← Lucifer DaaS1 decision on this page
Audit log
Every state-changing event for Lucifer DaaS: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-08-04 23:36:31ZScore: ? → ? (no score change)anchorpending
- chain
- ●—
- hash
HAuxVgEQwWdK…Zw5FE5Losha256 → base58
verifying row…canonical bytes (21196 B) ▸
{"actor":"system:backfill","investigation_id":"290c0f45-6d7c-4e0d-9ead-b049aaa7e965","kind":"publish","page_slug":"lucifer-daas","published_at":"2026-08-04T23:36:31.708Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Lucifer DaaS","sections":[{"content":"Lucifer DaaS is a crypto drainer-as-a-service platform that facilitates large-scale phishing-based wallet theft through a structured affiliate model. Unlike earlier drainer operations that sold software kits outright, Lucifer explicitly states the software is 'not for sale' and instead recruits affiliates who supply phishing traffic in exchange for 80% of any stolen funds, with the Lucifer operators retaining a 20% commission per successful 'hit.' This structure more closely resembles the ransomware-as-a-service affiliate model than traditional phishing kit sales. Flare threat intelligence researchers analyzed approximately 700 posts from underground forums, chat channels, and Telegram communities associated with Lucifer DaaS between January 2025 and early 2026, characterizing the operation as an increasingly professionalized criminal ecosystem. The platform is operationally and organizationally distinct from other named drainer operations such as Inferno, Vanilla, Angel, Quark, Pink, and MS Drainer, which operate under separate infrastructure and affiliate networks.","heading":"Operational Overview","severity":"critical","sources":[{"credibility":2,"name":"Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet — BleepingComputer (Flare research, published May 21, 2026)","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/inside-a-crypto-drainer-how-to-spot-it-before-it-empties-your-wallet/"},{"credibility":2,"name":"The Rise of Drainer-as-a-Service — SentinelOne","type":"research","url":"https://www.sentinelone.com/blog/the-rise-of-drainer-as-a-service-understanding-daas/"}]},{"content":"In March 2025, the Lucifer operators announced version 6.6.6 of their drainer software, advertising ERC20 token support, Permit2 abuse, off-chain signatures, Telegram notifications, wallet-security bypasses, and multichain functionality across EVM-compatible networks. Subsequent update announcements covered bug fixes, wallet compatibility updates, Telegram-browser support, deployment improvements, and hosting features. A notable addition was a 'Zero Config' automated deployment workflow that allowed affiliates with minimal technical skill to upload static files and receive a ready-to-deploy phishing package, lowering the operational barrier for new participants. The platform also introduced website-cloning functionality, providing affiliates with ZIP files preloaded with the latest Lucifer drainer code adapted to mimic targeted legitimate crypto projects. The Permit2 abuse capability is particularly significant: Uniswap's Permit2 standard allows users to authorize token transfers via an off-chain signature without paying gas fees, which attackers exploit by presenting the malicious approval as a routine 'Login' or 'Verify Identity' action in the victim's wallet interface. Once the signature is granted, the drainer can sweep ERC20 and other supported token balances nearly instantly. No specific smart contract addresses or on-chain indicators for Lucifer's commission-collection infrastructure have been publicly documented as of mid-2026.","heading":"Technical Capabilities and Version History","severity":"critical","sources":[{"credibility":2,"name":"Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet — BleepingComputer (Flare research, May 2026)","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/inside-a-crypto-drainer-how-to-spot-it-before-it-empties-your-wallet/"},{"credibility":3,"name":"Drainer-as-a-Service (DaaS): How This Software Steals Your Crypto — Bithide","type":"research","url":"https://bithide.io/blog/secure-crypto-from-drainers/"}]},{"content":"Lucifer DaaS recruits affiliates through underground forums and Telegram channels. The platform presents itself as a 'professional solution' and in May 2025 posted channel communications confirming it does not sell or lease the software and only splits '20% per hit.' Affiliate recruitment communications discouraged complete beginners, preferring 'experienced affiliates capable of generating reliable phishing traffic,' despite the platform's own automation features reducing the technical skill threshold for deployment. Affiliates are responsible for generating phishing traffic through methods including fake crypto project websites, NFT minting pages, airdrop claim portals, and DeFi interfaces. The Lucifer back-end manages transaction signatures, approvals, and token transfers once a victim connects their wallet. This division of labor — affiliates control victim acquisition, operators control the technical drain mechanism — mirrors structures observed in ransomware affiliate programs and represents a significant maturation from earlier drainer kit sales. The operators also discussed customer support, hosting recommendations, and referral systems, indicating a structured internal organization rather than a loosely coordinated operation.","heading":"Affiliate Recruitment and Business Model","severity":"critical","sources":[{"credibility":2,"name":"Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet — BleepingComputer (Flare research, May 2026)","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/inside-a-crypto-drainer-how-to-spot-it-before-it-empties-your-wallet/"},{"credibility":3,"name":"Crypto Drainers of 2025: The Rising Web of Wallet Theft — DeCode Cybercrime","type":"research","url":"https://decodecybercrime.com/crypto-drainers-of-2025-the-rising-web-of-wallet-theft/"}]},{"content":"Lucifer DaaS has demonstrated repeated adaptation to platform-level enforcement actions. In August 2025, Telegram banned the platform's automated bots; the operators responded by instructing affiliates to create replacement bots and grant them administrative privileges, resuming operations without meaningful disruption. In November 2025, a documentation domain hosted on Google Firebase was suspended, reportedly following research disclosures. The operators responded by migrating documentation to the InterPlanetary File System (IPFS), a decentralized peer-to-peer file distribution protocol, explicitly framing the move as a resilience strategy against centralized-platform takedowns. This infrastructure shift to content-addressed decentralized hosting represents a recognized trend among professional criminal operations seeking to reduce single points of failure. The operational continuity following both the August and November 2025 enforcement actions suggests the group maintains redundant communication and distribution channels.","heading":"Operational Resilience and Infrastructure","severity":"high","sources":[{"credibility":2,"name":"Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet — BleepingComputer (Flare research, May 2026)","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/inside-a-crypto-drainer-how-to-spot-it-before-it-empties-your-wallet/"}]},{"content":"Lucifer DaaS operates within a crowded drainer-as-a-service marketplace alongside named competitors including Inferno, Angel (GhostSec), Vanilla, Pink, MS Drainer, CLINKSINK, and others. Scam Sniffer reported that wallet drainers stole $494 million in 2024, a 67% increase over the $295 million stolen in 2023, with losses distributed across multiple competing DaaS operations. For 2025, Scam Sniffer reported a significant year-over-year decline in tracked phishing losses to approximately $84 million, though CertiK's broader phishing category recorded $723 million across 248 incidents using a wider scope of measurement. The figure of $1.93 billion sometimes cited in connection with DaaS operations in this family derives from Kroll's H1 2025 estimate of total crypto theft losses across all categories — hacks, exploits, phishing, and social engineering combined — and should not be attributed specifically to Lucifer DaaS or to the drainer-as-a-service category alone. No primary source has attributed a specific loss total exclusively to Lucifer DaaS operations. The Phishdestroy research portal published an analysis titled 'Anatomy of a Crypto Drainer: How $1.93B Vanished in 6 Months' that uses the Kroll H1 2025 aggregate figure as context for the broader DaaS economy but does not specifically name or quantify Lucifer's individual contribution.","heading":"Broader DaaS Ecosystem Context and Loss Estimates","severity":"high","sources":[{"credibility":2,"name":"Scam Sniffer 2024: Web3 Phishing Attacks — Wallet Drainers Drain $494 Million","type":"research","url":"https://drops.scamsniffer.io/scam-sniffer-2024-web3-phishing-attacks-wallet-drainers-drain-494-million/"},{"credibility":2,"name":"Cryptocurrency Wallet Drainers Stole $494 Million in 2024 — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/cryptocurrency-wallet-drainers-stole-494-million-in-2024/"},{"credibility":2,"name":"Scam Sniffer 2025: Crypto Phishing Losses Fall 83% to $84 Million — Scam Sniffer","type":"research","url":"https://drops.scamsniffer.io/scam-sniffer-2025-crypto-phishing-losses-fall-83-to-84-million/"},{"credibility":3,"name":"Anatomy of a Crypto Drainer: How $1.93B Vanished in 6 Months — Phishdestroy","type":"research","url":"https://phishdestroy.io/crypto-drainer-anatomy"},{"credibility":2,"name":"Crypto Phishing Losses Fell 83% in 2025, Scam Sniffer Reports — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/crypto-phishing-losses-fell-83-percent-2025-wallet-drainers"}]},{"content":"The DaaS ecosystem of which Lucifer is a part has attracted academic scrutiny. A 2025 paper titled 'Unmasking the Shadow Economy: A Deep Dive into Drainer-as-a-Service Phishing on Ethereum,' published in the Proceedings of the 2025 ACM Internet Measurement Conference, examined the on-chain and off-chain mechanics of Ethereum-targeted DaaS operations at scale. Separately, BlockSec published research characterizing the Ethereum DaaS sector as a '$135M drainer-as-a-service industry' based on on-chain attribution of smart contract-level drain transactions. Neither publication specifically names or quantifies Lucifer DaaS as a distinct contributor, but both establish the institutional and technical context within which Lucifer operates. The Flare analysis of 700 underground posts, as reported by BleepingComputer in May 2026, remains the most specific published research attributing structured intelligence findings to the Lucifer brand.","heading":"Academic and Institutional Research","severity":"medium","sources":[{"credibility":1,"name":"Unmasking the Shadow Economy: A Deep Dive into Drainer-as-a-Service Phishing on Ethereum — ACM IMC 2025","type":"research","url":"https://dl.acm.org/doi/10.1145/3730567.3764476"},{"credibility":2,"name":"Inside Ethereum's Shadow Economy: New Research Unmasks the $135M Drainer-as-a-Service Industry — BlockSec","type":"research","url":"https://blocksec.com/blog/inside-ethereum-s-shadow-economy-new-research-unmasks-the-135-m-drainer-as-a-service-industry"}]},{"content":"No operator identities behind Lucifer DaaS have been publicly attributed as of mid-2026. No arrests, indictments, DOJ charges, or regulatory actions by the SEC, CFTC, FBI, or international equivalents have been publicly announced specifically in connection with Lucifer DaaS. The operation's deliberate anonymity — communicating through Telegram channels and underground forums without known public-facing individuals — has made attribution difficult. The platform's migration to IPFS documentation hosting and rapid Telegram bot replacement following August 2025 bans further complicates enforcement. Other DaaS operations have faced enforcement actions: the operators behind Inferno Drainer shut down in 2023 citing 'too much attention,' and multiple actors in adjacent drainer networks have faced FBI or international law enforcement pressure, but no comparable public action has been announced for Lucifer specifically.","heading":"Attribution and Law Enforcement Status","severity":"high","sources":[{"credibility":2,"name":"Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet — BleepingComputer (Flare research, May 2026)","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/inside-a-crypto-drainer-how-to-spot-it-before-it-empties-your-wallet/"},{"credibility":2,"name":"Return of the Crypto Inferno Drainer — Check Point Research","type":"research","url":"https://research.checkpoint.com/2025/inferno-drainer-reloaded-deep-dive-into-the-return-of-the-most-sophisticated-crypto-drainer/"}]},{"content":"Lucifer DaaS targets holders of ERC20 tokens and other multichain crypto assets across EVM-compatible networks. Victims are typically lured to counterfeit websites impersonating legitimate crypto projects, NFT collections, DeFi protocols, or airdrop distribution events. Once a victim connects their wallet and approves a malicious transaction or off-chain Permit2 signature — often presented as a routine authentication action — the drainer's back-end infrastructure executes token sweeps within seconds. The Permit2 exploitation is particularly effective because the required approval does not cost gas fees and may visually resemble a standard login action in popular wallet interfaces. Web3 users interacting with newly launched tokens, NFT mints, airdrop claims, or unfamiliar DeFi platforms represent the highest-risk demographic. The platform's multichain capability means victims on Ethereum mainnet and compatible L2 or sidechain networks are equally exposed.","heading":"Victim Profile and Attack Vector","severity":"high","sources":[{"credibility":2,"name":"Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet — BleepingComputer (Flare research, May 2026)","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/inside-a-crypto-drainer-how-to-spot-it-before-it-empties-your-wallet/"},{"credibility":2,"name":"Uniswap Permit2 Phishing: $1 Million Loss Highlights Risk — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/09/uniswap-permit2-phishing-risk/"},{"credibility":2,"name":"Crypto Wallet Drainers — Group-IB Knowledge Hub","type":"research","url":"https://www.group-ib.com/resources/knowledge-hub/crypto-wallet-drainers/"}]}],"sources_used":[{"credibility":2,"name":"Inside a Crypto Drainer: How to Spot it Before it Empties Your Wallet — BleepingComputer (Flare research, May 21, 2026)","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/inside-a-crypto-drainer-how-to-spot-it-before-it-empties-your-wallet/"},{"credibility":1,"name":"Unmasking the Shadow Economy: A Deep Dive into Drainer-as-a-Service Phishing on Ethereum — ACM Internet Measurement Conference 2025","type":"research","url":"https://dl.acm.org/doi/10.1145/3730567.3764476"},{"credibility":2,"name":"Inside Ethereum's Shadow Economy: New Research Unmasks the $135M Drainer-as-a-Service Industry — BlockSec","type":"research","url":"https://blocksec.com/blog/inside-ethereum-s-shadow-economy-new-research-unmasks-the-135-m-drainer-as-a-service-industry"},{"credibility":2,"name":"Scam Sniffer 2024: Web3 Phishing Attacks — Wallet Drainers Drain $494 Million","type":"research","url":"https://drops.scamsniffer.io/scam-sniffer-2024-web3-phishing-attacks-wallet-drainers-drain-494-million/"},{"credibility":2,"name":"Scam Sniffer 2025: Crypto Phishing Losses Fall 83% to $84 Million","type":"research","url":"https://drops.scamsniffer.io/scam-sniffer-2025-crypto-phishing-losses-fall-83-to-84-million/"},{"credibility":2,"name":"Cryptocurrency Wallet Drainers Stole $494 Million in 2024 — BleepingComputer","type":"news_article","url":"https://www.bleepingcomputer.com/news/security/cryptocurrency-wallet-drainers-stole-494-million-in-2024/"},{"credibility":3,"name":"Anatomy of a Crypto Drainer: How $1.93B Vanished in 6 Months — Phishdestroy","type":"research","url":"https://phishdestroy.io/crypto-drainer-anatomy"},{"credibility":2,"name":"Crypto Phishing Losses Fell 83% in 2025, Scam Sniffer Reports — CoinTelegraph","type":"news_article","url":"https://cointelegraph.com/news/crypto-phishing-losses-fell-83-percent-2025-wallet-drainers"},{"credibility":2,"name":"Return of the Crypto Inferno Drainer — Check Point Research 2025","type":"research","url":"https://research.checkpoint.com/2025/inferno-drainer-reloaded-deep-dive-into-the-return-of-the-most-sophisticated-crypto-drainer/"},{"credibility":2,"name":"The Rise of Drainer-as-a-Service — SentinelOne","type":"research","url":"https://www.sentinelone.com/blog/the-rise-of-drainer-as-a-service-understanding-daas/"},{"credibility":2,"name":"Crypto Wallet Drainers — Group-IB Knowledge Hub","type":"research","url":"https://www.group-ib.com/resources/knowledge-hub/crypto-wallet-drainers/"},{"credibility":2,"name":"Uniswap Permit2 Phishing: $1 Million Loss Highlights Risk — Cryptonomist","type":"news_article","url":"https://en.cryptonomist.ch/2026/07/09/uniswap-permit2-phishing-risk/"},{"credibility":3,"name":"Phishing and Wallet Drainer Incidents Statistics 2025 — SQ Magazine","type":"research","url":"https://sqmagazine.co.uk/phishing-and-wallet-drainer-incidents-statistics/"},{"credibility":3,"name":"Drainer-as-a-Service (DaaS): Unmasking the Dark Web's Latest Threat — Cyberscope / Medium","type":"research","url":"https://cyberscope.medium.com/drainer-as-a-service-daas-unmasking-the-dark-webs-latest-threat-e54ad69d12da"}],"summary":"Lucifer DaaS is a drainer-as-a-service criminal platform active from at least January 2025 through early 2026, analyzed by Flare threat intelligence researchers across approximately 700 posts collected from underground forums and Telegram channels. The operation employs an affiliate commission model — taking 20% of stolen funds per theft event — and has progressively professionalized its tooling with multichain wallet-draining capabilities, Permit2 signature abuse, automated phishing deployment, and operational resilience measures including migration to decentralized hosting after platform takedowns. No operator identities, attributable wallet addresses, or law enforcement actions have been publicly confirmed as of mid-2026.","timeline":[{"date":"2025-01-01","event":"Earliest posts in Flare's analyzed dataset: Lucifer DaaS Telegram channel and underground forum activity begins the period analyzed by researchers. Approximate start date based on the January 2025 to early 2026 collection window.","source":"BleepingComputer / Flare research","source_url":"https://www.bleepingcomputer.com/news/security/inside-a-crypto-drainer-how-to-spot-it-before-it-empties-your-wallet/"},{"date":"2025-03-01","event":"Lucifer operators announce version 6.6.6, introducing ERC20 support, Permit2 abuse, off-chain signatures, Telegram notifications, wallet-security bypasses, and multichain functionality. Announcement reiterates the software is not for sale and confirms 20% operator commission.","source":"BleepingComputer / Flare research","source_url":"https://www.bleepingcomputer.com/news/security/inside-a-crypto-drainer-how-to-spot-it-before-it-empties-your-wallet/"},{"date":"2025-05-01","event":"Lucifer channel posts confirm the operation does not sell or lease the software, only splitting '20% per hit.' Platform continues recruiting affiliates through underground communities.","source":"BleepingComputer / Flare research","source_url":"https://www.bleepingcomputer.com/news/security/inside-a-crypto-drainer-how-to-spot-it-before-it-empties-your-wallet/"},{"date":"2025-08-01","event":"Telegram bans Lucifer DaaS bots. Operators instruct affiliates to create new bots and grant them administrative privileges, restoring operational capability without extended downtime.","source":"BleepingComputer / Flare research","source_url":"https://www.bleepingcomputer.com/news/security/inside-a-crypto-drainer-how-to-spot-it-before-it-empties-your-wallet/"},{"date":"2025-11-01","event":"Lucifer DaaS documentation domain hosted on Google Firebase is suspended, reportedly following security research disclosures. Operators migrate documentation to IPFS, citing decentralization as a resilience measure against future takedowns.","source":"BleepingComputer / Flare research","source_url":"https://www.bleepingcomputer.com/news/security/inside-a-crypto-drainer-how-to-spot-it-before-it-empties-your-wallet/"},{"date":"2026-05-21","event":"BleepingComputer publishes Flare threat intelligence analysis of Lucifer DaaS based on approximately 700 underground posts collected between January 2025 and early 2026, providing the first detailed public research into the platform's internal structure, business model, and technical evolution.","source":"BleepingComputer","source_url":"https://www.bleepingcomputer.com/news/security/inside-a-crypto-drainer-how-to-spot-it-before-it-empties-your-wallet/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 63174018-92d4-4ee5-bdb6-0d38efebaace
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.