v2 → v3
Scores
trust_score0 → 2
severity_base— → —
score_modifier0 → 0
Sections
Overview and Business Model
unchanged
Operator Identity and Background → Attack Methods and Technical Infrastructure
unchanged
Scale of Theft and Victim Count → Notable Incidents and High-Profile Targets
unchanged
Attack Methods and Techniques → Scale of Theft: Reconciling the Reported Totals
unchanged
Notable Victims and Incidents → Operator Identity, Attribution, and Law Enforcement Status
unchanged
On-Chain Addresses and Infrastructure → Shutdown Announcement and Post-Closure Activity
unchanged
Shutdown Announcement and Post-Closure Activity → On-Chain Addresses and Fund Flows
unchanged
ZachXBT Reporting and Investigator Coverage → Ecosystem Context and Relationship to Other Drainer Services
unchanged
Ecosystem Context and Affiliated Services → Prevention and Red Flags
unchanged
Known Operator and Fee-Collector Wallet Addresses → (section 10)
- Multiple on-chain analytics platforms and blockchain explorers have tagged the following Ethereum addresses as associated with Pink Drainer's operator infrastructure. Etherscan labels 0x63605e53d422c4f1ac0e01390ac59aaf84c44a51 as 'PinkDrainer: Wallet 1' and 0x9fa7bb759641fcd37fe4ae41f725e0f653f2c726 as 'PinkDrainer: Wallet 2.' An additional address, 0xa5e4b451d0a3c3d05fc3a8076fda45952b8f4f83, is labeled 'Pink Drainer 0xa5e4' on Etherscan with warnings attached by Blockmage Labs. In the December 2023 Chainlink LINK heist, the stolen 275,700 LINK tokens were split across two transactions: approximately 68,925 LINK went directly to the address labeled 'PinkDrainer: Wallet 2' (0x9fa7bb759641fcd37fe4ae41f725e0f653f2c726), while the remaining 206,775 LINK went to an affiliate address ending in 'E70e.' MistTrack, the compliance arm of SlowMist, identified the address 0x8980ab6d185af9bcc10292d4e91ae4c0b4f14213 as associated with Pink Drainer in a July 2024 post, noting that this address itself was subsequently victimized by an address poisoning scam after the group's retirement. The ENS domain pink-drainer.eth was also registered and used by the operators. Several additional addresses tagged as 'Pink Drainer Customer' on Etherscan include 0x5408eb7d0c5dd4a4073565cc009c0e04f922858d, 0xd7d1d6692e0612a632a78fab5a82e9c767d518bf, 0x842ed411f832a8f9dcfe1c6d520e0f0eb145d96e, and 0x5ae0804177de852b5524d6628544560bdb2a0aae, representing affiliate phishers who paid into or received proceeds from the service.+
Scale of Operations: Victims and Total Stolen → (section 11)
- According to data from ScamSniffer's Dune Analytics dashboard, Pink Drainer stole a total of approximately $85,297,091 across 21,131 victims over the course of its operation from July 2023 through May 2024. The growth trajectory was steep: as of June 2023, early reports identified approximately $2.99 million stolen from 1,932 victims. By December 19, 2023, total losses had risen to $18.7 million across 9,068 victims. By the time of the May 2024 shutdown announcement, cumulative losses had exceeded $85 million. Pink Drainer held an estimated 28% market share in the drainer-as-a-service ecosystem in early 2024, making it the dominant provider in that period. The service primarily targeted assets on Ethereum mainnet (approximately $2.43 million in early attacks alone) and Arbitrum, with additional losses on other EVM-compatible chains.+
Attack Methodology: Journalist Impersonation and Discord Compromise → (section 12)
- Pink Drainer affiliates employed a multi-stage social engineering attack to compromise high-profile Discord servers and Twitter/X accounts. In the primary method documented by ScamSniffer and Bleeping Computer, attackers impersonated journalists from prominent crypto media outlets including CoinTelegraph and Decrypt. Attackers would approach Discord server administrators or project team members via direct message, claiming to be reporters seeking an interview. Over several days of correspondence designed to build trust, victims were eventually directed through a fake KYC (Know Your Customer) process hosted on attacker-controlled domains. A malicious 'Drag Me' button in this workflow installed a JavaScript bookmark that silently stole the victim's Discord authentication token, bypassing two-factor authentication entirely. Once Discord tokens were obtained, attackers gained full administrative control of the target server, removed legitimate administrators, and posted phishing links promoting fake token airdrops, fake NFT mints, or fake bridge interactions. Victims who connected their wallets to these phishing pages and approved token transfer permissions lost their assets to the Pink Drainer smart contracts. The drainer script would analyze a victim's wallet, identify the most valuable assets, and execute optimized transactions to steal them.+
High-Profile Incidents and Named Victims → (section 13)
- Pink Drainer was attributed to a series of high-profile phishing incidents throughout 2023. In May and June 2023, multiple project Discord servers were compromised using the journalist impersonation method, including Evmos (May 8, 2023; phishing domain evmos-claim.org), Starknet ID (May 11), LiFi Protocol (May 17), Cherry Network (May 26), Pika Protocol (May 31; pikaprotocol.pm), Orbiter Finance (June 1; orbiter.pm), Flare Network (June 1), and the Twitter account of OpenAI CTO Mira Murati (June 2; chatgpt.build). Steve Aoki's account was also compromised in this wave. One notable victim of the June 2023 wave lost approximately $320,000 in NFTs including eight Otherside Koda NFTs, one Bored Ape Yacht Club NFT, and eleven Otherdeed NFTs from address 0xf529127107c91bbf6c141304718491a437fb2f5f. On September 9, 2023, the Twitter/X account of Ethereum co-founder Vitalik Buterin was compromised via a SIM-swap attack against his T-Mobile account. Pink Drainer was used to drain approximately $691,000-$700,000 from followers who clicked a fake commemorative NFT mint link promoted from the hijacked account. Pink Drainer operators received an estimated 33% cut of proceeds from this incident. On December 29, 2023, Pink Drainer was identified as responsible for a $4.4 million theft of Chainlink LINK tokens from a single victim. The victim was induced to sign an 'Increase Approval' transaction, after which 68,925 LINK was sent to PinkDrainer: Wallet 2 (0x9fa7bb759641fcd37fe4ae41f725e0f653f2c726) and 206,775 LINK to an affiliate address ending in 'E70e.' ZachXBT confirmed the stolen funds were subsequently converted to ETH and laundered through the eXch instant exchange.+
Money Laundering and Fund Flows → (section 14)
- Stolen funds from Pink Drainer operations were laundered through several methods. In the December 2023 Chainlink heist, ZachXBT reported that stolen LINK was converted to ETH and funneled through eXch, an instant cryptocurrency exchange that does not require identity verification. Protos reported that prior to shutdown, Pink Drainer-associated wallets had converted a significant portion of stolen proceeds to MakerDAO's sDAI (savings DAI), earning yield on illicit funds. Two addresses holding sDAI attributable to Pink Drainer were identified as the eleventh-largest combined holder of sDAI at the time, representing approximately 1.3% of the total sDAI supply. BscScan also records the PinkDrainer Wallet 1 address (0x63605e53d422c4f1ac0e01390ac59aaf84c44a51) operating across the BNB Smart Chain in addition to Ethereum mainnet, indicating multi-chain operations.+
Shutdown Announcement (May 2024) → (section 15)
- On May 17, 2024, the Pink Drainer operators announced their retirement via a private Telegram channel message. The announcement stated: 'We have reached our goal now, and according to plan, it is time for us to retire.' The operators confirmed they had no plans to return and that all stored user data and infrastructure would be wiped and securely destroyed. They claimed to have operated 'without any scams, backdooring, or major incidents' during their tenure. The operators also warned active affiliates that impersonators might attempt to fill the void. The retirement message included: 'It is very likely that our retirement will have no major impact on the scene, people will move on to other drainers just as quickly as they moved to us,' and urged affiliates to 'take a step back from the grind and enjoy what this world has to offer.' SlowMist founder Yu Xian publicly expressed skepticism about the permanence of the retirement, noting that law enforcement records made a clean exit difficult. Indeed, in July 2024 a wallet linked to the Pink Drainer operators (0x8980ab6d185af9bcc10292d4e91ae4c0b4f14213, identified by MistTrack/SlowMist) lost 10 ETH (approximately $30,000) to an address poisoning scam, demonstrating that funds from the operation continued to be moved post-shutdown.+
Industry Context and Successor Services → (section 16)
- Pink Drainer was one of several drainer-as-a-service platforms that emerged following the success of Monkey Drainer (which stole approximately $16.5 million before shutting down in February 2023) and Inferno Drainer (which facilitated over $80 million in theft before shutting down in November 2023). According to Nefture Security analysis, Pink Drainer held approximately 28% of the DaaS market at its peak in early 2024. Following Pink Drainer's retirement, Inferno Drainer subsequently re-emerged, and other services including Angel Drainer, Pussy Drainer, and Venom Drainer continued operating. ScamSniffer's 2024 annual report found that wallet drainer attacks collectively caused $494 million in losses across 332,000 victim addresses during 2024, a 67% increase year-over-year, despite Pink Drainer's retirement mid-year. The ACM Internet Measurement Conference published academic research in 2025 analyzing drainer-as-a-service operations on Ethereum, providing peer-reviewed documentation of this ecosystem.+
What Is Pink Drainer → (section 17)
unchanged
Business Model and Fee Structure → (section 18)
unchanged
Attack Methods and Technical Infrastructure → (section 19)
unchanged
Notable Attacks and High-Profile Targets → (section 20)
unchanged
The 'Retirement' Announcement (May 2024) → (section 21)
unchanged
On-Chain Tracking and Fund Flows → (section 22)
unchanged
Relationship to the Broader Drainer Ecosystem → (section 23)
unchanged
Law Enforcement and Attribution Challenges → (section 24)
unchanged
Prevention and Defense → (section 25)
unchanged
Red Flags and Indicators of a Pink Drainer Campaign → (section 26)
unchanged
Timeline events
+ added2024-06 — (no description)
+ added2024 — (no description)
- removed2023-03 — (no description)
- removed2023-05 — (no description)
- removed2023-05-08 — (no description)
- removed2023-05-31 — (no description)
- removed2023-06-02 — (no description)
- removed2023-06-12 — (no description)
- removed2023-07 — (no description)
- removed2023-11 — (no description)
- removed2023-12-19 — (no description)
- removed2023-12-29 — (no description)
- removed2024-05 — (no description)
- removed2024-07-07 — (no description)
- removed2026-03 — (no description)
~ changed2023-04: “” → “”
~ changed2023-06: “” → “”
~ changed2023-09-09: “” → “”
~ changed2023-12: “” → “”
~ changed2024-03: “” → “”
~ changed2024-05-17: “” → “”
~ changed2024-07: “” → “”
Accepted submissions
No changes to accepted submissions.
Each version is bound to the decision event that created it. Verify the chain anchor for either via the audit log.
v2 hash: 786a93e60ec24d17f8379b1479a3ab043c16e498dfbf6a923815a275b5911139
v3 hash: b02d8869684b8da26ab30d29470f84cb73300ac1832e4b69364b2f40e5e6c7b7