Wallet drainers stole over USD 500M in 2024. Pig-butchering investment scams added another USD 4B according to FBI IC3. This page tracks active drainer kits, rug-pulled tokens and known scam wallet addresses our corpus indexes.
Scammers impersonate legitimate "AML" (anti-money laundering) wallet-screening services such as AMLBot. Victims are invited to "check" their crypto wallet for ties to crime, but the site tricks them...
Scammers published a fake "Sparrow Wallet" crypto app on Apple's App Store that impersonated the legitimate desktop Bitcoin wallet and tricked at least three users into entering their seed phrases,...
Scammers build polished lookalike crypto-to-gift-card storefronts that mimic real platforms (dark theme, trust badges, "Pay with crypto" buttons) to steal your Bitcoin or Ethereum. Victims either...
Hackers compromised a third-party frontend vendor used by Polymarket and injected malicious JavaScript into the legitimate trading site. Visitors were prompted to sign fraudulent wallet transactions...
Approval phishing is a crypto scam where victims are tricked into signing a wallet transaction that grants attackers standing permission to spend or transfer tokens. Unlike classic phishing, victims...
A convincing clone of OpenAI's ChatGPT download page at openew[.]app is tricking Windows and Mac users into installing info-stealing malware. The site mirrors OpenAI's branding, dark theme, and...
Reverse trick: scammer posts on Reddit/Discord 'how do I withdraw $50k USDT from this wallet?' and shares a seed phrase. Victim imports seed; wallet shows $50k USDT (real). When victim adds ETH to...
Solana drainer asks user to sign a tx with Cross-Program Invocation (CPI) to a malicious program. Phantom simulation may not flag if program is unknown. Drainer transfers SOL + SPL tokens in one tx....
Telegram trading bots (Maestro, BananaGun, Bonkbot) are popular for memecoin sniping. Scammers clone these ('Maestro-Pro-Bot', 'BananaGun Sniper2') and demand seed or private key import. Indicators:...
Malware (ClipBanker, CryptoShuffler) monitors clipboard. When user copies a wallet address, malware silently replaces it with attacker's address sharing same length/format. CryptoShuffler stole...
Projects launch 'algorithmic stablecoin' with high yield via seigniorage (USDD, USDN, BEAN, BasisCash). When trust falters, peg breaks irreversibly (Terra/UST $40B collapse May 2022). Often paired...
Attacker bridges drained proceeds via Wormhole/Allbridge/deBridge to obscure trace. Some drainer kits exploit cross-chain accounts (Phantom multi-chain mode) — one signature drains both SOL and ETH...
Drainer offers 'free conversion' of legacy USDC.e (Avalanche/Optimism bridged) to native USDC. Or fake 'USDC v2 migration'. User signs permit on real USDC; attacker drains. Indicators: (1) real USDC...
Clone protocol forks Aave/Compound, adds backdoor in price oracle or admin function. User deposits, dev exploits to drain pool. Examples: Swaprum ($3M, 'CertiK audited'), CompounderFinance ($10M)....
Phishing clones (wormhole-bridge[.]io, multichain-bridge[.]live, stargate-defi[.]app). User connects wallet to 'bridge' but signs approval/permit; assets drain instead of bridging. Indicators: (1)...
DeFi farm advertises 10,000-1,000,000% APY (Anchor 20% was suspicious; 50k% is impossible). Once TVL hits target, dev drains via emergencyWithdraw/admin function. Indicators: (1) APY 500% with no...