Skip to main content
AVOID.NET

v1 → v2

Scores

trust_score00
severity_base
score_modifier00

Sections

Overview and Business Model

unchanged

Operator Identity and Background

unchanged

Scale of Theft and Victim Count

unchanged

Attack Methods and Techniques

unchanged

Notable Victims and Incidents

unchanged

On-Chain Addresses and Infrastructure

unchanged

Shutdown Announcement and Post-Closure Activity

unchanged

ZachXBT Reporting and Investigator Coverage

unchanged

Ecosystem Context and Affiliated Services

unchanged

Overview and Business Model → Known Operator and Fee-Collector Wallet Addresses

- Pink Drainer operated as a Drainer-as-a-Service (DaaS) platform, providing ready-made phishing toolkits to cybercriminals who deployed them across Discord servers, Twitter/X accounts, and fake project websites. The operators of Pink Drainer charged affiliates an upfront deposit and collected a 20-30% commission on all proceeds stolen by users of the toolkit. Profits were automatically split between the scammer deploying the phishing site and the Pink Drainer developer within the smart contract code itself. The service launched in approximately July 2023 and attracted a significant user base among crypto phishers who lacked the technical skills to build their own drainer scripts. According to Rekt News, the Pink Drainer script was described as sophisticated, selectively targeting the most valuable assets in a victim's wallet rather than draining indiscriminately. The service accepted affiliates via a private Telegram channel and provided website-building infrastructure, smart contract templates, and support.+ Multiple on-chain analytics platforms and blockchain explorers have tagged the following Ethereum addresses as associated with Pink Drainer's operator infrastructure. Etherscan labels 0x63605e53d422c4f1ac0e01390ac59aaf84c44a51 as 'PinkDrainer: Wallet 1' and 0x9fa7bb759641fcd37fe4ae41f725e0f653f2c726 as 'PinkDrainer: Wallet 2.' An additional address, 0xa5e4b451d0a3c3d05fc3a8076fda45952b8f4f83, is labeled 'Pink Drainer 0xa5e4' on Etherscan with warnings attached by Blockmage Labs. In the December 2023 Chainlink LINK heist, the stolen 275,700 LINK tokens were split across two transactions: approximately 68,925 LINK went directly to the address labeled 'PinkDrainer: Wallet 2' (0x9fa7bb759641fcd37fe4ae41f725e0f653f2c726), while the remaining 206,775 LINK went to an affiliate address ending in 'E70e.' MistTrack, the compliance arm of SlowMist, identified the address 0x8980ab6d185af9bcc10292d4e91ae4c0b4f14213 as associated with Pink Drainer in a July 2024 post, noting that this address itself was subsequently victimized by an address poisoning scam after the group's retirement. The ENS domain pink-drainer.eth was also registered and used by the operators. Several additional addresses tagged as 'Pink Drainer Customer' on Etherscan include 0x5408eb7d0c5dd4a4073565cc009c0e04f922858d, 0xd7d1d6692e0612a632a78fab5a82e9c767d518bf, 0x842ed411f832a8f9dcfe1c6d520e0f0eb145d96e, and 0x5ae0804177de852b5524d6628544560bdb2a0aae, representing affiliate phishers who paid into or received proceeds from the service.

Known Operator and Fee-Collector Wallet Addresses → Scale of Operations: Victims and Total Stolen

- Multiple on-chain analytics platforms and blockchain explorers have tagged the following Ethereum addresses as associated with Pink Drainer's operator infrastructure. Etherscan labels 0x63605e53d422c4f1ac0e01390ac59aaf84c44a51 as 'PinkDrainer: Wallet 1' and 0x9fa7bb759641fcd37fe4ae41f725e0f653f2c726 as 'PinkDrainer: Wallet 2.' An additional address, 0xa5e4b451d0a3c3d05fc3a8076fda45952b8f4f83, is labeled 'Pink Drainer 0xa5e4' on Etherscan with warnings attached by Blockmage Labs. In the December 2023 Chainlink LINK heist, the stolen 275,700 LINK tokens were split across two transactions: approximately 68,925 LINK went directly to the address labeled 'PinkDrainer: Wallet 2' (0x9fa7bb759641fcd37fe4ae41f725e0f653f2c726), while the remaining 206,775 LINK went to an affiliate address ending in 'E70e.' MistTrack, the compliance arm of SlowMist, identified the address 0x8980ab6d185af9bcc10292d4e91ae4c0b4f14213 as associated with Pink Drainer in a July 2024 post, noting that this address itself was subsequently victimized by an address poisoning scam after the group's retirement. The ENS domain pink-drainer.eth was also registered and used by the operators. Several additional addresses tagged as 'Pink Drainer Customer' on Etherscan include 0x5408eb7d0c5dd4a4073565cc009c0e04f922858d, 0xd7d1d6692e0612a632a78fab5a82e9c767d518bf, 0x842ed411f832a8f9dcfe1c6d520e0f0eb145d96e, and 0x5ae0804177de852b5524d6628544560bdb2a0aae, representing affiliate phishers who paid into or received proceeds from the service.+ According to data from ScamSniffer's Dune Analytics dashboard, Pink Drainer stole a total of approximately $85,297,091 across 21,131 victims over the course of its operation from July 2023 through May 2024. The growth trajectory was steep: as of June 2023, early reports identified approximately $2.99 million stolen from 1,932 victims. By December 19, 2023, total losses had risen to $18.7 million across 9,068 victims. By the time of the May 2024 shutdown announcement, cumulative losses had exceeded $85 million. Pink Drainer held an estimated 28% market share in the drainer-as-a-service ecosystem in early 2024, making it the dominant provider in that period. The service primarily targeted assets on Ethereum mainnet (approximately $2.43 million in early attacks alone) and Arbitrum, with additional losses on other EVM-compatible chains.

Scale of Operations: Victims and Total Stolen → Attack Methodology: Journalist Impersonation and Discord Compromise

- According to data from ScamSniffer's Dune Analytics dashboard, Pink Drainer stole a total of approximately $85,297,091 across 21,131 victims over the course of its operation from July 2023 through May 2024. The growth trajectory was steep: as of June 2023, early reports identified approximately $2.99 million stolen from 1,932 victims. By December 19, 2023, total losses had risen to $18.7 million across 9,068 victims. By the time of the May 2024 shutdown announcement, cumulative losses had exceeded $85 million. Pink Drainer held an estimated 28% market share in the drainer-as-a-service ecosystem in early 2024, making it the dominant provider in that period. The service primarily targeted assets on Ethereum mainnet (approximately $2.43 million in early attacks alone) and Arbitrum, with additional losses on other EVM-compatible chains.+ Pink Drainer affiliates employed a multi-stage social engineering attack to compromise high-profile Discord servers and Twitter/X accounts. In the primary method documented by ScamSniffer and Bleeping Computer, attackers impersonated journalists from prominent crypto media outlets including CoinTelegraph and Decrypt. Attackers would approach Discord server administrators or project team members via direct message, claiming to be reporters seeking an interview. Over several days of correspondence designed to build trust, victims were eventually directed through a fake KYC (Know Your Customer) process hosted on attacker-controlled domains. A malicious 'Drag Me' button in this workflow installed a JavaScript bookmark that silently stole the victim's Discord authentication token, bypassing two-factor authentication entirely. Once Discord tokens were obtained, attackers gained full administrative control of the target server, removed legitimate administrators, and posted phishing links promoting fake token airdrops, fake NFT mints, or fake bridge interactions. Victims who connected their wallets to these phishing pages and approved token transfer permissions lost their assets to the Pink Drainer smart contracts. The drainer script would analyze a victim's wallet, identify the most valuable assets, and execute optimized transactions to steal them.

Attack Methodology: Journalist Impersonation and Discord Compromise → High-Profile Incidents and Named Victims

- Pink Drainer affiliates employed a multi-stage social engineering attack to compromise high-profile Discord servers and Twitter/X accounts. In the primary method documented by ScamSniffer and Bleeping Computer, attackers impersonated journalists from prominent crypto media outlets including CoinTelegraph and Decrypt. Attackers would approach Discord server administrators or project team members via direct message, claiming to be reporters seeking an interview. Over several days of correspondence designed to build trust, victims were eventually directed through a fake KYC (Know Your Customer) process hosted on attacker-controlled domains. A malicious 'Drag Me' button in this workflow installed a JavaScript bookmark that silently stole the victim's Discord authentication token, bypassing two-factor authentication entirely. Once Discord tokens were obtained, attackers gained full administrative control of the target server, removed legitimate administrators, and posted phishing links promoting fake token airdrops, fake NFT mints, or fake bridge interactions. Victims who connected their wallets to these phishing pages and approved token transfer permissions lost their assets to the Pink Drainer smart contracts. The drainer script would analyze a victim's wallet, identify the most valuable assets, and execute optimized transactions to steal them.+ Pink Drainer was attributed to a series of high-profile phishing incidents throughout 2023. In May and June 2023, multiple project Discord servers were compromised using the journalist impersonation method, including Evmos (May 8, 2023; phishing domain evmos-claim.org), Starknet ID (May 11), LiFi Protocol (May 17), Cherry Network (May 26), Pika Protocol (May 31; pikaprotocol.pm), Orbiter Finance (June 1; orbiter.pm), Flare Network (June 1), and the Twitter account of OpenAI CTO Mira Murati (June 2; chatgpt.build). Steve Aoki's account was also compromised in this wave. One notable victim of the June 2023 wave lost approximately $320,000 in NFTs including eight Otherside Koda NFTs, one Bored Ape Yacht Club NFT, and eleven Otherdeed NFTs from address 0xf529127107c91bbf6c141304718491a437fb2f5f. On September 9, 2023, the Twitter/X account of Ethereum co-founder Vitalik Buterin was compromised via a SIM-swap attack against his T-Mobile account. Pink Drainer was used to drain approximately $691,000-$700,000 from followers who clicked a fake commemorative NFT mint link promoted from the hijacked account. Pink Drainer operators received an estimated 33% cut of proceeds from this incident. On December 29, 2023, Pink Drainer was identified as responsible for a $4.4 million theft of Chainlink LINK tokens from a single victim. The victim was induced to sign an 'Increase Approval' transaction, after which 68,925 LINK was sent to PinkDrainer: Wallet 2 (0x9fa7bb759641fcd37fe4ae41f725e0f653f2c726) and 206,775 LINK to an affiliate address ending in 'E70e.' ZachXBT confirmed the stolen funds were subsequently converted to ETH and laundered through the eXch instant exchange.

High-Profile Incidents and Named Victims → Money Laundering and Fund Flows

- Pink Drainer was attributed to a series of high-profile phishing incidents throughout 2023. In May and June 2023, multiple project Discord servers were compromised using the journalist impersonation method, including Evmos (May 8, 2023; phishing domain evmos-claim.org), Starknet ID (May 11), LiFi Protocol (May 17), Cherry Network (May 26), Pika Protocol (May 31; pikaprotocol.pm), Orbiter Finance (June 1; orbiter.pm), Flare Network (June 1), and the Twitter account of OpenAI CTO Mira Murati (June 2; chatgpt.build). Steve Aoki's account was also compromised in this wave. One notable victim of the June 2023 wave lost approximately $320,000 in NFTs including eight Otherside Koda NFTs, one Bored Ape Yacht Club NFT, and eleven Otherdeed NFTs from address 0xf529127107c91bbf6c141304718491a437fb2f5f. On September 9, 2023, the Twitter/X account of Ethereum co-founder Vitalik Buterin was compromised via a SIM-swap attack against his T-Mobile account. Pink Drainer was used to drain approximately $691,000-$700,000 from followers who clicked a fake commemorative NFT mint link promoted from the hijacked account. Pink Drainer operators received an estimated 33% cut of proceeds from this incident. On December 29, 2023, Pink Drainer was identified as responsible for a $4.4 million theft of Chainlink LINK tokens from a single victim. The victim was induced to sign an 'Increase Approval' transaction, after which 68,925 LINK was sent to PinkDrainer: Wallet 2 (0x9fa7bb759641fcd37fe4ae41f725e0f653f2c726) and 206,775 LINK to an affiliate address ending in 'E70e.' ZachXBT confirmed the stolen funds were subsequently converted to ETH and laundered through the eXch instant exchange.+ Stolen funds from Pink Drainer operations were laundered through several methods. In the December 2023 Chainlink heist, ZachXBT reported that stolen LINK was converted to ETH and funneled through eXch, an instant cryptocurrency exchange that does not require identity verification. Protos reported that prior to shutdown, Pink Drainer-associated wallets had converted a significant portion of stolen proceeds to MakerDAO's sDAI (savings DAI), earning yield on illicit funds. Two addresses holding sDAI attributable to Pink Drainer were identified as the eleventh-largest combined holder of sDAI at the time, representing approximately 1.3% of the total sDAI supply. BscScan also records the PinkDrainer Wallet 1 address (0x63605e53d422c4f1ac0e01390ac59aaf84c44a51) operating across the BNB Smart Chain in addition to Ethereum mainnet, indicating multi-chain operations.

Money Laundering and Fund Flows → Shutdown Announcement (May 2024)

- Stolen funds from Pink Drainer operations were laundered through several methods. In the December 2023 Chainlink heist, ZachXBT reported that stolen LINK was converted to ETH and funneled through eXch, an instant cryptocurrency exchange that does not require identity verification. Protos reported that prior to shutdown, Pink Drainer-associated wallets had converted a significant portion of stolen proceeds to MakerDAO's sDAI (savings DAI), earning yield on illicit funds. Two addresses holding sDAI attributable to Pink Drainer were identified as the eleventh-largest combined holder of sDAI at the time, representing approximately 1.3% of the total sDAI supply. BscScan also records the PinkDrainer Wallet 1 address (0x63605e53d422c4f1ac0e01390ac59aaf84c44a51) operating across the BNB Smart Chain in addition to Ethereum mainnet, indicating multi-chain operations.+ On May 17, 2024, the Pink Drainer operators announced their retirement via a private Telegram channel message. The announcement stated: 'We have reached our goal now, and according to plan, it is time for us to retire.' The operators confirmed they had no plans to return and that all stored user data and infrastructure would be wiped and securely destroyed. They claimed to have operated 'without any scams, backdooring, or major incidents' during their tenure. The operators also warned active affiliates that impersonators might attempt to fill the void. The retirement message included: 'It is very likely that our retirement will have no major impact on the scene, people will move on to other drainers just as quickly as they moved to us,' and urged affiliates to 'take a step back from the grind and enjoy what this world has to offer.' SlowMist founder Yu Xian publicly expressed skepticism about the permanence of the retirement, noting that law enforcement records made a clean exit difficult. Indeed, in July 2024 a wallet linked to the Pink Drainer operators (0x8980ab6d185af9bcc10292d4e91ae4c0b4f14213, identified by MistTrack/SlowMist) lost 10 ETH (approximately $30,000) to an address poisoning scam, demonstrating that funds from the operation continued to be moved post-shutdown.

Shutdown Announcement (May 2024) → Industry Context and Successor Services

- On May 17, 2024, the Pink Drainer operators announced their retirement via a private Telegram channel message. The announcement stated: 'We have reached our goal now, and according to plan, it is time for us to retire.' The operators confirmed they had no plans to return and that all stored user data and infrastructure would be wiped and securely destroyed. They claimed to have operated 'without any scams, backdooring, or major incidents' during their tenure. The operators also warned active affiliates that impersonators might attempt to fill the void. The retirement message included: 'It is very likely that our retirement will have no major impact on the scene, people will move on to other drainers just as quickly as they moved to us,' and urged affiliates to 'take a step back from the grind and enjoy what this world has to offer.' SlowMist founder Yu Xian publicly expressed skepticism about the permanence of the retirement, noting that law enforcement records made a clean exit difficult. Indeed, in July 2024 a wallet linked to the Pink Drainer operators (0x8980ab6d185af9bcc10292d4e91ae4c0b4f14213, identified by MistTrack/SlowMist) lost 10 ETH (approximately $30,000) to an address poisoning scam, demonstrating that funds from the operation continued to be moved post-shutdown.+ Pink Drainer was one of several drainer-as-a-service platforms that emerged following the success of Monkey Drainer (which stole approximately $16.5 million before shutting down in February 2023) and Inferno Drainer (which facilitated over $80 million in theft before shutting down in November 2023). According to Nefture Security analysis, Pink Drainer held approximately 28% of the DaaS market at its peak in early 2024. Following Pink Drainer's retirement, Inferno Drainer subsequently re-emerged, and other services including Angel Drainer, Pussy Drainer, and Venom Drainer continued operating. ScamSniffer's 2024 annual report found that wallet drainer attacks collectively caused $494 million in losses across 332,000 victim addresses during 2024, a 67% increase year-over-year, despite Pink Drainer's retirement mid-year. The ACM Internet Measurement Conference published academic research in 2025 analyzing drainer-as-a-service operations on Ethereum, providing peer-reviewed documentation of this ecosystem.

Industry Context and Successor Services → What Is Pink Drainer

- Pink Drainer was one of several drainer-as-a-service platforms that emerged following the success of Monkey Drainer (which stole approximately $16.5 million before shutting down in February 2023) and Inferno Drainer (which facilitated over $80 million in theft before shutting down in November 2023). According to Nefture Security analysis, Pink Drainer held approximately 28% of the DaaS market at its peak in early 2024. Following Pink Drainer's retirement, Inferno Drainer subsequently re-emerged, and other services including Angel Drainer, Pussy Drainer, and Venom Drainer continued operating. ScamSniffer's 2024 annual report found that wallet drainer attacks collectively caused $494 million in losses across 332,000 victim addresses during 2024, a 67% increase year-over-year, despite Pink Drainer's retirement mid-year. The ACM Internet Measurement Conference published academic research in 2025 analyzing drainer-as-a-service operations on Ethereum, providing peer-reviewed documentation of this ecosystem.+ 

(section 18) → Business Model and Fee Structure

unchanged

(section 19) → Attack Methods and Technical Infrastructure

unchanged

(section 20) → Notable Attacks and High-Profile Targets

unchanged

(section 21) → The 'Retirement' Announcement (May 2024)

unchanged

(section 22) → On-Chain Tracking and Fund Flows

unchanged

(section 23) → Relationship to the Broader Drainer Ecosystem

unchanged

(section 24) → Law Enforcement and Attribution Challenges

unchanged

(section 25) → Prevention and Defense

unchanged

(section 26) → Red Flags and Indicators of a Pink Drainer Campaign

unchanged

Timeline events

No timeline changes.

Accepted submissions

No changes to accepted submissions.

Each version is bound to the decision event that created it. Verify the chain anchor for either via the audit log.

v1 hash: 570e8372c0cf7fe31efcfac22e7628e3c92c56a2e0b69ce1203cac5bd4d95448
v2 hash: 786a93e60ec24d17f8379b1479a3ab043c16e498dfbf6a923815a275b5911139