
  10. Did Angel Drainer target restake farming? Yes, the group deployed fake interfaces to intercept EigenLayer restaking approvals.
  11. What is EIP 7702 delegation hijacking? A vector where attackers deceive users into delegating wallet execution rights to a malicious smart contract.
  12. How do attackers distribute the phishing links? Scammers use search engine ads, fake social media accounts, and compromised Discord channels.
  13. What percentage fee does Angel Drainer charge its users? The developers charge a 20 percent commission on all stolen assets.
  14. What was the Ledger Connect Kit attack? A December 2023 supply chain attack linked to Angel Drainer that resulted in $600, 000 in losses.
  15. Did the group absorb other drainer toolkits? Yes, Angel Drainer absorbed the Inferno Drainer infrastructure in October 2024.
  16. What number of victims lost funds to drainers in total in 2023 and 2024? Over 324, 000 users lost assets to various drainer groups.
  17. What is the primary method of theft? Malicious ERC 20 token approvals and transfers.
  18. Can hardware wallets protect against drainers? Hardware wallets require user confirmation, users can still mistakenly approve malicious transactions.
  19. Did Angel Drainer cease operations? The group temporarily stopped operations in July 2024 after researchers identified its organizers.
  20. How do victims recover stolen funds? Recovery requires immediate revocation of approvals and blockchain forensic tracking.

The Anatomy of a $25 Million Theft

Angel Drainer stole over $25 million from 35, 000 cryptocurrency wallets between August 2023 and late 2024. The developers operate a Drainer as a Service model. They rent malicious scripts to lower tier scammers in exchange for a 20 percent cut of all stolen assets. Security firm Blockaid confirmed the group deployed highly superior tactics to drain user funds. The attackers rely on seven primary vectors to execute these thefts.

Vector 1: Safe Vault Contract Exploitation

In February 2024, Angel Drainer deployed a new attack vector using Safe vault contracts. Etherscan automatically adds a verification flag to Safe contracts. The attackers used this automatic verification to create a false sense of security. Victims saw the verified flag and approved the transactions. This single vector resulted in the theft of $403, 000 from 128 wallets in a matter of days. The malicious smart contract intercepted the approvals and drained the associated funds.

Vector 2: Permit2 Gasless Signature Phishing

The drainer heavily uses Permit2 signatures to steal ERC 20 tokens. Traditional approvals require users to pay gas fees to authorize a smart contract. Permit2 allows users to sign off chain messages to grant spending permissions. Angel Drainer presents victims with fake interfaces that request these gasless signatures. Once the victim signs the message, the attacker broadcasts the transaction and drains the wallet. This method bypasses traditional security warnings because the initial signature occurs off chain.

Vector 3: Restake Farming Interception

Restaking platforms like EigenLayer gained massive popularity in early 2024. Angel Drainer capitalized on this trend by deploying fake restaking interfaces. Victims attempting to deposit their assets into legitimate restaking platforms were redirected to malicious clones. The drainer intercepted the deposit approvals and routed the funds to attacker controlled addresses. Blockchain intelligence firm Match Systems identified this restake farming vector as a primary driver of the group revenue in 2024.

Vector 4: Cross Chain dApp Deployment via AngelX

On August 31, 2024, the developers launched an upgraded version called AngelX. This iteration expanded the attack surface beyond Ethereum. AngelX targeted users on The Open Network and Tron. Security practitioners detected over 300 malicious decentralized applications deployed by the AngelX system within its few weeks. The expansion allowed the group to target newer ecosystems with less mature security infrastructure.

Vector 5: DNS Hijacking and Frontend Injections

Angel Drainer funds and executes DNS hijacking attacks against legitimate decentralized finance applications. In these attacks, the scammers compromise the domain name system of a legitimate application. They redirect users to a malicious server hosting the Angel Drainer script. When users connect their wallets to what they believe is the official site, the script automatically assesses their balances and prompts malicious approvals. This vector was notably used in the Balancer application attack, resulting in over $350, 000 in losses.

Vector 6: EIP 7702 Delegation Hijacking

Following Ethereum upgrades, EIP 7702 allows standard externally owned accounts to temporarily delegate execution rights to smart contracts. Angel Drainer adapted its scripts to deceive users into signing these delegation requests. By signing the request, the victim hands over control of their account behavior to the attacker. The drainer then executes unapproved transfers directly from the victim wallet. This vector is highly dangerous because traditional wallet interfaces struggle to flag delegation requests as malicious.

Vector 7: Contract Generation for Security Evasion

To bypass anti phishing extensions like BlockAid and WalletGuard, Angel Drainer uses generated unmarked contract addresses. The script evaluates the victim wallet balance. If the assets exceed a predefined minimum threshold, the drainer client notifies the backend server. The server counterfactually creates a new smart contract at a fresh address. This prevents security tools from flagging the transaction because the contract address has no prior malicious history.

Financial Impact Analysis

The financial destruction caused by these seven vectors is measurable. The table illustrates the estimated financial impact and victim count associated with specific Angel Drainer campaigns in 2024.

Attack Campaign Financial Impact (USD) Victims
Safe Vault Exploit
$403, 000
128
Balancer DNS Hijack
$350, 000
Unknown
Ledger Connect Kit
$600, 000
Multiple
Total 2024 Operations
$25, 000, 000+
35, 000

The Drainer as a Service Business Model

Angel Drainer operates on a strict Drainer as a Service model. The core developers do not execute the phishing campaigns themselves. They build the smart contracts, maintain the backend infrastructure, and design the frontend templates. Cybercriminals rent access to this toolkit. The renters are responsible for driving traffic to the malicious sites through search engine advertisements, compromised social media accounts, and fake airdrop announcements. The Angel Drainer smart contract automatically splits the stolen funds. The renters receive 80 percent of the assets. The core developers receive a 20 percent commission. This division of labor allows the developers to expand their operations without directly exposing themselves to the victims.

Inferno Drainer Acquisition

In October 2024, the environment of cryptocurrency theft shifted. The developers behind Inferno Drainer, a competing service responsible for over $80 million in stolen assets, announced their retirement. They transferred their entire infrastructure and client base to the Angel Drainer team. This acquisition consolidated two of the most destructive phishing toolkits into a single entity. The merger provided Angel Drainer with superior social engineering templates and a larger network of cybercriminals to distribute their malicious links. The combined resources make the AngelX version exceptionally dangerous for retail investors.

The Mechanics of the Phishing Pages

The phishing pages deployed by Angel Drainer renters are highly sophisticated. They perfectly clone the interfaces of legitimate decentralized exchanges, non fungible token marketplaces, and staking platforms. When a user connects their wallet to the fake site, the Angel Drainer script immediately scans the wallet for valuable assets. It prioritizes high value tokens and NFTs. The script then generates a malicious transaction request disguised as a routine approval or login signature. The user interface frequently displays a fake loading screen or an error message to distract the victim while the backend script drains the assets.

Law Enforcement and Security Responses

Blockchain security firms actively monitor and flag Angel Drainer contracts. Companies like Match Systems, Blockaid, and Scam Sniffer continuously update their databases to block known malicious addresses. In July 2024, Match Systems announced they successfully identified several organizers behind the Angel Drainer group. Two hours after this announcement, the operators temporarily shut down their Telegram channel and paused their services. The group resurfaced weeks later with the AngelX upgrade. The cat and mouse game between security researchers and the drainer developers continues to escalate.

Nine High Value Target Wallets Compromised According to Blockaid Threat Intelligence

Seven Primary Phishing Vectors Deployed by Angel Drainer in Early 2024
Seven Primary Phishing Vectors Deployed by Angel Drainer in Early 2024

Blockaid threat intelligence tracked Angel Drainer operations closely between January 2023 and December 2024. The security firm identified a pattern where the malicious software specifically hunted high value wallets. The developers programmed the script to bypass security alerts if the victim held assets above a specific financial threshold. This evasion tactic allowed the syndicate to drain massive sums from individual users. The drainer uses generated unmarked contract addresses when the stolen assets exceed the predefined minimum value. When the draining process succeeds the client notifies the backend and a smart contract is counterfactually created at the given address. Security researchers documented nine specific high value wallet categories and individual breaches that define the syndicate operations.

Angel Drainer High Value Wallet Financial Impact

Victim Profile Date of Compromise Estimated Loss Attack Vector
Single Whale Wallet August 2024 $55. 5 Million setOwner Phishing Signature
Single Whale Wallet September 2024 $32. 5 Million Malicious Contract Approval
Individual Victim Early 2024 $11. 0 Million Phishing Scam
Safe Vault Wallets February 2024 $403, 000 Permit2 Transaction

Item 1: The 55. 5 Million Single Whale Wallet

In August 2024 a single cryptocurrency wallet lost 55. 5 million in DAI stablecoin. Threat intelligence reports confirmed the victim signed a malicious setOwner phishing signature. This signature allowed the attackers to modify the ownership address of a proxy contract. Proxy contracts are frequently used in decentralized finance to allow for upgradability while maintaining a consistent address. By changing the owner address the attackers gained total control over the victim funds instantly. They bypassed all subsequent approval requirements. This breach stands as the largest single theft attributed to wallet drainer networks in 2024. The massive sum was immediately transferred to attacker controlled addresses and dispersed across multiple blockchains to complicate recovery efforts.

Item 2: The 32. 5 Million Victim

September 2024 saw another massive breach when a single wallet lost 32. 5 million. The attackers deployed the AngelX toolkit to execute this theft. Blockaid reported that AngelX launched on August 31 2024 and immediately escalated the volume of attacks. The developers upgraded the user interface and control panel to help scammers create highly customized decentralized applications. These applications tricked the victim into approving a catastrophic token transfer. The AngelX system introduced advanced evasion techniques that made detection exceedingly difficult for standard security software. The attackers used these customized applications to mimic legitimate decentralized finance platforms ensuring the victim felt secure when signing the transaction.

Item 3: The 11 Million Individual Victim

During the half of 2024 security analysts tracked an 11 million loss from a single high value wallet. At the time researchers recorded this as the second largest individual cryptocurrency theft on record. The attackers used the Angel Drainer JavaScript malware to deceive the user. The victim granted token approvals to a fraudulent smart contract. The syndicate then swept the entire balance into intermediary wallets for laundering. Threat intelligence data showed that the drainer developers took a 20 percent cut of the stolen funds. This fee structure incentivized the developers to continuously refine their malicious code and provide dedicated support to the scammers executing the attacks.

Item 4: The 128 Safe Vault Wallets

Blockaid disclosed a highly sophisticated attack on February 12 2024. Angel Drainer deployed a malicious Safe vault contract. The attackers knew that Etherscan automatically adds a verification flag to Safe contracts. This verification flag gave 128 high value wallet owners a false sense of security. The victims inadvertently authorized a Permit2 transaction. The Permit2 standard allows users to share token approvals across different applications attackers weaponized it to drain entire balances in a single transaction. The syndicate stole 403, 000 in digital assets before Blockaid and the Safe team could mitigate the damage. Blockaid noted that this was not a direct attack on Safe rather an exploitation of user trust in Etherscan verification flags.

Item 5: The Ledger Connect Kit Victims

In December 2023 Angel Drainer orchestrated the infamous Ledger Connect Kit exploit. The attackers compromised the front end library used by numerous decentralized applications. High value wallet owners interacting with these applications unknowingly executed malicious code. Blockaid estimated that the syndicate stole over 25 million from nearly 35, 000 wallets across their entire campaign with the Ledger Connect Kit serving as a primary vector for securing high value victims. The attackers injected the malicious JavaScript directly into the library ensuring that any user connecting their hardware wallet to an affected application was immediately targeted. This supply chain attack demonstrated the advanced technical capabilities of the Angel Drainer developers.

Item 6: The Restake Farming Platform Victims

Blockaid analysts raised alarms in February 2024 regarding a new attack vector. Angel Drainer began attacking restaking platforms. The attackers exploited the queueWithdrawal function to execute an approval farming attack. High value wallets participating in restake farming were tricked into signing withdrawal requests that redirected their staked assets to attacker controlled addresses. This method bypassed standard security checks by mimicking legitimate platform operations. Restaking platforms hold massive amounts of liquidity making them highly lucrative marks for drainer syndicates. The attackers carefully crafted the phishing sites to look identical to the official restaking interfaces ensuring maximum conversion rates among high value users.

Item 7: The 343, 000 aEthWETH Victim

On chain data revealed a single victim who lost approximately 343, 000 in staked Ethereum assets. The user clicked a fraudulent Aave advertisement on a Google search result page. The link directed the victim to a counterfeit website. The user signed an Increase Allowance transaction granting the scammer infinite approval for their tokens. The attackers quickly moved the aEthWETH to a malicious contract and swapped the funds for standard Ethereum. The stolen Ethereum was then transferred to an administrative wallet controlled by the drainer developers. From there the funds were split between the developers and the scammer who purchased the malicious advertisement. The developers then routed their share through decentralized exchanges to obscure the transaction history.

Item 8: The TON Network Whale Wallets

Blockaid reported that the AngelX system aggressively attacked The Open Network starting in September 2024. The developers identified that newer blockchain ecosystems possessed fewer security tools. The syndicate deployed over 300 malicious decentralized applications in just four days. These applications specifically hunted whale wallets holding large balances of native tokens. Blockaid noted that the evasion rate of AngelX on The Open Network was exceptionally high. The attackers exploited the absence of mature anti phishing extensions on the network to operate with near impunity. They created fake airdrop campaigns and token presales to lure high value users into connecting their wallets and signing malicious transactions.

Item 9: The TRON Ecosystem High Value Wallets

Alongside The Open Network AngelX expanded its operations to the TRON blockchain. The attackers focused on high value wallets holding Tether stablecoins. Blockaid research revealed that more than 90 percent of AngelX applications evaded detection by major security providers. The syndicate capitalized on the rapid transaction speeds and low fees of the TRON network to drain victim wallets and launder the stolen stablecoins before security firms could intervene. The attackers used customized smart contracts that automatically transferred the stolen Tether to multiple intermediary addresses. This automated laundering process made it exceedingly difficult for centralized exchanges to freeze the funds before they were converted into untraceable assets.

Five Malicious Smart Contract Approval Mechanisms Exploited for Asset Exfiltration

Smart contract approvals form the foundation of decentralized finance. Users must grant permissions to applications to execute trades, stake assets, and move tokens. Malicious actors exploit these necessary functions to drain wallets. Between 2023 and 2025, the Angel Drainer syndicate weaponized five specific smart contract approval methods to steal over $25 million from unsuspecting users. The group operates a Drainer as a Service model. They rent their malicious scripts to affiliates in exchange for a percentage of the stolen funds. The affiliates deploy fake websites, compromise legitimate domains, and launch supply chain attacks to trick users into signing these fatal approvals.

Stolen Asset Distribution and Affiliate Fee Structure

Angel Drainer operates as a service. The developers take a percentage of all stolen assets. The remaining funds go to the affiliate who deployed the malicious site.

Entity Role Profit Share Visual Representation
Affiliate Attacker Traffic Generation 80% to 85%
Angel Drainer Developers Infrastructure Provider 15% to 20%

1. CREATE2 Opcode Manipulation and Nested Multicall Contracts

Angel Drainer developers use the CREATE2 opcode to bypass security alerts and obscure their on chain activity. The CREATE2 function allows developers to precalculate a smart contract address before deploying the actual code to the Ethereum network. Attackers generate a temporary empty address for each malicious signature request. Security providers and wallet scanners check this address against known blacklists. The empty address has no transaction history and holds no malicious code at the time of the scan. The security tools mark the address as benign. The victim signs the transaction believing the interaction is safe.

The attacker then deploys the malicious contract to the precalculated address. This new contract executes the transfer and drains the assets. SlowMist and ScamSniffer reported that attackers used this method to steal $3 million from 11 victims in late 2023. One single victim lost $1. 6 million to this specific address poisoning and CREATE2 deployment method.

The drainer script also uses nested smart contracts to execute multicall functions. Blockchain security groups developed algorithms to identify simple Permit and transferFrom transactions on known scammer addresses. Angel Drainer bypasses these monitors by processing operations within the multicall of the newly created CREATE2 contracts. The new contract holds no transaction records and obscures the final destination of the funds. The multicall function processes multiple transactions in a single block. The script executes a Permit transaction followed by two transferFrom transactions. The transfer sends 85% of the stolen assets to the affiliate. The second transfer sends 15% to the Angel Drainer developers.

2. eth_sign Blind Signature Exploitation via DNS Hijacking

The eth_sign method represents a serious vulnerability in decentralized finance interactions. This open signature method allows a user to sign any arbitrary hash. The payload appears as a raw hexadecimal string. Users without deep technical knowledge cannot read or verify the transaction details. Attackers deploy malicious decentralized applications and prompt users to connect via WalletConnect. The application requests an eth_sign approval. If the user declines the request, the malicious site uses WebSocket Secure connections to spam the prompt continuously. The user eventually clicks confirm to dismiss the popup.

Angel Drainer deployed this exact tactic during the Balancer system attack on September 19, 2023. Attackers compromised the domain name system of the official Balancer website. The attackers redirected users to a malicious interface. The script automatically checked the balance of the connected wallet. The site then prompted the user to sign an eth_sign transaction. The attacker received the signed data and broadcasted it to the network. This granted the attacker full control over the specified assets. The attackers stole at least $350, 000 from victims during this specific domain hijacking event. Security firms advise users to reject all eth_sign requests and rely on wallets that parse contract calls into readable formats.

3. SetApprovalForAll Non Fungible Token Exfiltration

Attackers extract non fungible tokens using the SetApprovalForAll function. This function exists within the ERC 721 and ERC 1155 token standards. Marketplaces use this function to move tokens on behalf of sellers. Angel Drainer weaponizes this legitimate function to drain high value digital art and liquidity positions. The attacker creates a fake minting website or airdrop claim page. The site prompts the user to sign a transaction. The transaction contains the SetApprovalForAll command.

The user signs the prompt. The attacker instantly gains operator privileges over the entire token collection held in the victim wallet. The attacker does not need the private key of the user. The attacker simply transfers the high value tokens to a secondary wallet. On July 21, 2025, a single victim lost $1. 23 million in Uniswap V3 Position NFTs after signing a malicious multicall transaction containing this exact function. The attacker routed the stolen assets through the CoW Swap system and exchanged the non fungible tokens for 1. 15 million DAI stablecoins. The automated script executes these transfers within seconds of the user clicking confirm. The drainer infrastructure supports automated asset transfers across multiple chains. The system evaluates the floor price of the tokens and prioritizes the most liquid assets for immediate liquidation.

4. queueWithdrawal Exploitation on Restaking Platforms

Angel Drainer developers constantly update their scripts to attack new decentralized finance systems. In February 2024, the group deployed a specific exploit attacking the EigenLayer restaking platform. EigenLayer allows users to restake Ethereum to secure other networks. The system uses a specific queueWithdrawal function with the hex code 0xf123991e. Angel Drainer created a custom script to manipulate this Strategy Manager contract function.

The phishing page prompts the user to sign a routine transaction. The user believes they are claiming staking rewards or participating in a governance vote. The signature actually approves a malicious withdrawer address. The system then redirects the staking rewards from the EigenLayer platform directly to the attacker. Blockaid analysts discovered this attack vector and noted that standard security tools failed to parse the approval type. The transaction approval differs from the regular ERC 20 approve method due to the nature of Ethereum staking. The attackers combined this EigenLayer exploit with the CREATE2 method to route the stolen funds through hidden empty addresses. EigenLayer officially confirmed the attack and urged users to verify all withdrawal requests.

5. ERC 20 Approve and TransferFrom Hijacking via Supply Chain Attacks

The most frequent method for asset theft involves standard ERC 20 token approvals. Decentralized exchanges require users to approve token spending limits before executing a trade. Angel Drainer mimics this exact process. The phishing site presents a fake yield farming opportunity. The site asks the user to approve a token spend. The underlying code requests an infinite allowance. The user signs the approval. The attacker then calls the transferFrom function on the token contract. The contract moves the maximum allowed balance from the victim wallet to the attacker wallet.

Angel Drainer expanded this attack vector through a massive supply chain compromise on December 14, 2023. Attackers uploaded a malicious version of the Ledger Connect Kit to the Node Package Manager registry. The compromised code injected the Angel Drainer malware directly into legitimate decentralized applications. Users interacting with safe websites suddenly received malicious approval requests. The Ledger Connect Kit attack affected multiple high profile decentralized finance frontends. The malicious packages remained live on the registry for approximately two hours before security teams removed them. During that window, any user who connected their hardware wallet and clicked confirm unknowingly handed over full control of their ERC 20 tokens. The attacker automates this process using a script. The script checks the wallet balance and drains the most valuable tokens. The developers take a 15% to 20% fee from the stolen funds. The remaining 80% to 85% goes to the affiliate who drove traffic to the phishing site. Ledger detected the exploit and removed the malicious code, the incident demonstrated the severe threat of automated approval hijackings.

ScamSniffer Phishing Reports Detailing Twelve Fake Airdrop Campaigns

Nine High Value Target Wallets Compromised According to Blockaid Threat Intelligence
Nine High Value Target Wallets Compromised According to Blockaid Threat Intelligence

ScamSniffer Data on Malicious Airdrop Operations

ScamSniffer published extensive data detailing the operational footprint of the Angel Drainer syndicate. Security researchers identified thousands of malicious domains linked to the group. The syndicate deployed automated scripts to drain cryptocurrency wallets. Attackers lured victims using fake airdrop announcements and compromised front end interfaces. The data shows a clear pattern of exploitation directed at multiple blockchain networks.

1. The Balancer Domain Name System Hijack

On September 19 2023 attackers compromised the official Balancer decentralized finance website. The syndicate hijacked the Domain Name System routing. Users navigating to the legitimate URL encountered a malicious interface. The script prompted visitors to sign an approval transaction. ScamSniffer and SlowMist confirmed the attack originated from the Angel Drainer group. The exploit resulted in the theft of $350, 000 from unsuspecting liquidity providers. The attackers used Cloudflare to mask their actual server addresses. The malicious JavaScript code automatically assessed the connected user balance. It then executed a phishing attack by prompting an Approve transaction. Once the user signed the attackers used the transferFrom function to move the funds to their own addresses.

2. The Ledger Connect Kit Supply Chain Breach

In December 2023 the syndicate executed a supply chain attack on the Ledger Connect Kit. Developers use this library to connect decentralized applications with hardware wallets. The attackers injected malicious JavaScript into the library. This compromised the front end of multiple major platforms including SushiSwap and Zapper. ScamSniffer reported that the exploit drained $600, 000 from users. The malicious code automatically triggered wallet approval requests when users interacted with the affected applications. The attackers compromised the Node Package Manager registry for the Connect Kit. They published a malicious version of the package. Applications that automatically updated to the latest version unknowingly served the drainer script to their users. The script monitored user activity and injected a fake modal window. This window prompted users to connect their wallets to secure their accounts. The prompt actually initiated a drainer transaction.

3. The Etherscan Advertising Aggregator Malvertising

In April 2024 ScamSniffer identified a malvertising campaign focused on Etherscan users. Attackers purchased advertising space through third party aggregators. These advertisements appeared on the legitimate Etherscan block explorer. The ads promoted fake token airdrops. Clicking the advertisement redirected users to a phishing domain hosting the Angel Drainer script. The campaign exploited the trust users place in the official block explorer. Advertising aggregators distribute ads across multiple platforms. The attackers exploited the automated approval processes of these aggregators. They submitted benign looking advertisements that passed initial security checks. Once the ads went live the attackers altered the destination URLs. The new URLs pointed to phishing sites. ScamSniffer noted that this method allowed the attackers to bypass direct scrutiny from Etherscan administrators.

4. The Galxe Web3 Credential Network Compromise

In October 2023 the syndicate attacked Galxe. Galxe operates as a Web3 credential data network. Attackers gained unauthorized access to the domain registrar account. They modified the DNS records to point to a fraudulent website. The fake site offered a fabricated airdrop reward. ScamSniffer data indicates that 1, 120 users interacted with the malicious smart contract. The attackers stole $270, 000 during the incident. The attackers bypassed security procedures using forged documents. They convinced the domain registrar to grant them access to the Galxe account. This allowed them to change the DNS routing. Users who had previously bookmarked the legitimate site were redirected to the malicious clone. The clone site featured a prominent Claim Airdrop button. Clicking this button initiated a smart contract interaction that drained the user wallet.

5. The Lottie Player Animation Library Exploit

In October 2024 attackers compromised the Lottie Player animation library. decentralized applications use this library to render animations. The syndicate injected malicious code into the widely distributed package. When users visited applications using the compromised library a fake airdrop pop up appeared. ScamSniffer reported that one victim lost 10 Bitcoin during this specific campaign. The stolen Bitcoin held a value of $723, 000. Thousands of websites integrate the Lottie Player library. The attackers gained access to the developer account and published a compromised version. The malicious code was designed to execute only when a Web3 wallet extension was detected in the user browser. This selective execution made the compromise difficult to detect during standard security audits. The fake pop up perfectly mimicked the styling of the host application.

6. The Blast Network fwDETH Restaking Phishing

ScamSniffer documented a massive single user theft in October 2024 on the Blast network. The victim interacted with a fraudulent airdrop link promoted on social media. The link directed the user to a phishing site running a drainer script. The user signed a malicious Permit signature. The attackers instantly drained 15, 079 fwDETH restaking tokens. The stolen assets held a market value of $5. 87 million at the time of the theft. The attackers used a technique called gasless phishing. The Permit signature allows a third party to execute a transaction on behalf of the user. The user only needs to sign a message off chain. This signature does not require the user to pay gas fees making it appear harmless. The attackers captured the signature and submitted it to the blockchain. This instantly transferred the fwDETH tokens to their control.

7. The Arbitrum Wrapped Bitcoin Theft

In November 2024 ScamSniffer reported another high value theft linked to fake airdrop promotions. A user on the Arbitrum network clicked a deceptive link offering free tokens. The phishing site requested a wallet connection and a signature to claim the reward. The user authorized the transaction. The drainer script executed a transfer of Wrapped Bitcoin. The attackers stole $409, 000 in a single transaction. The attackers used a Create2 address calculation method. This allowed them to generate a new deposit address for each victim. The unique addresses helped them evade detection by automated security scanners. The phishing site presented a fake progress bar indicating the airdrop claim was processing. In the background the script was transferring the Wrapped Bitcoin to the newly generated address.

8. The Uniswap Permit2 FET Token Drain

Attackers frequently exploit the Uniswap Permit2 signature standard. In November 2024 a phishing campaign focused on users holding FET tokens. The scammers distributed links to a fake airdrop claim page. The page instructed users to sign a Permit2 message to receive bonus tokens. This signature granted the attackers full control over the victim FET balance. ScamSniffer confirmed the theft of $344, 000 from a single wallet using this method. The Permit2 contract is a legitimate tool developed by Uniswap to streamline token approvals. The attackers exploited user unfamiliarity with this new standard. The phishing site presented a signature request that appeared to be a standard login message. The message actually contained the Permit2 parameters granting the attackers a massive allowance. The attackers then called the transferFrom function to drain the FET tokens.

9. The Fight Out Web3 Game Impersonation

Security researchers identified over 3, 000 domains registered by the Angel Drainer syndicate in early 2023. One prominent campaign impersonated a Web3 game called Fight Out. The attackers registered domains closely matching the official project. They promoted a fake token generation event and airdrop. Users connecting their wallets to claim the tokens unknowingly signed approval transactions. The drainer script emptied the connected wallets. The attackers created a sophisticated network of fake social media accounts to promote the Fight Out airdrop. They purchased followers and engagement to make the accounts appear legitimate. The phishing site featured high quality graphics and a detailed roadmap. The site also included a fake live feed showing other users successfully claiming the airdrop. This created a false sense of urgency and social proof.

10. The Revoke Cash Authorization Tool Clones

The syndicate deployed a highly deceptive campaign directed at security conscious users. They created exact replicas of Revoke Cash. Revoke Cash is a legitimate tool used to cancel active token approvals. The attackers promoted these fake sites through search engine advertisements. Users attempting to secure their wallets connected to the phishing sites. Instead of revoking permissions the users signed transactions granting the attackers unlimited access to their funds. The attackers used search engine optimization techniques to rank their fake Revoke Cash sites above the legitimate site. They also purchased sponsored search results. Users searching for Revoke Cash were presented with the malicious links at the top of the search results. The fake sites perfectly replicated the user interface of the legitimate tool. The only difference was the underlying smart contract logic.

11. The Stargate Finance Cross Chain Network Spoofing

ScamSniffer data revealed multiple phishing domains mimicking Stargate Finance. Stargate Finance operates as a cross chain liquidity network. The attackers circulated fake announcements claiming Stargate was conducting a retroactive airdrop for past users. The phishing sites perfectly replicated the Stargate user interface. Victims attempting to claim the fabricated airdrop authorized malicious smart contracts. The attackers drained the approved assets across multiple blockchain networks. The attackers monitored the official Stargate Finance communication channels. When the legitimate project announced a minor update the attackers launched their fake airdrop campaign. They claimed the update included a retroactive reward for early adopters. The phishing sites were hosted on domains with minor typographical errors. Users who did not carefully inspect the URL were easily deceived.

12. The Gemini Cryptocurrency Exchange Impersonation

The syndicate also attacked users of centralized exchanges. They registered domains impersonating the Gemini cryptocurrency exchange. The attackers sent direct emails and social media messages claiming Gemini was distributing a special airdrop to active traders. The links directed users to a Web3 interface requiring a wallet connection. ScamSniffer identified these domains as part of the broader Angel Drainer infrastructure. Users who connected their wallets and signed the claim transaction lost their holdings. The attackers used email spoofing techniques to make their messages appear to originate from official Gemini addresses. The emails contained personalized greetings and accurate trading history data obtained from previous data breaches. This level of personalization made the phishing emails highly convincing. The links in the emails directed users to a fake Gemini Web3 portal.

Summary of ScamSniffer Verified Phishing Campaigns

Campaign Name Date Reported Exploit Method Verified Financial Loss
Balancer Domain Name System Hijack September 2023 Domain Name System Routing Alteration $350, 000
Ledger Connect Kit Supply Chain Breach December 2023 Malicious JavaScript Injection $600, 000
Etherscan Advertising Aggregator Malvertising April 2024 Third Party Advertisement Phishing Undisclosed
Galxe Web3 Credential Network Compromise October 2023 Domain Registrar Account Takeover $270, 000
Lottie Player Animation Library Exploit October 2024 Node Package Manager Compromise $723, 000
Blast Network fwDETH Restaking Phishing October 2024 Gasless Permit Signature Phishing $5, 870, 000
Arbitrum Wrapped Bitcoin Theft November 2024 Create2 Address Generation Phishing $409, 000
Uniswap Permit2 FET Token Drain November 2024 Permit2 Allowance Exploitation $344, 000
Fight Out Web3 Game Impersonation Early 2023 Fake Token Generation Event Undisclosed
Revoke Cash Authorization Tool Clones 2023 Search Engine Advertisement Phishing Undisclosed
Stargate Finance Cross Chain Network Spoofing 2023 Typographical Error Domain Phishing Undisclosed
Gemini Cryptocurrency Exchange Impersonation 2023 Email Spoofing and Data Breach Use Undisclosed

Match Systems Investigations Tracking the 25 Million Dollar Cross Chain Money Laundering Routes

20 Investigative Questions Answered

Who investigated the money laundering routes of Angel Drainer? Match Systems conducted the primary blockchain forensics.

When did Match Systems announce the deanonymization of the developers? The firm published its findings on July 16, 2024.

How long did it take for the group to suspend operations after the announcement? The operators shut down the service two hours later.

Where is the headquarters of Match Systems? The blockchain intelligence firm operates out of Dubai, United Arab Emirates.

Who leads the Match Systems investigation team? Chief Executive Officer Andrey Kutin directs the forensics unit.

What commission rate did the developers charge their affiliates? The syndicate took a 20 percent cut of all stolen assets.

What initial deposit did affiliates pay to access the phishing tools? Operators required deposits between $5, 000 and $10, 000.

Which centralized exchange received the highest volume of stolen Ethereum from the Balancer attack? Binance received 1, 652. 67 ETH.

How much Ethereum moved through the eXch mixer? Attackers laundered 389. 29 ETH through this specific mixing service.

Did the syndicate use Tornado Cash? Yes, investigators traced 21 ETH directly to Tornado Cash during the Balancer exploit.

Which other centralized exchanges processed the stolen funds? The group routed funds through Bybit and OKX.

What exact volume of Ethereum went to Bybit? Forensics show 116. 57 ETH deposited into Bybit accounts.

How much Ethereum did the attackers send to OKX? The group transferred 25. 83 ETH to OKX.

Which privacy network saw increased use by the syndicate in 2024? The attackers routed funds through Railgun to obscure transaction histories.

Which cross chain networks facilitated the movement of stolen assets? The group used Thorchain, Swft, ChangeNOW, FixedFloat, and SimpleSwap.

What total financial damage did these specific laundering routes process? The network laundered over $25 million in stolen cryptocurrency.

How individual wallets fed into this laundering network? The stolen funds originated from 35, 000 compromised wallets.

Which other malware group sold its infrastructure to the syndicate? Inferno Drainer transferred its code to the group.

When did Inferno Drainer transfer its code to the operators? The transaction occurred in October 2024.

What action does Match Systems take after tracing the funds? The firm labels suspicious addresses and alerts exchanges to block withdrawals.

Match Systems Deanonymization Operation

On July 16, 2024, Dubai based blockchain intelligence firm Match Systems published a public notice regarding the identities of the Angel Drainer developers. Chief Executive Officer Andrey Kutin and his forensics team announced they had made progress in identifying the individuals behind the criminal syndicate. The firm urged victims to submit transaction data to assist in mapping the complete network of malicious addresses. Two hours after Match Systems posted the deanonymization update on social media, the operators of the phishing toolkit announced a total suspension of their services on their Telegram channel. Match Systems immediately began labeling the known addresses and alerting centralized exchanges to freeze the remaining stolen assets.

Match Systems uses specialized blockchain analytics tools to conduct open source intelligence gathering in jurisdictions where local police face difficulties obtaining information. The firm provides free incident analysis within minutes of a reported theft to assess recovery chances and freeze stolen assets fast. When the firm announced the deanonymization of the developers, they stated they had accumulated enough digital evidence to identify the core members of the criminal gang. The rapid shutdown of the Telegram channel indicated that the developers knew their operational security had failed. The firm did not publicly release the names of the developers, opting instead to work directly with centralized exchanges and law enforcement to intercept the physical cash out attempts.

The Financial Structure of the Syndicate

The operators ran a highly structured Drainer as a Service business model. Affiliates who wanted to use the malicious scripts to launch phishing campaigns had to pay an initial deposit ranging from $5, 000 to $10, 000. Security firm SlowMist reported that in premium tiers, the deposit requirement reached $40, 000. Once an affiliate successfully tricked a victim into signing a malicious contract approval, the automated smart contracts instantly routed a 20 percent commission to the core developers. The remaining 80 percent went to the affiliate. This automated split required a sophisticated network of intermediary wallets to process the funds before they reached their final destinations.

The Drainer as a Service model lowers the barrier to entry for novice cybercriminals. The core developers handle all the technical infrastructure, including the smart contract deployment, the obfuscation of the malicious JavaScript code, and the maintenance of the backend servers. The affiliates only need to focus on traffic generation. They achieve this by compromising official Discord servers, hijacking verified X accounts, and executing domain name system attacks. The 20 percent fee generated massive revenue for the core team without requiring them to execute the phishing campaigns directly. Scam Sniffer reported that in 2023 alone, drainer fees allowed these software providers to bank at least $47 million. The automated nature of the fee split means the blockchain permanently records the flow of funds, giving investigators a permanent trail to follow.

Tracing the Stolen Ethereum

Blockchain investigators mapped the exact routes used to clean the stolen assets. During the September 2023 Balancer domain name system hijacking attack, the syndicate stole hundreds of thousands of dollars in cryptocurrency. SlowMist and Match Systems analyzed the two levels of Ethereum transactions connected to the malicious addresses. The data revealed a clear preference for mixing services and centralized exchanges with varying compliance standards.

The laundering process begins the moment the victim signs the malicious approval. The smart contract executes a transferFrom function, sweeping the approved tokens into a temporary holding wallet. From there, the automated scripts swap the stolen ERC20 tokens, such as Chainlink, Lido Staked Ethereum, and MakerDAO stablecoins, into native Ethereum using decentralized exchanges. This consolidation step prepares the funds for the mixing phase.

The forensics data shows the exact distribution of the laundered Ethereum from these specific clusters. The attackers sent the largest volume directly to Binance. They used the eXch mixer to obscure the second largest portion. Bybit and OKX received smaller deposits, while Tornado Cash processed a specific fraction of the funds to break the on chain link.

Laundered Ethereum Distribution Chart

Destination Platform Platform Type Volume in ETH Visual Representation
Binance Centralized Exchange 1, 652. 67

eXch Mixing Service 389. 29

Bybit Centralized Exchange 116. 57

OKX Centralized Exchange 25. 83

Tornado Cash Decentralized Mixer 21. 00

Cross Chain Networks and Privacy Systems

The syndicate did not rely solely on Ethereum based mixers. To clean the $25 million extracted from 35, 000 wallets, the operators employed a multi chain laundering strategy. They moved assets across different blockchain networks using decentralized routers. Investigators tracked funds flowing through Thorchain, which allows native asset swaps without wrapped tokens. The attackers also used instant exchange platforms like ChangeNOW, FixedFloat, and SimpleSwap. These platforms frequently require minimal identity verification, making them attractive options for cybercriminals looking to convert stolen Ethereum or stablecoins into Bitcoin or Monero.

The attackers executed a specific sequence to move funds from the Ethereum network to the Tron blockchain. They used platforms like Swft to transfer the native Ethereum into Tether on the Tron network. Tron offers lower transaction fees and faster settlement times, making it a preferred network for illicit over the counter trading desks. Investigators identified specific over the counter brokers operating in jurisdictions with weak anti money laundering controls who facilitated the final conversion from Tether to fiat currency. The use of the Sinbad mixer also played a role in the Bitcoin laundering phase. The attackers moved funds to the Bitcoin network, ran them through Sinbad, and then used Thorchain to swap the cleaned Bitcoin back into Ethereum. This circular laundering method creates multiple breaks in the transaction graph, requiring investigators to collaborate across different blockchain analytics platforms to reconstruct the full sequence.

In 2024, blockchain security firms noted an increase in the use of Railgun by various phishing syndicates. Railgun provides zero knowledge privacy for smart contract interactions. Attackers routed stolen assets through this network to shield their transaction histories from public block explorers. Match Systems and other forensics teams had to deploy advanced heuristic analysis to trace the outputs from these privacy pools back to the centralized exchanges where the criminals attempted to cash out.

The Inferno Drainer Code Transfer

The ecosystem of malicious smart contracts consolidated in late 2024. Inferno Drainer, another major phishing syndicate, had previously stolen over $80 million from cryptocurrency users. After facing increased pressure from security researchers, the Inferno Drainer developers decided to exit the market. In October 2024, they sold their entire infrastructure and source code to the Angel Drainer syndicate. This transfer of technology allowed the remaining operators to integrate new evasion techniques and expand their cross chain capabilities. The acquisition shows how these criminal enterprises operate like traditional software companies, buying out competitors to acquire better technology and larger market shares.

Match Systems continues to monitor the new addresses generated by the upgraded AngelX toolkit. The forensics firm updates its database of malicious contracts daily, providing real time intelligence to exchanges and law enforcement agencies. By tracking the exact route the stolen funds take through mixers and cross chain networks, investigators can freeze the assets the moment they touch a compliant centralized platform.

Eight Decentralized Finance Platforms Weaponized for the Permit2 Exploit

Five Malicious Smart Contract Approval Mechanisms Exploited for Asset Exfiltration
Five Malicious Smart Contract Approval Mechanisms Exploited for Asset Exfiltration

20 Questions Answered: Platforms Weaponized by Angel Drainer

Question Answer
1. Which decentralized exchange created the Permit2 standard? Uniswap created the Permit2 standard.
2. How did attackers spoof Uniswap? Attackers registered fake domains with transposed letters to deceive users.
3. When did the Balancer domain hijacking occur? The Balancer domain hijacking occurred on September 19, 2023.
4. How much was stolen in the Balancer attack? Attackers stole at least $350, 000 from Balancer users.
5. What vulnerability did the Balancer attack exploit? The attack exploited domain name system hijacking via social engineering.
6. Which credential platform suffered a similar domain attack? Galxe suffered a similar domain hijacking attack.
7. When did the Galxe attack happen? The Galxe attack happened on October 6, 2023.
8. What number of users were affected in the Galxe breach? Approximately 1, 120 users were affected.
9. What was the financial impact of the Galxe breach? Users lost nearly $270, 000 in the Galxe breach.
10. Which hardware wallet provider had its library compromised? Ledger had its software library compromised.
11. What was the name of the compromised Ledger library? The compromised library was the Ledger Connect Kit.
12. When did the Ledger Connect Kit attack take place? The attack took place on December 14, 2023.
13. How much did the Ledger exploit drain? The exploit drained over $600, 000 in two hours.
14. Which decentralized exchange was affected by the Ledger exploit? SushiSwap was directly affected by the Ledger exploit.
15. How did attackers target Aave users? Attackers targeted Aave users through malicious Google Search advertisements.
16. How much did a single Aave user lose to a fake ad? A single user lost approximately $343, 000.
17. Which restaking network was targeted by a custom malicious function? EigenLayer was targeted by a custom malicious function.
18. What was the name of the malicious EigenLayer function? The malicious function was named queueWithdrawal.
19. Which nonfungible token marketplace saw users targeted by Permit2 phishing? OpenSea saw users targeted by Permit2 phishing.
20. How much was lost across OpenSea and other networks in January 2024? Users lost a combined $55 million.

1. Uniswap

Uniswap introduced the Permit2 smart contract to manage token approvals across different applications. Angel Drainer weaponized this exact standard to bypass traditional security checks. Attackers deployed automated site cloning tools to replicate the Uniswap interface. They registered deceptive domains with transposed letters to catch users making typographical errors. Once a user connected a wallet to the fake Uniswap site, the malicious script evaluated the token balances. The script then prompted the user to sign an off chain Permit2 message. This signature granted the attacker unlimited access to the user’s tokens without requiring an on chain transaction fee from the victim. Security researchers at SlowMist identified 73 concurrent phishing sites deployed under a single deceptive domain network targeting Uniswap users.

2. Balancer

On September 19, 2023, the decentralized finance platform Balancer suffered a domain name system hijacking attack. Attackers compromised the domain registrar account and redirected the official Balancer website to a malicious server controlled by Angel Drainer. The front end of the application contained a malicious JavaScript file. When users connected their wallets to the compromised site, the script automatically assessed their balances. The script then prompted users to sign an approval transaction followed by a Permit2 signature. Attackers used the transferFrom function to drain the approved tokens. Blockchain analytics firm MistTrack confirmed that the stolen funds flowed directly to Angel Drainer wallets. The attack resulted in a minimum of $350, 000 stolen from unsuspecting liquidity providers.

3. Galxe

The Web3 credential data network Galxe experienced a similar domain hijacking attack on October 6, 2023. An unidentified individual contacted the domain service provider Dynadot and posed as an authorized Galxe member. The attacker used forged documents to bypass security procedures and gain unauthorized access to the domain account. The attacker modified the domain name system records to redirect users to a fraudulent website. The fake site prompted users to sign transactions under the guise of claiming credential data. MistTrack analysis revealed direct interactions between the Galxe hacker addresses and Angel Drainer wallets. Approximately 1, 120 users interacted with the malicious site. The attackers siphoned nearly $270, 000 in digital assets before Galxe restored the domain on October 7.

4. Ledger Connect Kit

Angel Drainer orchestrated a supply chain attack on the Ledger Connect Kit on December 14, 2023. The Ledger Connect Kit is a software library used by decentralized applications to connect hardware wallets. Attackers compromised the Node Package Manager account of a former Ledger employee. They injected malicious JavaScript into versions 1. 1. 5 through 1. 1. 7 of the library. This malicious code executed automatically on any decentralized application that loaded the compromised library. The script deployed a hidden drainer payload that prompted users to sign malicious Permit2 transactions. Security firm SlowMist reported that Angel Drainer used smart contracts to manage the access domains of the malicious files. The attack drained over $600, 000 from users across multiple platforms in a two hour window.

5. SushiSwap

SushiSwap was one of the primary decentralized exchanges impacted by the Ledger Connect Kit supply chain attack. Because SushiSwap integrated the Ledger library for wallet connections, the malicious JavaScript loaded directly on the legitimate SushiSwap interface. Users visiting the authentic SushiSwap website encountered fraudulent prompts asking them to sign token approvals. The Angel Drainer script intercepted the wallet connection process and substituted legitimate transaction requests with malicious Permit2 signatures. Users who approved these requests unknowingly granted the attackers full access to their token balances. The incident forced SushiSwap developers to temporarily disable the Ledger integration and advise users to revoke any recent contract approvals.

6. Aave

Attackers weaponized the brand identity of the decentralized lending platform Aave through malicious search engine advertisements. Scammers purchased Google Search advertisements targeting keywords related to Aave smart contracts. These advertisements appeared at the top of search results and directed users to a highly convincing clone of the Aave interface. The fake site prompted users to connect their wallets and sign a transaction to manage their deposited assets. A single victim lost approximately $343, 000 worth of wrapped Ethereum after signing a malicious signature on the fake Aave site. On chain data showed the stolen funds moving to a malicious contract before being split between the phishing customer and the Angel Drainer administration wallets.

7. EigenLayer

Angel Drainer developed custom attack vectors to target users of the restaking network EigenLayer. In February 2024, security firm Blockaid detailed an attack where the phishing group implemented a malicious queueWithdrawal function. Attackers lured EigenLayer users to fraudulent websites offering fake restaking rewards. The site prompted users to sign a transaction that appeared to claim these rewards. The signature actually authorized the malicious queueWithdrawal function. This function diverted the user’s staking rewards directly to an address controlled by the attacker. Security providers failed to parse and validate this specific approval type because it was a new method. The transaction appeared benign to internal security tooling and bypassed standard warning systems.

8. OpenSea

The nonfungible token marketplace OpenSea saw its users targeted in a massive phishing campaign powered by Angel Drainer infrastructure. Attackers distributed fake promotional offers and airdrop claims through compromised social media accounts. Users who clicked the links landed on websites that mimicked the OpenSea interface. The sites requested off chain signatures to verify wallet ownership or claim free digital assets. These signatures were actually Permit2 approvals that granted the attackers control over the users’ tokens and nonfungible assets. Web3 scam tracker Scam Sniffer reported that approximately 40, 000 users across OpenSea and other networks fell victim to these phishing attacks in January 2024. The combined losses from these attacks reached $55 million.

Financial Impact Across Targeted Platforms

Stolen Funds by Platform Attack (USD) Balancer: $350, 000 Galxe: $270, 000 Ledger Connect Kit: $600, 000 Aave (Fake Ads): $343, 000

Six Key Social Engineering Tactics Used to Deceive Crypto Investors

Cybercriminals deploying the Angel Drainer toolkit rely on psychological manipulation to bypass security measures. Security researchers tracked multiple distinct methods used to trick victims into signing malicious smart contracts throughout 2024. The data reveals a highly organized criminal enterprise that exploits trust, urgency, and technical confusion.

1. Compromised Verified Social Media Accounts

Cybercriminals frequently attack verified accounts on platforms like X and Discord to distribute malicious links. Attackers use phishing or SIM swapping to take control of accounts belonging to prominent organizations and individuals. Once they secure access, the attackers broadcast announcements about fake token airdrops or exclusive minting events. The posts include links that direct followers to phishing websites hosted by drainer operators. In January 2024, criminals compromised the official social media accounts of the United States Securities and Exchange Commission and the threat intelligence firm Mandiant. The attackers used these trusted profiles to post links to cryptocurrency phishing sites. Victims who clicked the links believed they were claiming free tokens. Instead, they connected their wallets to malicious scripts that requested unauthorized asset transfers. A January 2025 report from Scam Sniffer revealed that phishing campaigns using these methods stole nearly 500 million dollars from over 332, 000 victims throughout 2024. The data shows that attackers created over 16, 000 unique domains to spoof more than 100 different cryptocurrency brands. The compromised accounts provide an air of legitimacy that convinces even experienced investors to authorize the malicious transactions.

2. Malicious Search Engine Advertisements

Fraudsters purchase advertisements on major search engines and social networks to intercept users looking for legitimate decentralized finance platforms. The attackers bid on keywords related to popular platforms like Zapper, Lido, and Radiant. When a user searches for these terms, the malicious advertisement appears at the top of the results. Clicking the link triggers redirect deception techniques that send the user to a cloned website. A December 2023 investigation by Infosecurity Magazine found that a single drainer campaign using Google and X ads stole 59 million dollars from 63, 000 victims. The attackers bypass ad platform audits by focusing on specific geographic regions and masking their final destination URLs. In October 2024, security researchers uncovered a Google ad scam promoting the Soneium blockchain project. The attackers loaded the landing page with hidden software designed to siphon cryptocurrency. To evade detection by Google security scanners, the phishing page initially masqueraded as an unfinished website for a radiology service. Once approved by the ad network, the page switched its content to the crypto drainer script. Scam Sniffer reported observing over 10, 000 phishing sites using these advertisement methods, demonstrating the massive size of the operation.

3. Address Poisoning Scams

Address poisoning manipulates the transaction history displayed inside a user wallet to trick them into sending funds to an attacker. Scammers deploy automated bots to monitor blockchain activity and identify active wallets. The bots study the transaction patterns of the victim to find frequently used recipient addresses. The attackers then algorithmically generate a new vanity address that matches the and last characters of the legitimate recipient. The scammer sends a transaction with a value of zero from the fake address to the victim wallet. This action places the fake address into the transaction history of the victim. When the victim later attempts to send funds to their regular contact, they copy the poisoned address directly from their history log. Chainalysis reported in October 2024 that an address poisoning attack in May nearly cost a single investor 68 million dollars in wrapped Bitcoin. The tactic proved so that even the operators of the Pink Drainer criminal group lost 30, 000 dollars to a rival address poisoning scam in July 2024. In response to the growing threat, cryptocurrency exchanges like Binance developed new algorithms specifically to detect and flag near zero value transfers associated with address poisoning.

4. Fake Token Revoker Services

Security platforms advise cryptocurrency users to regularly revoke unused smart contract approvals to protect their assets from future exploits. Scammers weaponized this security advice by creating fake approval requests. The attackers airdrop malicious tokens to a victim wallet and generate a fake approval notification on blockchain explorers. When the user sees the unfamiliar approval, they panic and attempt to revoke it using a block explorer or a dedicated revoker website. Binance researchers detailed in February 2025 how these fake approval scams trick users into paying exorbitant network fees. The scammers program the fake tokens to mint gas tokens during the revoke transaction. Gas tokens allow users to store cheap network computational power when demand is low. The malicious contract forces the victim wallet to mint a massive amount of these gas tokens and sends them directly to the attacker. The victim pays hundreds of dollars in transaction fees while believing they are securing their wallet. In April 2024, Reddit users reported receiving malicious contract allowances in their Coinbase Wallets that demanded up to 150 dollars in network fees just to process the revoke command. The fake approval remains visible on the blockchain explorer even after the failed transaction, prompting victims to try again and lose more money.

5. Domain Name System Hijacking

Attackers attack the foundational infrastructure of legitimate decentralized finance applications to intercept user traffic before it reaches the genuine application. The Angel Drainer group specializes in social engineering attacks directed at domain service providers. The attackers use forged documents and impersonation tactics to bypass security procedures at the domain registrar. Once they gain unauthorized access to the domain account, they modify the routing records. This modification redirects all legitimate user traffic to a fraudulent server controlled by the attackers. In September 2023, the Angel Drainer group executed a successful domain hijacking attack against the Balancer application. Users who typed the correct web address into their browsers were unknowingly routed to a malicious clone. SlowMist researchers discovered that the fake site contained JavaScript code that automatically assessed the balance of any connected wallet. The script then generated a malicious approval signature request. This specific attack resulted in the theft of 350, 000 dollars from 1, 120 users who believed they were interacting with the genuine application. The hijacking tactic is particularly dangerous because the victim does everything correctly, yet still lands on a compromised website.

6. Deepfake Video Endorsements

Criminals use artificial intelligence to generate highly realistic videos of prominent cryptocurrency executives promoting fraudulent schemes. The attackers train machine learning models on public appearances of industry leaders to clone their voices and facial expressions. The resulting deepfake videos are broadcast across social media platforms and live streaming services. In early 2024, scammers circulated deepfake videos of executives from a major cryptocurrency company on X and YouTube. The AI generated executives offered generous token airdrops to users who verified their accounts. The videos instructed viewers to visit a specific website and connect their wallets to claim the reward. Hackread reported in December 2024 that these social engineering campaigns specifically focus on retail investors who trust recognized industry figures. The websites featured in the videos hosted drainer scripts that immediately emptied the connected accounts. The attackers also use deepfake technology to impersonate journalists and security researchers. By fabricating endorsements from trusted sources, the scammers bypass the natural skepticism of the victims. The high production value of the fake live streams creates a false sense of urgency, pushing victims to sign the malicious transactions before they have time to verify the claims.

2024 Phishing Campaign Metrics by Tactic
Social Engineering Tactic Primary Delivery Channel Estimated Victims Notable Financial Loss Event
Compromised Social Accounts X, Discord, Telegram 332, 000 500 Million Dollars (Annual Total)
Search Engine Advertisements Google Ads, X Ads 63, 000 59 Million Dollars (Single Campaign)
Address Poisoning Blockchain Transaction History 2, 774 (Single Campaign) 68 Million Dollars (Single Victim)
Fake Token Revokers Block Explorers, Wallet Apps Undisclosed 150 Dollars (Per Transaction Fee)
Domain Name System Hijacking Domain Registrars 1, 120 (Balancer Attack) 350, 000 Dollars (Balancer Attack)
Deepfake Video Endorsements YouTube, X Live Streams Undisclosed Total Wallet Drain

Ten Demographic Clusters Among the 35000 Individual Victims Identified by On Chain Data

ScamSniffer Phishing Reports Detailing Twelve Fake Airdrop Campaigns
ScamSniffer Phishing Reports Detailing Twelve Fake Airdrop Campaigns

20 Demographic Questions Answered

How total wallets did Angel Drainer compromise? 35, 000 wallets.

What was the total financial damage inflicted by Angel Drainer? Over $25 million.

Which age group reported the highest financial losses to crypto scams in 2024? Victims aged 60 and older.

How much did the over 60 demographic lose to crypto investment fraud in 2024? They lost $1. 6 billion.

What percentage of scam victims fall into the 30 to 49 age bracket? This group makes up 41. 2 percent of victims.

Which age group represents 23. 4 percent of scam victims? Young adults aged 20 to 29.

How much did the top 20 high profile crypto victims lose in early 2024? They lost $58 million shared.

What was the single largest individual crypto theft recorded in early 2024? One victim lost $11 million.

Which messaging app saw a 2, 000 percent increase in crypto malware attacks? Telegram.

What specific hardware wallet community did Angel Drainer focus on? Ledger Connect Kit users.

How much was stolen during the Ledger Connect Kit exploit? Attackers stole $484, 000.

Which decentralized finance function did Angel Drainer exploit for restaking? The Eigenlayer queueWithdrawal function.

How wallets were drained in the February 2024 Safe Vault attack? 128 crypto wallets.

What blockchain networks saw the highest volume of stolen funds from Angel Drainer? Ethereum and Arbitrum.

What percentage of scam victims are youths aged 19 and under? They account for 6. 3 percent.

What is the median loss for scam victims aged 80 and older? The median loss is $25, 000.

What is the median loss for victims under the age of 19? The median loss is $505.

Which social media platforms are most used to contact the 30 to 49 demographic? Facebook and Telegram.

How phishing sites were identified in the broader Drainer as a Service ecosystem? Security researchers identified 32, 819 phishing sites.

What percentage of illicit profits did the top three drainer families capture? They captured 93. 9 percent of all illicit profits.

Cluster 1: High Net Worth Whales

On chain data shows a concentrated financial impact among a small group of high net worth individuals. Security firm Scam Sniffer tracked $58 million in losses attributed to just 20 high profile victims in early 2024. One individual victim lost $11 million in a single transaction. These users hold massive token balances and frequently interact with complex decentralized finance applications. Attackers use tailored spear phishing campaigns to deceive these specific individuals into signing malicious Permit2 transactions. The financial yield from this single cluster provides the bulk of the revenue for Drainer as a Service operators.

Cluster 2: The Over 60 Demographic

Data from the Federal Bureau of Investigation Internet Crime Complaint Center shows victims aged 60 and older face the most severe financial destruction. This age group reported $1. 6 billion in losses to cryptocurrency investment fraud in 2024. The median loss for victims aged 80 and older reached $25, 000. Operators focus on this demographic through tech support fraud and government impersonation schemes. The attackers guide these victims to cryptocurrency automated teller machines or instruct them to scan malicious Quick Response codes to authorize irreversible blockchain transfers.

Cluster 3: Middle Aged Professionals

Individuals between the ages of 30 and 49 represent the highest volume of total scam victims. ScamShield data indicates this group accounts for 41. 2 percent of all reported cases. Attackers contact these professionals through Facebook, WhatsApp, and Telegram. The operators lure them with fake investment opportunities and exclusive trading groups. This demographic possesses disposable income and actively seeks alternative investment vehicles. They frequently connect their primary wallets to unverified decentralized applications promoted in these private chat channels.

Cluster 4: Young Adult Retail Investors

Users aged 20 to 29 make up 23. 4 percent of the victim pool. This group actively participates in electronic commerce and social media trends. Scammers deploy fake token airdrops and non fungible token minting sites on platforms like X and Discord to capture their attention. These young adults connect their wallets to claim free digital assets. The malicious smart contracts then execute unauthorized transfers. The median loss for younger demographics remains lower than older groups, yet the sheer volume of attacks ensures a steady revenue stream for the drainer syndicates.

Cluster 5: Telegram Trading Communities

The Drainer as a Service ecosystem heavily focuses on users active on the Telegram messaging application. ForkLog reported a 2, 000 percent increase in malware attacks targeting crypto investors on Telegram between late 2024 and early 2025. Attackers deploy fake verification bots and distribute links to exclusive airdrop channels. When users click these links, malicious code hijacks their clipboard and downloads wallet draining scripts. This cluster consists of highly active traders who rely on instant messaging for market alpha and rapid transaction execution.

Cluster 6: Hardware Wallet Users

Angel Drainer specifically compromised users who relied on hardware wallets for enhanced security. The group executed the Ledger Connect Kit hack, stealing $484, 000 from victims. These users believed their offline storage devices protected them from online phishing. The attackers compromised the front end library used by decentralized applications to connect with Ledger devices. When victims approved what appeared to be standard decentralized finance transactions, the malicious code bypassed their perceived security and drained their hardware wallets.

Cluster 7: Restaking Farmers

A distinct cluster of victims emerged among users participating in complex yield farming strategies. Angel Drainer focused on the Eigenlayer restake farming community. The attackers exploited the queueWithdrawal function within the protocol. Victims authorized a malicious function that diverted their staking rewards directly to an attacker controlled address. This demographic consists of advanced cryptocurrency users who understand smart contract interactions failed to verify the specific destination addresses hidden within the complex approval requests.

Cluster 8: Safe Vault Administrators

In February 2024, Angel Drainer stole $400, 000 from 128 wallets by compromising users of Safe vault contracts. Safe, formerly known as Gnosis Safe, provides multi signature wallet solutions for decentralized autonomous organizations and high net worth individuals. The attackers deployed a malicious Safe vault contract that received automatic verification from the Etherscan block explorer. This verification flag instilled a false sense of security. The victims, who are cautious fund managers and organization administrators, signed Permit2 transactions that drained their corporate and personal treasuries.

Cluster 9: Cross Chain Arbitrageurs

On chain forensics by SlowMist identified Angel Drainer hot wallets spanning multiple blockchain networks. The Ethereum and Arbitrum chains saw the most significant volume of stolen funds. The victims in this cluster actively move assets across different networks to capture arbitrage opportunities and lower transaction fees. Phishing sites prompt these users to approve asset transfers on cheaper two networks like Arbitrum. The operators then use a TransferFrom function to execute multiple transfer calls in a single transaction, draining various assets simultaneously across different chains.

Cluster 10: Youth and Student Demographics

Victims aged 19 and under account for 6. 3 percent of the total compromised wallets. The median loss for this group sits at $505. Scammers focus on these younger users through online gaming platforms, electronic commerce sites, and social media giveaways. The attackers use malware like StealC and Atomic macOS Stealer to compromise their personal computers. These victims frequently operate with an absence of basic digital security hygiene and store their wallet seed phrases in plain text files on their desktops. The attackers harvest these credentials directly without needing the victim to sign a malicious contract.

Victim Age Demographics in 2024

Age Group Percentage Visual Representation
19 and under 6. 3%
20 to 29 23. 4%
30 to 49 41. 2%
50 to 64 20. 7%
65 and above 8. 4%

Four Infrastructure Providers Unwittingly Hosting Angel Drainer Frontends

20 Direct Questions Answered

What hosting platforms did Angel Drainer abuse. The group used Cloudflare Pages, Vercel, Firebase Hosting, and Netlify.

Why do attackers use legitimate infrastructure. Trusted domains bypass basic security filters and domain reputation checks.

How Cloudflare Pages subdomains hosted the drainer. Security researchers identified 530 malicious subdomains on the platform.

What timeframe did the Sucuri infrastructure analysis cover. The analysis examined data from January 26, 2024 to February 21, 2024.

How Vercel subdomains were detected. The data showed 183 phishing pages hosted on Vercel.

Which Google service hosted Angel Drainer sites. The attackers used Firebase Hosting for their deployments.

How Firebase subdomains were identified. Researchers found 139 malicious subdomains on Firebase.

What role did Netlify play in the attacks. The platform hosted fake CAPTCHA pages and malicious wallet connection interfaces.

How do attackers bypass domain reputation filters. They deploy scripts on subdomains of highly trusted enterprise platforms.

What is a fallback script in this context. It is a secondary code source used if the primary malicious script gets blocked.

Which placeholder domain did the drainer use for tracking. The developers used the lorem ipsum domain name in their requests.

How total unique domain names did URLScan detect in the 27 day window. The scanner recorded 5, 751 unique domain names.

What percentage of the top level domains were. com. The. com extension accounted for 1, 639 of the unique domains.

How do fake CAPTCHA pages assist the drainer. They create a false sense of security before the user connects their wallet.

What is the primary evasion technique against antiphishing tools. The script overrides the Ethereum provider request method to hide remote procedure calls.

How did the attackers use the lorem ipsum domain. They used it as a placeholder in their fallback script URLs to track deployments.

What happens when a user signs a transaction on these hosted pages. The smart contract transfers the assets to a third party wallet.

Why do security scanners struggle to block these subdomains. The subdomains rotate rapidly and share IP addresses with legitimate applications.

What specific Cloudflare domain extension was abused. The attackers heavily used the pages. dev extension.

How did the attackers automate the deployment of these sites. They used the continuous integration features of these hosting providers to deploy code from GitHub repositories.

Exploiting Enterprise Content Delivery Networks

Angel Drainer operators systematically abused free tier hosting services provided by major technology companies to deploy their malicious frontends. By hosting phishing sites on trusted infrastructure, the attackers bypassed standard domain reputation filters. Security systems evaluate the base domain of a website to determine its risk level. Platforms like Cloudflare, Vercel, Google, and Netlify maintain high trust scores because they host millions of legitimate enterprise applications. The attackers registered thousands of subdomains on these platforms to mask their illicit activities.

A detailed analysis by Sucuri published on February 21, 2024 examined URLScan data over a 27 day period. The researchers tracked the deployment of Angel Drainer scripts using a specific placeholder request to a nonexistent lorem ipsum domain. This tracking method revealed the massive of the infrastructure abuse. The scanner recorded 5, 751 unique domain names hosting the drainer script between January 26, 2024 and February 21, 2024. The data exposed four primary infrastructure providers that unwittingly hosted the majority of these malicious applications.

Cloudflare Pages and the Pages. Dev Subdomains

Cloudflare Pages emerged as the most heavily abused platform in the dataset. The service allows developers to deploy static websites quickly. Angel Drainer operators deployed 530 unique phishing pages using the pages. dev subdomain extension. Attackers created deceptive URLs like securedkey. pages. dev to trick victims into believing they were accessing official cryptocurrency portals. The use of Cloudflare infrastructure provided the attackers with enterprise grade distributed denial of service protection and fast global content delivery. This ensured the phishing sites loaded instantly for victims across different geographic regions.

The speed and reliability of Cloudflare Pages worked to the advantage of the attackers. When a victim clicked a malicious link on a social media platform, the site rendered immediately. The fast load times reduced the window for the victim to reconsider their actions. Security vendors struggled to block these sites because blacklisting the entire pages. dev domain would break thousands of legitimate websites. The attackers rotated their subdomains continuously to stay ahead of targeted takedowns.

Vercel and the Vercel. App Subdomains

Vercel ranked as the second most exploited infrastructure provider. The platform specializes in hosting frontend frameworks like. js. The Sucuri analysis identified 183 malicious subdomains using the vercel. app extension. The attackers crafted URLs such as coinbasewalletconnectv4. vercel. app to impersonate legitimate wallet connection services. Vercel offers continuous deployment features that pull code directly from Git repositories. The drainer operators used this functionality to automate the rollout of new phishing sites.

When security researchers reported a malicious Vercel subdomain, the hosting provider would take it offline. The attackers simply pushed a new commit to their repository, and Vercel automatically generated a fresh subdomain with the identical malicious payload. This automated deployment pipeline allowed the Angel Drainer group to maintain a persistent presence on the web even with active takedown efforts from security teams.

Google Firebase Hosting and the Web. App Subdomains

Google Firebase Hosting served as the third major pillar of the Angel Drainer frontend infrastructure. The service provides fast and secure hosting for web applications. Researchers found 139 phishing sites operating on the web. app subdomain extension. Attackers used names like paperholdnet. web. app to host their deceptive interfaces. Firebase Hosting includes automatic secure sockets certification, which gave the phishing sites a padlock icon in the browser address bar. This visual indicator of security further deceived victims into trusting the malicious pages.

The integration of Firebase with other Google Cloud services provided the attackers with a highly resilient hosting environment. The global content delivery network backed by Google ensured high availability. The attackers exploited the free tier limits of Firebase to host their lightweight frontend scripts without incurring financial costs. The infrastructure absorbed the traffic spikes generated during large phishing campaigns distributed via social media.

Netlify and Fake CAPTCHA Gateways

Netlify provided the fourth major hosting environment for the Angel Drainer operations. Threat intelligence reports from PhishDestroy documented the extensive use of the netlify. app extension. Attackers deployed domains like trezorren. netlify. app to impersonate hardware wallet manufacturers. The operators specifically used Netlify to host fake CAPTCHA verification pages. These deceptive gateways required users to complete a visual puzzle before accessing the main site.

The fake CAPTCHA pages served a dual purpose. They filtered out automated security scanners that could not solve the puzzle, keeping the malicious payload hidden from threat intelligence bots. They also conditioned the victim to comply with instructions. After passing the fake security check, the user landed on the actual drainer interface. The psychological manipulation increased the probability that the victim would approve the subsequent malicious smart contract signature.

Infrastructure Abuse Metrics

The distribution of the malicious subdomains highlights the systematic exploitation of free hosting tiers. The table details the specific infrastructure providers and the number of identified phishing subdomains during the 27 day observation window.

Infrastructure Provider Subdomain Extension Identified Phishing Sites Example Malicious URL
Cloudflare Pages pages. dev 530 securedkey. pages. dev
Vercel vercel. app 183 coinbasewalletconnectv4. vercel. app
Google Firebase web. app 139 paperholdnet. web. app
Netlify netlify. app 100 plus trezorren. netlify. app

The Angel Drainer operators demonstrated a clear preference for platforms that offered automated deployments, free secure sockets certificates, and global content delivery networks. By distributing their frontends across four different enterprise providers, they created a highly redundant infrastructure. If one provider initiated a mass takedown of their subdomains, the attackers instantly shifted their traffic to the remaining platforms. This architectural redundancy allowed the group to steal over 25 million dollars in cryptocurrency assets throughout 2024.

Operational Security and Financial Impact

The use of legitimate hosting providers directly contributed to the financial success of the Angel Drainer group. By eliminating server costs and maintenance overhead, the developers focused entirely on refining their malicious smart contracts and evasion techniques. The free tiers offered by Cloudflare, Vercel, Firebase, and Netlify provided unlimited bandwidth for their phishing campaigns. This zero cost infrastructure model allowed the group to their operations globally without leaving a financial paper trail.

Traditional cybercriminals purchase bulletproof hosting using cryptocurrency, which leaves a traceable ledger of transactions. The Angel Drainer operators avoided this exposure completely. They registered free accounts using disposable email addresses and routed their connections through proxy networks. When a hosting provider suspended an account for terms of service violations, the attackers simply registered a new free account and resumed operations within minutes.

The financial damage facilitated by this infrastructure abuse reached 25 million dollars in 2024. The high availability of the phishing sites ensured that victims could access the malicious frontends at any time. The attackers synchronized their infrastructure deployments with major cryptocurrency events. When a legitimate project announced a token distribution, the Angel Drainer group deployed dozens of cloned websites across their four primary hosting providers simultaneously. This coordinated deployment strategy overwhelmed security researchers and guaranteed that at least one malicious frontend remained active during the peak hours of the token event.

The reliance on enterprise content delivery networks also defeated geographic blocking attempts. Legitimate projects restrict access from certain countries to comply with local regulations. The phishing sites hosted on global edge networks remained accessible worldwide. This global reach expanded the pool of chance victims and maximized the illicit revenue generated by the drainer toolkit. The infrastructure strategy employed by the Angel Drainer developers represents a highly optimized method for conducting large cryptocurrency theft.

Three Primary Obfuscation Techniques Bypassing Standard Web3 Security Alerts

Match Systems Investigations Tracking the 25 Million Dollar Cross Chain Money Laundering Routes
Match Systems Investigations Tracking the 25 Million Dollar Cross Chain Money Laundering Routes

The Evasion Architecture of Angel Drainer

Security firms deployed new transaction simulators and malicious domain blacklists throughout 2024 to stop unauthorized cryptocurrency transfers. The developers behind Angel Drainer responded by engineering three specific obfuscation techniques to blind these defense systems. The malicious script bypassed standard Web3 security alerts by manipulating browser communication, exploiting Ethereum Virtual Machine opcodes, and hiding payloads inside compiled WebAssembly modules.

Technique 1: RPC Call Redirection via Alternate Invocation

Standard decentralized applications communicate with cryptocurrency wallets using JavaScript libraries like ethers. js or web3. js. The wallet software injects an application programming interface called the Ethereum Provider directly into the webpage. This provider manages the JSON RPC requests between the website and the wallet extension. Security tools and browser extensions monitor this specific provider interface to intercept and analyze pending transactions before the user signs them.

Security researcher Bernhard Mueller published an analysis in April 2024 detailing how Angel Drainer bypasses this monitoring level. The malicious script actively overrides the standard request method within the browser environment. The standard protocol requires the decentralized application to call window. ethereum. request to initiate a transfer. Security extensions hook into this specific JavaScript object. They intercept the payload, analyze the destination address, and display a warning overlay if the address matches a known threat database.

Angel Drainer circumvents this hook entirely. The script constructs the raw JSON payload and transmits it using window. postMessage. This native browser function allows direct communication between the webpage and the background script of the wallet extension. The security tool remains completely blind to the transmission because it only monitors the window. ethereum object. The wallet receives the message, assumes it passed standard security checks, and presents the signing prompt to the user.

The security platform Revoke. cash categorized this method as an Alternate Invocation bypass in May 2024. The phishing defense extension waits for traffic on the standard provider interface. The traffic never arrives because the drainer routes the communication through a different channel. The malicious request reaches the wallet extension directly. The security tool registers zero anomalous activity and fails to trigger a warning interface. The wallet prompts the user to approve the transaction without any red flags from the installed security software.

This interception bypass creates a blind spot for transaction simulators. The security tools fail to detect the drainer unless the specific phishing domain already exists on a static blacklist. The developers specifically targeted MetaMask with this window. postMessage routing technique while deploying a different alternate invocation method for Coinbase Wallet users.

Technique 2: Counterfactual Deployment Using the CREATE2 Opcode

Transaction simulators like Blockaid protect users by analyzing pending transfers against databases of known malicious addresses. If a user attempts to approve a token transfer to a flagged smart contract, the simulator blocks the transaction. Angel Drainer defeats this behavioral analysis by utilizing the CREATE2 opcode to generate unmarked contract addresses.

The Ethereum Virtual Machine uses the CREATE opcode to deploy smart contracts to addresses calculated from the creator address and a nonce. The CREATE2 opcode allows developers to calculate a future smart contract address deterministically using the creator address, a custom salt value, and the contract bytecode. This feature allows developers to know the exact blockchain address of a contract before it actually exists on the network.

Angel Drainer operators weaponized this feature to bypass static analysis. When a victim connects to the phishing site, the script evaluates the total value of the assets in the wallet. If the value exceeds a predefined threshold, the drainer generates a unique salt and calculates a new target address using CREATE2. The script configures the phishing site to request token approvals for this specific empty address.

The transaction simulator checks the target address. The blockchain shows zero transaction history and no deployed bytecode at that location. The simulator returns a safe status because the address appears completely benign. The user signs the Permit2 message or the token approval transaction. The attacker immediately receives the signature on their backend server.

The attacker then broadcasts a contract deployment transaction to the network. The malicious smart contract materializes at the exact precalculated address. The contract instantly uses the victim signature to execute a transfer function. The assets move from the victim wallet to the attacker wallet. Bitget reported this evasion tactic in May 2024, noting that the nested smart contract operations successfully obscured the transaction flow from standard security alerts. SlowMist recorded millions in losses linked to similar CREATE2 address poisoning techniques throughout the year.

Technique 3: Runtime Extraction via WASM Modules

Cybersecurity companies deploy automated web scanners to index compromised websites and blacklist phishing domains. These scanners hunt for specific variable names, function calls, and code structures associated with known wallet drainers. Angel Drainer developers hide their core logic from these scanners using advanced compression and runtime extraction.

The drainer payload arrives on the phishing site or the compromised WordPress installation as a string encoded in base64. This string contains JavaScript that has been compressed with the xz algorithm and further scrambled using obfuscator. io. The HTML file on the server contains only a compiled WebAssembly binary and the encoded string. When a security scanner reads the file, it sees no recognizable malicious patterns. The scanner categorizes the site as safe.

The true execution happens only when a real user visits the webpage. The browser loads the WebAssembly module. The module decodes the base64 string into memory. The WebAssembly code then executes an xz decompression algorithm to extract the archive. The browser executes the raw JavaScript to render the phishing interface and initialize the wallet connection.

This runtime extraction prevents static code analysis tools from reading the payload. The Sucuri SiteCheck platform detected Web3 drainer malware on 9, 966 websites in the half of 2024. GoDaddy reported 23, 372 infected sites across the entire year. The distribution network for these obfuscated payloads relied heavily on compromised Web2 infrastructure. Attackers exploited known flaws in WordPress plugins to inject the WebAssembly modules into legitimate websites.

The Sucuri report highlighted that the Sign1 malware campaign accounted for a massive portion of these injections. The malware employed evasive tactics like URL creation with time randomized generation and XOR encoding to fetch the drainer scripts. Once the PHP server level redirect or the browser level JavaScript executed, the site loaded the Angel Drainer WebAssembly module. Visitors reading a standard blog post or shopping on a retail site would suddenly face a popup demanding a wallet connection to verify their identity. The runtime extraction guaranteed that the hosting provider and the website owner remained unaware of the malicious activity until users reported stolen funds.

Summary of 2024 Evasion Tactics

The combination of these three techniques allowed the malware to operate without detection across thousands of domains. The table details the specific level targeted by each obfuscation method.

Obfuscation Technique Targeted Security Level Bypass Method Discovery Timeline
Alternate Invocation Browser Phishing Defense Extensions Routes JSON RPC calls directly to the wallet via window. postMessage to evade the injected Ethereum Provider API. April 2024
CREATE2 Counterfactual Deployment Transaction Simulators Requests approvals for empty addresses and deploys the malicious contract only after the victim signs the transaction. May 2024
WASM xz Decompression Automated Web Scanners Hides the core JavaScript payload inside an archive encoded in base64 that extracts only during runtime in the browser. September 2024

Security vendors eventually updated their detection algorithms to catch these specific patterns. Blockaid implemented new checks for CREATE2 address generation. Extension providers patched the alternate invocation flaws. The operators behind the malware responded by shutting down the original infrastructure in July 2024 and launching the upgraded AngelX toolkit in August 2024 to deploy new evasion methods.

Nine Specific Malicious Signatures Identified Across the Ethereum Virtual Machine Networks

20 Technical Questions Answered

1. What is eth sign? An Ethereum method that allows users to sign arbitrary data payloads.

2. Why do attackers use eth sign? The method displays unreadable hexadecimal code to the user instead of clear text.

3. What is blind signing? The act of approving a transaction without reading the human readable contract details.

4. What does the approve function do? It grants a smart contract permission to spend a specific ERC20 token balance.

5. How do drainers exploit the approve function? Attackers request unlimited token allowances to drain the entire balance at once.

6. What is setApprovalForAll? A function that grants an operator control over an entire NFT collection.

7. Which assets does setApprovalForAll attack? The function attacks ERC721 and ERC1155 non fungible tokens.

8. What is the Permit function? An EIP2612 standard that allows users to approve token transfers via off chain signatures.

9. How does Permit enable gasless phishing? Victims sign a message without paying gas fees directly.

10. What is Permit2? A Uniswap platform feature that batches token approvals.

11. Why do attackers use Permit2? The platform allows drainers to steal multiple different tokens in a single transaction.

12. What is transferFrom? A function that moves tokens from one address to another after approval.

13. How does transferFrom automate theft? Smart contracts execute the function immediately after a victim signs an approval.

14. What is Create2? An Ethereum opcode that calculates a contract address before deployment.

15. How does Create2 bypass security blocklists? Attackers generate new addresses to evade static security filters.

16. What are deceptive payable functions? Smart contract functions named claim or mint that actually sweep native Ethereum.

17. How do fake claim functions steal funds? The functions require users to send a payable value that goes directly to the attacker.

18. What is eth signTypedData? An EIP712 standard designed to make signatures readable.

19. How do attackers obfuscate EIP712 messages? Drainers use misleading domain separators and variable names to hide malicious intent.

20. How do drainers split stolen funds on chain? Automated contracts route 80 percent of stolen assets to affiliates and 20 percent to the core developers.

Security researchers from BlockSec and Check Point identified specific smart contract functions used by the Angel Drainer organization. The group deployed malicious scripts across the Ethereum Virtual Machine networks to steal digital assets. The toolkit intercepts user interactions and replaces legitimate transaction requests with malicious approval signatures. The architecture relies on manipulating standard Ethereum improvement proposals. The developers built a system that adapts to the specific assets held in a victim wallet. The script scans the wallet balance and selects the most signature type to extract the maximum value. The organization operates a Drainer as a Service model. The core developers rent the software to affiliates who distribute the phishing links. The smart contracts automatically split the stolen funds between the affiliate and the core team.

Verified Drainer Group Profits (March 2023 to April 2025)

Inferno Drainer
$59. 0 Million
Angel Drainer
$53. 1 Million
Pink Drainer
$14. 7 Million

Data Source: BlockSec Academic Research Report (October 2025)

1. The eth sign Blind Signing Method

The eth sign method represents the oldest and most dangerous signature type on the Ethereum network. The function asks users to sign a raw hexadecimal string. The interface provides no human readable context regarding the transaction details. Attackers used this method during the December 2023 Ledger Connect Kit exploit. The Angel Drainer script injected malicious code into decentralized applications to force hardware wallet users to sign these unreadable messages. The signature grants the attacker full authority to execute arbitrary transactions on behalf of the victim. Security providers strongly advise users to disable eth sign functionality in their wallet settings. The Ethereum community continues to push for clear signing standards to replace this outdated method.

2. The ERC20 approve Function

The standard approve function allows a third party smart contract to spend a specific amount of tokens from a user wallet. Angel Drainer scripts manipulate this function by requesting an unlimited token allowance. The script populates the amount parameter with the maximum possible integer value. Victims believe they are verifying their identity or connecting to a decentralized exchange. The signature actually gives the drainer contract permanent permission to transfer the entire balance of the specified ERC20 token. The attacker can execute the theft immediately or wait for the wallet balance to increase. Users must manually revoke these approvals using third party tools to secure their accounts after interacting with a malicious site.

3. The setApprovalForAll NFT Authorization

The setApprovalForAll function exists within the ERC721 and ERC1155 non fungible token standards. The function requires a boolean value of true or false. Angel Drainer interfaces present fake minting pages that prompt users to sign this transaction. The signature grants the attacker operator status over the entire NFT collection held by the victim. The drainer script then transfers all high value digital collectibles to a centralized attacker wallet in a single block execution. The attacker bypasses individual token transfer limits by gaining blanket authority over the entire contract address associated with the user.

4. The EIP2612 Permit Gasless Signature

The EIP2612 standard introduced the Permit function to improve user experience by eliminating initial gas fees for token approvals. Users sign an off chain message to authorize a spender. Angel Drainer exploits this standard by disguising the signature request as a simple website login prompt. The victim signs the message without paying transaction fees. The attacker receives the cryptographic signature and submits it to the blockchain while paying the gas fee themselves. This method bypasses traditional transaction warnings because the initial interaction occurs entirely off chain. The victim only realizes the theft occurred when the tokens leave their wallet minutes later.

5. The Uniswap Permit2 Batch Authorization

Uniswap developed the Permit2 smart contract to manage token approvals across multiple decentralized finance platforms. The architecture allows users to sign a single off chain message to approve multiple different tokens simultaneously. Angel Drainer integrated Permit2 support to maximize extraction speed. The malicious script scans the victim wallet for all valuable assets and generates a single Permit2 signature request. Once the victim signs the message, the drainer contract gains simultaneous access to the entire portfolio. The attacker sweeps all approved tokens in one subsequent transaction. This batch processing capability makes Permit2 one of the most destructive tools in the drainer arsenal.

6. The transferFrom Automated Sweeping Function

The transferFrom function executes the actual theft after a victim signs an approve or Permit message. Angel Drainer operates automated smart contracts that monitor the blockchain for successful malicious approvals. The system immediately calls the transferFrom function to move the assets from the victim wallet to the attacker address. The researchers at BlockSec found that these contracts automatically split the stolen funds. The code routes 80 percent of the assets to the affiliate who deployed the phishing site and 20 percent to the core Angel Drainer developers. The automated execution ensures the victim has no time to revoke the approval before the funds disappear.

7. Deceptive claim and mint Payable Functions

Drainer scripts attack native Ethereum balances by deploying custom smart contracts with deceptive function names. The attacker names the function claim, mint, or SecurityUpdate. The phishing website prompts the user to execute this function to receive a fake airdrop. The transaction requires the user to attach a payable value equal to their entire native Ethereum balance. The smart contract receives the funds and immediately forwards the Ethereum to the attacker wallet. The function name provides a false sense of security to users who inspect the transaction details. The wallet interface displays a benign action while the underlying code executes a total balance transfer.

8. The Create2 Deterministic Address Deployment

The Create2 opcode allows developers to calculate a smart contract address before deploying the actual code to the blockchain. Angel Drainer uses this opcode to bypass static security blocklists. Security providers flag known malicious contract addresses to warn users. The drainer script generates a new, unflagged address for every single victim using Create2. The script prompts the victim to approve the unflagged address. The attacker deploys the malicious contract to that exact address only after the victim signs the approval. This technique renders static address blocklists completely ineffective. The security industry must rely on transaction simulation to detect these attacks.

9. The EIP712 eth signTypedData Obfuscation

The EIP712 standard structures signature data to make it readable in wallet interfaces. Developers use the eth signTypedData method to display the exact parameters a user is signing. Angel Drainer manipulates this standard by using misleading domain separators and variable names. The script populates the structured data with benign sounding terms like VerifyIdentity or SecureLogin. The underlying cryptographic parameters still grant the attacker full control over the specified assets. The visual deception convinces users to authorize the transaction based on the fake variable names displayed in their wallet. The attacker exploits the trust users place in formatted signature requests.

Regulatory and Law Enforcement Responses Across Five Global Jurisdictions

20 Law Enforcement and Regulatory Questions Answered

1. Which international operation focused on approval phishing scams in 2024? Operation Spincaster focused on wallets used by scam groups to steal funds.

2. How law enforcement agencies participated in Operation Spincaster? Twelve law enforcement agencies participated in the joint venture.

3. What was the primary goal of Operation Spincaster? The operation aimed to shut down wallets executing approval phishing scams.

4. Which firm partnered with police for Operation Spincaster? Chainalysis partnered with 17 cryptocurrency exchanges and police forces.

5. How much cryptocurrency did the DOJ seize in June 2025? The United States Department of Justice seized $225. 3 million in digital assets.

6. What did the FBI 2024 Internet Crime Report state about cryptocurrency fraud losses? The report recorded $5. 8 billion in reported losses from cryptocurrency investment fraud.

7. When did Singapore amend its Payment Services Act? The Monetary Authority of Singapore introduced amendments on April 2, 2024.

8. What new requirement did Singapore impose on Digital Payment Token providers in 2024? Providers must segregate customer assets and place them in a trust account.

9. What is the penalty for violating Singapore’s June 2025 cryptocurrency regulations? Violators face fines up to 250, 000 Singapore dollars and up to three years in prison.

10. Which European agency led the 700 million euro cryptocurrency fraud bust in late 2025? Europol coordinated the international operation.

11. How suspects were arrested during the October 2025 Europol raids? Police arrested nine suspects across Cyprus, Germany, and Spain.

12. Where did the Spanish Guardia Civil arrest suspects in June 2025? Officers apprehended three suspects in the Canary Islands and two in Madrid.

13. How much did Operation Borrelli seize in cryptocurrency fraud? The operation shut down a group that laundered 460 million euros.

14. Why was Telegram’s CEO arrested in France in August 2024? French authorities arrested Pavel Durov for failing to moderate illegal activities on the platform.

15. How did the Telegram arrest affect Angel Drainer? The group shifted its main activity to other platforms to avoid law enforcement tracking.

16. Which messaging platforms do cryptocurrency drainers use? Operators migrated to private messaging systems developed internally.

17. What is the role of the US Secret Service in cryptocurrency drainer investigations? The agency leads investigations into international money laundering schemes alongside the FBI.

18. How do European authorities track stolen cryptocurrency assets? Investigators use blockchain analysis to trace funds moved across multiple exchanges.

19. What deadline did Singapore set for unlicensed overseas cryptocurrency operations? Firms must cease operations by June 30, 2025.

20. Which countries participated in the November 2024 Europol action day? Law enforcement from Belgium, Bulgaria, the Netherlands, Spain, and the United States participated.

Global Law Enforcement Cryptocurrency Seizures

Operation and Jurisdiction Date Seized Value in USD Equivalent
Operation Borrelli in Spain June 2025
$540, 000, 000
DOJ Civil Forfeiture in United States June 2025
$225, 300, 000
Malaga Action Day in Spain November 2024
$29, 000, 000
October Raids by Europol October 2025
$483, 500

United States Department of Justice and Federal Bureau of Investigation

The United States Department of Justice and the Federal Bureau of Investigation aggressively pursue cryptocurrency drainer operators. In July 2024, the agencies participated in Operation Spincaster. This joint venture included Chainalysis, 17 cryptocurrency exchanges, and 12 law enforcement agencies. The operation successfully shut down wallets used by scam networks to steal funds from victims using approval phishing scams. These scams trick victims into allowing a rogue smart contract to spend assets from their wallets. In October 2024, the Federal Bureau of Investigation arrested a suspect in Alabama connected to the January 2024 unauthorized takeover of the United States Securities and Exchange Commission social media account. The hacker posted a fake message about Bitcoin exchange traded funds, causing the value of Bitcoin to spike by $1, 000. The suspect used a SIM swapping scheme to gain control of the account. The Federal Bureau of Investigation recorded $5. 8 billion in reported losses from cryptocurrency investment fraud in its 2024 Internet Crime Report. To combat this financial crime, the Department of Justice filed a civil forfeiture complaint in June 2025 to seize $225. 3 million in cryptocurrency. The United States Secret Service and Federal Bureau of Investigation field offices in San Francisco led the investigation into these blockchain based schemes. The seized digital assets represent proceeds from cryptocurrency confidence scams that lure victims under the pretense of high return investments.

European Union Agency for Law Enforcement Cooperation

Europol coordinates major actions against cryptocurrency fraud across member states. In June 2025, Europol announced the conclusion of Operation Borrelli. This international effort shut down a cryptocurrency investment fraud ring that laundered 460 million euros from more than 5, 000 victims. The investigation started in 2023 and culminated in five arrests on June 25, 2025. Scammers used social engineering tricks to keep the illusion of high returns going. Once victims deposited money, the operators moved the funds across multiple accounts to obscure their origin. In late 2025, Europol executed another massive operation against a criminal network that laundered over 700 million euros. The operation occurred in two phases. On October 27, 2025, police carried out coordinated raids across Cyprus, Germany, and Spain. Authorities arrested nine suspects and seized 800, 000 euros in bank accounts, 415, 000 euros in cryptocurrencies, and 300, 000 euros in cash. Authorities confiscated three servers, the platform domain, more than 25 million euros in Bitcoin, and over 12 terabytes of operational data. The criminal network operated numerous fake cryptocurrency investment platforms. They lured thousands of victims with advertisements promising high returns. The perpetrators contacted the victims repeatedly from call centers and used social engineering tactics to pressure them into making investments on the fake trading platforms. The second phase in November 2025 focused on the affiliate marketing infrastructure supporting these online scams.

France National Police and Cyber Command

French authorities took direct action against the infrastructure enabling cryptocurrency drainers. On August 24, 2024, French police arrested Telegram Chief Executive Officer Pavel Durov outside Paris. Authorities accused Durov of failing to moderate illegal activities on the instant messaging network. Prosecutors accused Durov of complicity in the distribution of illegal content on the instant messaging network he runs. The charges he faces carry a sentence of up to 10 years in prison. Telegram served as the primary communication and sales channel for cryptocurrency drainer developers. The arrest directly impacted groups like Angel Drainer. Following the arrest, Angel Drainer and other cybercrime groups shifted their main activity to alternative platforms. Security researchers observed these groups migrating to private messaging systems developed internally. Cybercriminals cannot manage their communications from their own servers on Telegram due to its centralized infrastructure. A report by cybersecurity firm Kaspersky found that criminals are beginning to quit Telegram. Analysts tracked 800 criminal channels blocked between 2021 and 2024. They concluded that the platform is tightening its policies, significantly accelerating the rate of closures. The risk and reward ratio is changing for scammers. Established cybercrime groups specializing in selling malware as a service have begun to shift their main activity to other platforms. The French enforcement action forced drainer operators to rebuild their communication networks, temporarily slowing their ability to sell malicious scripts to affiliates.

Monetary Authority of Singapore

The Monetary Authority of Singapore enforces strict regulations on cryptocurrency service providers to protect retail customers. Singapore is at the forefront of cryptocurrency adoption in the Asia Pacific region. The country secured approximately $627 million in funding for cryptocurrency companies across 88 deals in 2023. The Monetary Authority of Singapore authorized 19 cryptocurrency service providers as of January 2024. The Payment Services Act establishes a regulatory framework for digital payment token service providers in Singapore. Cryptocurrency is not considered legal tender in Singapore, it can be used as an alternative means of payment. On April 2, 2024, the regulator introduced amendments to the Payment Services Act. These amendments expand the scope of regulated payment services and impose user protection requirements on digital payment token service providers. The rules require providers to segregate customer assets and place them in a trust account. Providers must maintain proper books and ensure active systems protect the integrity of customer assets. Providers must demonstrate compliance with strict licensing criteria. They must maintain a minimum base capital of 250, 000 Singapore dollars and conduct due diligence on counterparties. They are required to notify customers about the risks associated with investing in cryptocurrencies. The regulator also set a strict deadline for locally based digital token service providers. Firms must cease offering services to overseas markets by June 30, 2025, unless they obtain the proper license. The regulator rejected suggestions for a grace period, citing the high risk of money laundering in the cryptocurrency sector. Organizations found in breach of the legislation face severe penalties. These penalties include fines up to 250, 000 Singapore dollars and imprisonment for up to three years.

Spain Guardia Civil Operations

The Spanish Guardia Civil executes tactical raids against cryptocurrency fraud networks operating within its borders. The agency played a central role in Operation Borrelli in June 2025. Officers apprehended three suspects in the Canary Islands and two in Madrid. The suspects allegedly used a network of associates to raise funds through cash withdrawals and cryptocurrency transfers. The Guardia Civil also participated in a Europol coordinated action day on November 4, 2024, in Malaga. This operation focused on underground bankers moving proceeds from serious crimes. The raids led to the arrest of nine suspects and the seizure of 27 million euros in cryptocurrencies. The Malaga operation built on the findings from two major investigations named Operation Gorgon and Operation Whitewall. This subsequent operation involved close collaboration between experts in serious and organized crime and financial investigations. The step in the investigation was to analyze the data in greater depth to identify individuals in contact with the suspects. This effort aimed to map the criminal network and understand the roles of its members. The close collaboration between Europol, the Spanish Guardia Civil, and members of the dedicated Operational Taskforce facilitated the distribution of numerous intelligence packages. In October 2025, the Guardia Civil executed further raids at the request of French and Belgian authorities. These actions focused on the 700 million euro laundering network. The Spanish authorities confiscated digital devices, high value watches, and financial assets during these coordinated strikes. The Spanish authorities continue to monitor the assets of the criminal organization in the countries where it operates and resides.

Keep exploring...

Breaking News and Daily Headlines from Around the World You Need to Know

Lorem ipsum dolor sit amet consectetur adipiscing elit, auctor ridiculus vitae laoreet duis facilisi, phasellus pulvinar et malesuada nec nisl. Torquent eros fringilla vivamus...

Stay Informed with the Latest Updates on Politics, Sports, and Global Affairs

Lorem ipsum dolor sit amet consectetur adipiscing elit, auctor ridiculus vitae laoreet duis facilisi, phasellus pulvinar et malesuada nec nisl. Torquent eros fringilla vivamus...

Advertisements

spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img
spot_img

Related Articles

How Buying Clothes from BLM Designated Stores Helps the Movement

Doing business like this takes much more effort than doing your own business at...

Streaming Services that Bring Your Favorite Teams Live

Doing business like this takes much more effort than doing your own business at...

Home Deliveries Are the Go To for Online Clothes Stores

Doing business like this takes much more effort than doing your own business at...

Take Precautions When Shopping at Huge Malls to Prevent Viruses

Doing business like this takes much more effort than doing your own business at...

This Building Can Be Seen from Space Due to its Immense Structure

Doing business like this takes much more effort than doing your own business at...

Protests Across the US Against the Ideas of President Trump

Doing business like this takes much more effort than doing your own business at...

What are Barack Obama’s Thoughts on the Current US Leadership?

Doing business like this takes much more effort than doing your own business at...

Taking Steps to Creating a Better Planet for Future Generations

Doing business like this takes much more effort than doing your own business at...