Lucifer DaaS
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·55KRkj…97hmSummary
Lucifer DaaS is a drainer-as-a-service criminal platform active from at least January 2025 through early 2026, analyzed by Flare threat intelligence researchers across approximately 700 posts collected from underground forums and Telegram channels. The operation employs an affiliate commission model — taking 20% of stolen funds per theft event — and has progressively professionalized its tooling with multichain wallet-draining capabilities, Permit2 signature abuse, automated phishing deployment, and operational resilience measures including migration to decentralized hosting after platform takedowns. No operator identities, attributable wallet addresses, or law enforcement actions have been publicly confirmed as of mid-2026.
Connected Entities
6 entities · 60 linked investigations- wallet drainers→mentioned with→Ethereum(70%)
- Uniswap→mentioned with→Ethereum(80%)
- Inferno Drainer→mentioned with→Ethereum(70%)
- Lucifer DaaS→mentioned with→wallet drainers(80%)
- Lucifer Drainer→mentioned with→Inferno Drainer(80%)
- Lucifer Drainer→mentioned with→Lucifer DaaS(80%)
- Lucifer DaaS→mentioned with→Lucifer Drainer(80%)
- Lucifer DaaS→mentioned with→Inferno Drainer(80%)
- wallet drainers→mentioned with→Inferno Drainer(80%)
- Lucifer DaaS→mentioned with→Ethereum(80%)
- + 2 more
Timeline(6 events)
2025
Earliest posts in Flare's analyzed dataset: Lucifer DaaS Telegram channel and underground forum activity begins the period analyzed by researchers. Approximate start date based on the January 2025 to early 2026 collection window.
BleepingComputer / Flare researchMarch 2025
Lucifer operators announce version 6.6.6, introducing ERC20 support, Permit2 abuse, off-chain signatures, Telegram notifications, wallet-security bypasses, and multichain functionality. Announcement reiterates the software is not for sale and confirms 20% operator commission.
BleepingComputer / Flare researchMay 2025
Lucifer channel posts confirm the operation does not sell or lease the software, only splitting '20% per hit.' Platform continues recruiting affiliates through underground communities.
BleepingComputer / Flare researchAugust 2025
Telegram bans Lucifer DaaS bots. Operators instruct affiliates to create new bots and grant them administrative privileges, restoring operational capability without extended downtime.
BleepingComputer / Flare researchNovember 2025
Lucifer DaaS documentation domain hosted on Google Firebase is suspended, reportedly following security research disclosures. Operators migrate documentation to IPFS, citing decentralization as a resilience measure against future takedowns.
BleepingComputer / Flare research21 May 2026
BleepingComputer publishes Flare threat intelligence analysis of Lucifer DaaS based on approximately 700 underground posts collected between January 2025 and early 2026, providing the first detailed public research into the platform's internal structure, business model, and technical evolution.
BleepingComputerDecision Log
- hash: Bzg96hm5Pw2UfYCXoynGi65PpqCSLVc3EmTH63FRHCpv
- hash: J5c5CkEuPG8WetKx2B8Efg8CVHVETdZqvhv37bWhv6SC
- hash: HAuxVgEQwWdKPgSu3yJ2aiTxAfjnSHq7iYWGZw5FE5Lo
This investigation is cryptographically anchored to the Solana blockchain (3 events). 13 of 14 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 8/4/2026, 11:36:21 PM
last updated: 8/26/2026, 9:04:25 AM
7 viewsavoid.net — verified advice for a post-truth world