← Pink Drainer1 decision on this page
Audit log
Every state-changing event for Pink Drainer: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-05-14 06:12:25ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 419,630,287
- sig
27aS7szWXo14…xn4yk5MWexplorer ↗- hash
AvEbBfcTnA51…gR1vGiQdsha256 → base58
verifying row…full verify ↗canonical bytes (27103 B) ▸
{"actor":"system:backfill","investigation_id":"6db4029b-a5c9-4a70-99d9-607cf9da1ee7","kind":"publish","page_slug":"pink-drainer","published_at":"2026-05-14T06:12:25.531Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"Pink Drainer","sections":[{"content":"Pink Drainer operated as a Drainer-as-a-Service (DaaS) criminal enterprise, providing a sophisticated phishing toolkit to affiliate scammers in exchange for a percentage of stolen proceeds. The operator offered the toolkit on a turnkey basis, requiring an initial deposit and taking a 20-30% cut of all assets drained by affiliates. This model, common among competing drainer services such as Inferno Drainer, Angel Drainer, and MS Drainer, allowed the operator to profit without directly conducting phishing attacks. The operator publicly claimed 'I don't phish anyone, I just code,' distancing himself from responsibility for victim losses. Pink Drainer's toolkit enabled phishing crews to create malicious websites mimicking legitimate crypto protocols, and to exploit wallet approval mechanisms — particularly the 'Increase Approval' transaction function — to drain tokens and NFTs from victim wallets almost instantly after a signature was obtained. The service was operational across Ethereum mainnet, Arbitrum, and other EVM-compatible networks.","heading":"Overview and Business Model","severity":"critical","sources":[{"credibility":3,"name":"Pink Drainer Out, Inferno Drainer Back: New Shift in the Crypto Wallet Drainer Industry (Nefture Security / Coinmonks)","type":"news","url":"https://medium.com/coinmonks/pink-drainer-out-inferno-drainer-back-new-shift-in-the-crypto-wallet-drainer-industry-6915c270bb68"},{"credibility":3,"name":"Wallet Drainers: a +300 Million Crypto Scam-as-a-Service Industry (Nefture Security / Coinmonks)","type":"news","url":"https://medium.com/coinmonks/wallet-drainers-a-300-million-crypto-scam-as-a-service-industry-09aa1d44172e"},{"credibility":2,"name":"Pink Drainer creator defends his wallet draining crypto scam kit (CoinTelegraph Magazine)","type":"news","url":"https://cointelegraph-magazine.com/pink-drainer-security-researcher-steals-millions-from-participants/"},{"credibility":2,"name":"Creator Of The Pink Drainer Crypto Scam That Stole Millions Has No Remorse (Market Realist)","type":"news","url":"https://marketrealist.com/what-is-the-pink-drainer-kit-scam/"}]},{"content":"Pink Drainer was operated by a pseudonymous individual known by the alias 'Pink,' who previously operated under the handle 'Blockdev' and ran the X (Twitter) account @ChainThreats while posing as a blockchain security researcher. According to reporting from Nefture Security and CoinTelegraph Magazine, this individual initially gained credibility in the security community by publicly attacking and DDoS-ing the then-dominant Monkey Drainer service, presenting as a defender of users. The cover was reportedly exposed when 'Blockdev' collaborated with 'Fantasy,' the founder of blockchain security firm Blockmage Labs, to investigate Venom Drainer. During that collaboration, the wallet address used to set up the draining infrastructure was traced back to Blockdev, revealing the dual identity. Pink referred to victims as 'participants' rather than victims and expressed no remorse. The operator claimed the majority of victims were Chinese nationals operating in DeFi markets where such activity was legally restricted in their jurisdiction, a claim widely disputed by analysts given the global scope of victims documented by ScamSniffer.","heading":"Operator Identity and Background","severity":"critical","sources":[{"credibility":3,"name":"Pink Drainer Out, Inferno Drainer Back (Nefture Security / Coinmonks)","type":"news","url":"https://medium.com/coinmonks/pink-drainer-out-inferno-drainer-back-new-shift-in-the-crypto-wallet-drainer-industry-6915c270bb68"},{"credibility":2,"name":"Pink Drainer creator defends his wallet draining crypto scam kit (CoinTelegraph Magazine)","type":"news","url":"https://cointelegraph-magazine.com/pink-drainer-security-researcher-steals-millions-from-participants/"},{"credibility":2,"name":"Creator Of The Pink Drainer Crypto Scam That Stole Millions Has No Remorse (Market Realist)","type":"news","url":"https://marketrealist.com/what-is-the-pink-drainer-kit-scam/"}]},{"content":"According to ScamSniffer's Dune Analytics dashboard — the most comprehensive public tracking of Pink Drainer activity — the service facilitated the theft of $85.29 million from 21,131 victims between July 2023 and May 2024. During 2023 alone, Pink Drainer obtained $18.7 million from 9,068 victims. The single largest individual victim loss attributed to Pink Drainer was $4.33 million in Chainlink (LINK) tokens drained from one victim in December 2023 via the Increase Approval exploit. The operator privately disputed early estimates of $18 million, claiming the actual total surpassed $53 million at the time, suggesting the service's own records may have tracked higher volumes than initial blockchain analytics detected. At the time of the shutdown announcement in May 2024, Pink Drainer-affiliated addresses had staked approximately 18.1 million DAI (roughly 1.35% of total sDAI tokens) in the Spark DeFi lending protocol, representing funds being passively grown rather than immediately converted to fiat. As of March 2026, wallets associated with Pink Drainer were estimated to still hold approximately $12 million in digital assets, with a $117,000 movement of ETH and sDAI detected to a newly created wallet address.","heading":"Scale of Theft and Victim Count","severity":"critical","sources":[{"credibility":2,"name":"Pink Drainer Scam Stats - Dune Analytics (ScamSniffer)","type":"onchain","url":"https://dune.com/scamsniffer/pinkdrainer-stats"},{"credibility":2,"name":"Pink Drainer Hackers Drain $4.4 Million in LINK (CryptoPotato)","type":"news","url":"https://cryptopotato.com/pink-drainer-hackers-drain-4-4-million-in-link/"},{"credibility":2,"name":"Pink Drainer Addresses Stake 12M DAI in Spark, Becoming Top sDAI Holder: PeckShield (CryptoPotato)","type":"onchain","url":"https://cryptopotato.com/pink-drainer-addresses-stakes-12m-dai-in-spark-becoming-top-sdai-holder-peckshield/"},{"credibility":3,"name":"The $85M Crypto Scam Isn't Dead Yet: Pink Drainer Wallet Suddenly Moves $117K (MEXC News)","type":"news","url":"https://www.mexc.com/news/896215"},{"credibility":2,"name":"Pink Drainer shuts down after dealing over $85 million in damage (Crypto Briefing)","type":"news","url":"https://cryptobriefing.com/pink-drainer-shutdown/"}]},{"content":"Pink Drainer employed multiple attack vectors during its operational period. The primary method from its earliest documented phase (May-June 2023) was social engineering via journalist impersonation: threat actors posed as reporters from well-known crypto media outlets including CoinTelegraph and Decrypt, contacted targets through Discord and social media, conducted multi-day phony interviews to build trust, and then directed victims to fraudulent KYC verification sites. Those sites embedded malicious JavaScript bookmarklets — typically hidden behind a 'Drag Me' button — that, when activated by the victim, exfiltrated Discord authentication tokens without requiring passwords or MFA bypass. This granted attackers administrative access to Discord servers, which were then used to distribute phishing links to wider audiences. A second core method involved malicious transaction approval exploitation: victims were tricked into signing transactions using the Ethereum 'Increase Approval' or 'Permit' functions on fake versions of legitimate DeFi protocols, immediately transferring token spend authorization to attacker-controlled addresses. Funds were typically converted to ETH within minutes and laundered through the instant exchange service eXch to obscure traceability. The service name itself originated when ScamSniffer analysts traced an early theft of approximately $320,000 in NFTs back to the ENS address 'pink-drainer.eth,' which was used as a fee receiver.","heading":"Attack Methods and Techniques","severity":"critical","sources":[{"credibility":1,"name":"Hackers steal $3 million by impersonating crypto news journalists (BleepingComputer)","type":"news","url":"https://www.bleepingcomputer.com/news/cryptocurrency/hackers-steal-3-million-by-impersonating-crypto-news-journalists/"},{"credibility":1,"name":"Posing as journalists, Pink Drainer pilfers $3.3M in crypto (The Register)","type":"news","url":"https://www.theregister.com/2023/06/12/pink_drainer_crypto_scam/"},{"credibility":2,"name":"Pink Drainer steals $3M from multiple hack events including OpenAI CTO, Orbiter Finance (ScamSniffer)","type":"official","url":"https://drops.scamsniffer.io/pink-drainer-steals-3m-from-multiple-hack-events-including-openai-cto-orbiter-finance/"},{"credibility":2,"name":"Hacking group Pink Drainer strikes again, pilfering $4.4M from just 1 victim (CoinTelegraph)","type":"news","url":"https://cointelegraph.com/news/chainlink-pink-drainer-crypto-phishing-scam"}]},{"content":"Pink Drainer was responsible for a wide range of high-profile and large-scale incidents. In May-June 2023, the group compromised the Discord and social media accounts of multiple prominent entities using its journalist-impersonation technique, including: Evmos (May 8, 2023), Starknet ID (May 11), LiFi (May 17), Cherry Network and eth_ben (May 26), Pika Protocol (May 31), and Orbiter Finance, Flare Network, and OpenAI CTO Mira Murati (June 1-2). The Mira Murati account compromise promoted a fraudulent ERC-20 token named 'OPENAI' and reached an estimated 80,000 users before the tweet was removed. In December 2023, a single Chainlink investor lost 275,700 LINK tokens worth approximately $4.33 million in a single phishing event: 68,925 LINK was sent to the wallet labeled 'PinkDrainer: Wallet 2' on Etherscan (0x9fa7bb759641fcd37fe4ae41f725e0f653f2c726) and 206,775 LINK was sent to a second address ending in 'E70e.' The stolen LINK was quickly converted to ETH and routed through eXch. Steve Aoki's social media account was also among those compromised in earlier campaigns. By the time of the service's shutdown announcement, the total victim universe included more than 21,000 individuals across Ethereum mainnet, Arbitrum, and other EVM chains.","heading":"Notable Victims and Incidents","severity":"critical","sources":[{"credibility":2,"name":"Pink Drainer steals $3M from multiple hack events including OpenAI CTO, Orbiter Finance (ScamSniffer)","type":"official","url":"https://drops.scamsniffer.io/pink-drainer-steals-3m-from-multiple-hack-events-including-openai-cto-orbiter-finance/"},{"credibility":1,"name":"Hackers steal $3 million by impersonating crypto news journalists (BleepingComputer)","type":"news","url":"https://www.bleepingcomputer.com/news/cryptocurrency/hackers-steal-3-million-by-impersonating-crypto-news-journalists/"},{"credibility":2,"name":"OpenAI's CTO Hacked Twitter Account Promotes Fraudulent 'OPENAI' Token (Decrypt)","type":"news","url":"https://decrypt.co/143207/openais-cto-hacked-twitter-account-promotes-fraudulent-openai-token"},{"credibility":2,"name":"Hacking group Pink Drainer strikes again, pilfering $4.4M from just 1 victim (CoinTelegraph)","type":"news","url":"https://cointelegraph.com/news/chainlink-pink-drainer-crypto-phishing-scam"},{"credibility":2,"name":"Pink Drainer Hackers Drain $4.4 Million in LINK (CryptoPotato)","type":"news","url":"https://cryptopotato.com/pink-drainer-hackers-drain-4-4-million-in-link/"}]},{"content":"Multiple on-chain identifiers have been publicly attributed to Pink Drainer by blockchain security firms and indexed on Etherscan. Known labeled addresses include: PinkDrainer: Wallet 1 (0x63605e53d422c4f1ac0e01390ac59aaf84c44a51), PinkDrainer: Wallet 2 (0x9fa7bb759641fcd37fe4ae41f725e0f653f2c726), and a known contract address (0x00000f312c54d0dd25888ee9cdc3dee988700000). The ENS address 'pink-drainer.eth' served as an early fee receiver and was the initial identifier that led researchers to name the group. Pink Drainer-affiliated addresses staked approximately 18.1 million DAI in the Spark DeFi protocol at the time of shutdown (May 2024), at that point representing roughly 1.35% of total sDAI supply and making Pink Drainer one of Spark's largest single depositors. The operator preferred accumulating stolen proceeds in DAI stablecoins — reportedly to 'watch the pile grow' — rather than immediately converting to fiat. Stolen LINK tokens from the December 2023 incident were routed through eXch, an instant cryptocurrency exchange service used to obscure fund trails. In March 2026, blockchain analysts detected approximately $117,000 in ETH and sDAI moved from Pink Drainer-associated wallets to a newly created address, while the remaining holdings were estimated at approximately $12 million.","heading":"On-Chain Addresses and Infrastructure","severity":"high","sources":[{"credibility":1,"name":"PinkDrainer: Wallet 1 - Etherscan","type":"onchain","url":"https://etherscan.io/address/0x63605e53d422c4f1ac0e01390ac59aaf84c44a51"},{"credibility":1,"name":"PinkDrainer: Wallet 2 - Etherscan","type":"onchain","url":"https://etherscan.io/address/0x9fa7bb759641fcd37fe4ae41f725e0f653f2c726"},{"credibility":1,"name":"PinkDrainer: Contract 1 - Etherscan","type":"onchain","url":"https://etherscan.io/address/0x00000f312c54d0dd25888ee9cdc3dee988700000"},{"credibility":2,"name":"Pink Drainer Addresses Stake 12M DAI in Spark, Becoming Top sDAI Holder: PeckShield (CryptoPotato)","type":"onchain","url":"https://cryptopotato.com/pink-drainer-addresses-stakes-12m-dai-in-spark-becoming-top-sdai-holder-peckshield/"},{"credibility":3,"name":"The $85M Crypto Scam Isn't Dead Yet: Pink Drainer Wallet Suddenly Moves $117K (MEXC News)","type":"onchain","url":"https://www.mexc.com/news/896215"}]},{"content":"On May 17, 2024, Pink Drainer announced its retirement via a private Telegram message that was subsequently revealed by on-chain investigator ZachXBT. The announcement stated: 'We have reached our goal now, and according to plan, it's time for us to retire.' The operators declared they had no plans to return, promised all stored information would be wiped and destroyed, and stated that any future communications would be signed by their known wallet addresses (0x636 and 0x9fa). The announcement also acknowledged the likely market impact, noting 'people will move on to other drainers just as quickly as they moved to us.' The service had by this point stolen over $85 million from 21,100 victims in approximately 14 months of operation. Security experts, including Yu Xian of SlowMist, publicly expressed skepticism about the retirement's permanence, noting that drainer operators frequently rebranded under new identities or returned after allowing investigator attention to dissipate. The Nefture Security analysis observed that the Pink Drainer shutdown coincided with Inferno Drainer's return, representing a common pattern in the DaaS ecosystem. In July 2024, an address associated with Pink Drainer lost 10 ETH (approximately $30,000) to an address poisoning attack — discovered by MistTrack — in which an attacker sent funds from a near-identical address and successfully tricked the operator into sending funds to the wrong destination. As of March 10, 2026, approximately $117,000 in ETH and sDAI moved from Pink Drainer-affiliated wallets to a new address, with an estimated $12 million in remaining holdings still unspent.","heading":"Shutdown Announcement and Post-Closure Activity","severity":"high","sources":[{"credibility":2,"name":"Pink Drainer Announces Shut Down After Victimizing 21,100 Users (Blocmates)","type":"news","url":"https://www.blocmates.com/news-posts/pink-drainer-announces-shut-down-after-victimizing-21-100-users"},{"credibility":1,"name":"Crypto wallet drainer linked to $85 million in thefts shuts down (The Block)","type":"news","url":"https://www.theblock.co/post/295041/pink-drainer-shutting-down"},{"credibility":2,"name":"Pink Drainer Shuts Down After Stealing $85 Million in Crypto (BeInCrypto)","type":"news","url":"https://beincrypto.com/pink-drainer-shuts-down/"},{"credibility":2,"name":"Pink Drainer Loses 10 Ether to Address Poisoning Scam (CryptoTimes)","type":"news","url":"https://www.cryptotimes.io/2024/07/08/pink-drainer-loses-10-ether-to-address-poisoning-scam/"},{"credibility":1,"name":"Address associated with crypto draining tool Pink Drainer falls for address poisoning scam (The Block)","type":"news","url":"https://www.theblock.co/post/303851/pink-drainer-address-poisoning"},{"credibility":2,"name":"Crypto drainers are retiring as investigators start to close in (CoinTelegraph)","type":"news","url":"https://cointelegraph.com/news/crypto-drainers-investigators-hacks-defi"}]},{"content":"On-chain investigator ZachXBT played a significant role in publicizing Pink Drainer's activity and shutdown. ZachXBT revealed the operators' private Telegram retirement announcement on May 17, 2024, and previously documented the laundering of stolen Chainlink tokens from the December 2023 incident through eXch. ZachXBT's disclosure of the retirement announcement was cited by multiple major outlets including The Block, BeInCrypto, and CoinTelegraph as the primary source for the shutdown news, demonstrating the investigator's role as a key intelligence relay in the crypto security community. ScamSniffer, an independent on-chain anti-phishing firm, maintained a publicly accessible Dune Analytics dashboard tracking Pink Drainer victim counts and stolen totals in near-real-time. ScamSniffer also published early attribution reports in June 2023 identifying the group after tracing victim funds to the 'pink-drainer.eth' ENS address. PeckShield, another on-chain analytics firm, tracked Pink Drainer's staking activity in Spark in March and May 2024. MistTrack detected and reported the July 2024 address poisoning incident targeting a Pink Drainer-affiliated wallet. Crystal Intelligence published separate analysis of the address poisoning event.","heading":"ZachXBT Reporting and Investigator Coverage","severity":"medium","sources":[{"credibility":2,"name":"Pink Drainer steals $3M from multiple hack events including OpenAI CTO, Orbiter Finance (ScamSniffer)","type":"official","url":"https://drops.scamsniffer.io/pink-drainer-steals-3m-from-multiple-hack-events-including-openai-cto-orbiter-finance/"},{"credibility":2,"name":"Pink Drainer Scam Stats - Dune Analytics (ScamSniffer)","type":"onchain","url":"https://dune.com/scamsniffer/pinkdrainer-stats"},{"credibility":2,"name":"Pink Drainer Announces Shut Down After Victimizing 21,100 Users (Blocmates)","type":"news","url":"https://www.blocmates.com/news-posts/pink-drainer-announces-shut-down-after-victimizing-21-100-users"},{"credibility":1,"name":"Crypto wallet drainer linked to $85 million in thefts shuts down (The Block)","type":"news","url":"https://www.theblock.co/post/295041/pink-drainer-shutting-down"},{"credibility":2,"name":"Pink Drainer Hackers Drain $4.4 Million in LINK (CryptoPotato)","type":"news","url":"https://cryptopotato.com/pink-drainer-hackers-drain-4-4-million-in-link/"}]},{"content":"Pink Drainer emerged in April 2023, one of at least four drainer crews — alongside Inferno Drainer, MS Drainer, and Angel Drainer — that entered the market in the month following Monkey Drainer's March 2023 retirement. The 'Blockdev' alias had previously posed as a Monkey Drainer adversary, creating an apparent trajectory from security researcher persona to drainer operator. Venom Drainer, another competitor, closed in April 2023, and Pink Drainer absorbed a portion of its user base. The broader drainer ecosystem during 2023 collectively stole hundreds of millions in cryptocurrency. Pink Drainer, Inferno Drainer, Pussy Drainer, and Venom Drainer together stole over $66 million in the first half of 2023 alone. Inferno Drainer announced its own retirement in November 2023, and Pink Drainer subsequently grew to fill the vacuum — its rate of theft accelerating substantially in early 2024. Inferno Drainer then announced a return to operations shortly after Pink Drainer's shutdown in May 2024, consistent with a pattern of DaaS operators timing rebrands and reactivations around competitors' exits to capture their affiliate base. Pink Drainer's own shutdown announcement acknowledged this market dynamic: 'people will move on to other drainers just as quickly as they moved to us.' The overall DaaS ecosystem in 2024 resulted in $494 million stolen from 332,000 victim wallets, according to analysis by Chainalysis and Moonlock.","heading":"Ecosystem Context and Affiliated Services","severity":"high","sources":[{"credibility":3,"name":"Pink Drainer Out, Inferno Drainer Back: New Shift in the Crypto Wallet Drainer Industry (Nefture Security / Coinmonks)","type":"news","url":"https://medium.com/coinmonks/pink-drainer-out-inferno-drainer-back-new-shift-in-the-crypto-wallet-drainer-industry-6915c270bb68"},{"credibility":2,"name":"Pink, Pussy, Venom, Inferno — Drainers coming for a crypto wallet near you (CoinTelegraph)","type":"news","url":"https://cointelegraph.com/news/cypto-drainers-pink-pussy-venom-and-inferno-steal-millions"},{"credibility":1,"name":"Cryptocurrency wallet drainers stole $494 million in 2024 (BleepingComputer)","type":"news","url":"https://www.bleepingcomputer.com/news/security/cryptocurrency-wallet-drainers-stole-494-million-in-2024/"},{"credibility":2,"name":"Crypto drainers are retiring as investigators start to close in (CoinTelegraph)","type":"news","url":"https://cointelegraph.com/news/crypto-drainers-investigators-hacks-defi"},{"credibility":1,"name":"Understanding Crypto Drainers (Chainalysis)","type":"research","url":"https://www.chainalysis.com/blog/crypto-drainers/"}]}],"sources_used":[],"summary":"Pink Drainer was a Drainer-as-a-Service (DaaS) phishing toolkit that operated from approximately July 2023 to May 2024, stealing over $85.3 million in cryptocurrency and NFTs from more than 21,100 victims across Ethereum mainnet, Arbitrum, and other EVM-compatible chains. The service was operated by a pseudonymous individual using the alias 'Pink' (formerly known as 'Blockdev'), who rented the toolkit to affiliate phishing crews in exchange for a 20-30% cut of stolen funds. The operators announced retirement on May 17, 2024, citing mission accomplished, though wallets associated with the service retained approximately $12-18 million in assets post-shutdown and moved funds as recently as March 2026.","timeline":[{"date":"2023-03","event":"Monkey Drainer, the dominant drainer service, retires. Multiple new drainer crews emerge the following month, including Pink Drainer, Inferno Drainer, MS Drainer, and Angel Drainer.","source":"Nefture Security / Coinmonks","source_url":"https://medium.com/coinmonks/pink-drainer-out-inferno-drainer-back-new-shift-in-the-crypto-wallet-drainer-industry-6915c270bb68"},{"date":"2023-04","event":"Pink Drainer begins operations, with 'Pink' (formerly 'Blockdev') launching the DaaS phishing toolkit. Venom Drainer also closes this month.","source":"Nefture Security / Coinmonks","source_url":"https://medium.com/coinmonks/pink-drainer-out-inferno-drainer-back-new-shift-in-the-crypto-wallet-drainer-industry-6915c270bb68"},{"date":"2023-05","event":"Pink Drainer begins journalist-impersonation campaign targeting Discord administrators, compromising Evmos (May 8), Starknet ID (May 11), LiFi (May 17), Cherry Network (May 26), and Pika Protocol (May 31).","source":"ScamSniffer","source_url":"https://drops.scamsniffer.io/pink-drainer-steals-3m-from-multiple-hack-events-including-openai-cto-orbiter-finance/"},{"date":"2023-06","event":"Pink Drainer compromises Orbiter Finance, Flare Network, and the Twitter account of OpenAI CTO Mira Murati (June 1-2). ScamSniffer attributes approximately $3 million in total thefts to this campaign phase across 1,932 victims. The 'pink-drainer.eth' ENS address is identified, giving the group its name.","source":"BleepingComputer / The Register / ScamSniffer","source_url":"https://www.bleepingcomputer.com/news/cryptocurrency/hackers-steal-3-million-by-impersonating-crypto-news-journalists/"},{"date":"2023-07","event":"Pink Drainer activity formalized as an ongoing operation. ScamSniffer begins tracking cumulative statistics from this date.","source":"ScamSniffer Dune Dashboard","source_url":"https://dune.com/scamsniffer/pinkdrainer-stats"},{"date":"2023-11","event":"Inferno Drainer announces retirement. Pink Drainer accelerates theft activity, absorbing affiliates formerly using competing services.","source":"Nefture Security / Coinmonks","source_url":"https://medium.com/coinmonks/pink-drainer-out-inferno-drainer-back-new-shift-in-the-crypto-wallet-drainer-industry-6915c270bb68"},{"date":"2023-12","event":"Pink Drainer executes its largest single-victim theft: 275,700 LINK tokens ($4.33 million) drained from one victim via the Increase Approval exploit. Stolen LINK is laundered through eXch. ZachXBT documents the laundering activity.","source":"CoinTelegraph / CryptoPotato","source_url":"https://cointelegraph.com/news/chainlink-pink-drainer-crypto-phishing-scam"},{"date":"2023-12","event":"Cumulative Pink Drainer thefts reach $18.7 million from 9,068 victims as of December 19, 2023, per ScamSniffer.","source":"ScamSniffer / CryptoPotato","source_url":"https://cryptopotato.com/pink-drainer-hackers-drain-4-4-million-in-link/"},{"date":"2024-03","event":"PeckShield reports Pink Drainer-affiliated addresses have staked 12 million DAI into Spark DeFi protocol, making Pink Drainer one of the protocol's largest sDAI holders at approximately 1.194% of total supply.","source":"PeckShield / CryptoPotato","source_url":"https://cryptopotato.com/pink-drainer-addresses-stakes-12m-dai-in-spark-becoming-top-sdai-holder-peckshield/"},{"date":"2024-05","event":"Pink Drainer announces retirement on May 17, 2024. ZachXBT reveals the private Telegram message: 'We have reached our goal now, and according to plan, it's time for us to retire.' Cumulative theft stands at $85.29 million from 21,131 victims. Affiliated addresses hold approximately 18.1 million DAI staked in Spark.","source":"The Block / ZachXBT / Blocmates","source_url":"https://www.theblock.co/post/295041/pink-drainer-shutting-down"},{"date":"2024-07","event":"A Pink Drainer-affiliated wallet loses 10 ETH (approximately $30,000) to an address poisoning attack. The scam is discovered and reported by MistTrack and covered by The Block and CoinTelegraph.","source":"The Block / CryptoTimes","source_url":"https://www.theblock.co/post/303851/pink-drainer-address-poisoning"},{"date":"2026-03","event":"Approximately $117,000 in ETH and sDAI moves from Pink Drainer-associated wallets to a newly created address. Blockchain analysts estimate approximately $12 million in remaining holdings across Pink Drainer-linked addresses.","source":"MEXC News","source_url":"https://www.mexc.com/news/896215"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 9c42ee9f-61d9-4bfa-8495-5a73c2892b95
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.