← StepDrainer1 decision on this page
Audit log
Every state-changing event for StepDrainer: moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.
- #1publishby system:backfill2026-10-04 23:19:49ZScore: ? → ? (no score change)anchoranchored
- chain
- ●mainnet-betaslot 453,402,280
- sig
SZzQgn95zDfH…AKgtwyPfexplorer ↗- hash
WF5TGgVFSNu7…znekGPpesha256 → base58
verifying row…full verify ↗canonical bytes (12628 B) ▸
{"actor":"system:backfill","investigation_id":"16056c09-453f-4901-affa-a67d0e7e96b1","kind":"publish","page_slug":"stepdrainer","published_at":"2026-10-04T23:19:49.320Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"StepDrainer","sections":[{"content":"StepDrainer is a commercially sold Malware-as-a-Service (MaaS) platform engineered to steal digital assets from cryptocurrency wallets. It is distinct from other named drainer platforms such as Inferno Drainer. The platform was documented by SpiderLabs (LevelBlue) in April 2026 and by Cryptopolitan and Cryptonews.net in May 2026. It is distributed within cybercriminal ecosystems and requires no bespoke development by the purchasing threat actor, lowering the barrier for deployment.","heading":"Overview and Classification","severity":"critical","sources":[{"credibility":2,"name":"Crypto Drainers as a Converging Threat — SpiderLabs/LevelBlue","type":"research","url":"https://www.levelblue.com/blogs/spiderlabs-blog/crypto-drainers-as-a-converging-threat-insights-into-emerging-hybrid-attack-ecosystems"},{"credibility":2,"name":"StepDrainer MaaS Platform Targeting Multi-Chain Crypto Wallets — Offseq Radar","type":"research","url":"https://radar.offseq.com/threat/stepdrainer-maas-platform-targeting-multi-chain-cr-8e2c0d64"}]},{"content":"According to SpiderLabs (LevelBlue) and Offseq Radar, StepDrainer is sold at two price tiers within underground markets: approximately $750 for full source code access, and $150 for a shared version that carries a 20% commission deducted from each successful theft by the operator. This tiered model is consistent with the broader Drainer-as-a-Service ecosystem and enables multiple independent threat actors to deploy instances simultaneously.","heading":"Pricing and Distribution Model","severity":"critical","sources":[{"credibility":2,"name":"Crypto Drainers as a Converging Threat — SpiderLabs/LevelBlue","type":"research","url":"https://www.levelblue.com/blogs/spiderlabs-blog/crypto-drainers-as-a-converging-threat-insights-into-emerging-hybrid-attack-ecosystems"},{"credibility":2,"name":"StepDrainer MaaS Platform Targeting Multi-Chain Crypto Wallets — Offseq Radar","type":"research","url":"https://radar.offseq.com/threat/stepdrainer-maas-platform-targeting-multi-chain-cr-8e2c0d64"}]},{"content":"StepDrainer operates across more than 20 blockchain networks including Ethereum, BNB Chain, Arbitrum, and Polygon, targeting both ERC-20 fungible tokens and NFT collections. The platform abuses legitimate Web3 smart contract primitives — specifically OpenSea's Seaport protocol and EIP-2612 Permit v2 — to generate wallet-approval dialogs that are structurally indistinguishable from legitimate transaction prompts. Victims are shown fabricated reward messages (for example, fake '+500 USDT' transfer notifications) while unknowingly authorizing full asset transfers. The drainer prioritizes the highest-value holdings in a wallet first and supports automated cross-chain asset extraction. It is also compatible with widely used mobile wallets and includes encrypted logging via Telegram for operator monitoring. According to SpiderLabs, the platform supports both EVM and Solana routing modes and targets over 40 wallet types including Phantom, MetaMask, Trust Wallet, and Solflare.","heading":"Technical Capabilities and Attack Methods","severity":"critical","sources":[{"credibility":2,"name":"Crypto Drainers as a Converging Threat — SpiderLabs/LevelBlue","type":"research","url":"https://www.levelblue.com/blogs/spiderlabs-blog/crypto-drainers-as-a-converging-threat-insights-into-emerging-hybrid-attack-ecosystems"},{"credibility":2,"name":"StepDrainer drains crypto wallets across +20 networks — Cryptonews.net","type":"news_article","url":"https://cryptonews.net/news/security/32793104/"},{"credibility":2,"name":"StepDrainer drains crypto wallets across +20 networks — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/stepdrainer-crypto-wallets-20-networks/"}]},{"content":"Operators of StepDrainer have been observed deploying phishing pages that impersonate OpenClaw, a legitimate open-source AI assistant project. The fraudulent interface is styled as an 'AI-powered trading assistant,' featuring an AI mascot, gradient backgrounds, rounded UI elements, and false claims of automated portfolio analysis. Victims are encouraged to connect their wallets so the purported AI system can 'analyze' their on-chain activity. A Web3Modal-style wallet-selection grid displaying legitimate wallet logos is then presented, at which point the draining mechanism is triggered. The use of a credible AI brand and contemporary dashboard aesthetics is intended to reduce victim suspicion.","heading":"Social Engineering: AI Trading Assistant Lure","severity":"high","sources":[{"credibility":2,"name":"Crypto Drainers as a Converging Threat — SpiderLabs/LevelBlue","type":"research","url":"https://www.levelblue.com/blogs/spiderlabs-blog/crypto-drainers-as-a-converging-threat-insights-into-emerging-hybrid-attack-ecosystems"},{"credibility":2,"name":"StepDrainer MaaS Platform Targeting Multi-Chain Crypto Wallets — Offseq Radar","type":"research","url":"https://radar.offseq.com/threat/stepdrainer-maas-platform-targeting-multi-chain-cr-8e2c0d64"}]},{"content":"StepDrainer employs an unusual evasion architecture. According to SpiderLabs, campaign configuration is stored in Base64-encoded form within a Solana blockchain account (address: 8ycauMwVE61B4uWz87B2k2G8mMK7iFjRoBHooaVAcP4k), which has been active since September 2025. This account references over 100 on-chain transactions and is used to dynamically distribute domain configurations without relying on a traditional centralized command-and-control server. The platform's stager API endpoints have been identified across more than 3,000 domains. Malicious JavaScript payloads are heavily obfuscated and delivered through secondary CDN paths using randomized PHP endpoint names and variable names to evade signature-based detection. A fallback C2 domain of 8kwfaa30jtlnwi[.]com has been identified. Specific known malicious domains include moonscan.live and scanclaw.live, with a payload file hash of 7fd19c564761e2c8c9b583cf30db810e313417c7d3572f637f8cedf4d2cc1e91.","heading":"Infrastructure: On-Chain Configuration and Script Rotation","severity":"high","sources":[{"credibility":2,"name":"Crypto Drainers as a Converging Threat — SpiderLabs/LevelBlue","type":"research","url":"https://www.levelblue.com/blogs/spiderlabs-blog/crypto-drainers-as-a-converging-threat-insights-into-emerging-hybrid-attack-ecosystems"},{"credibility":2,"name":"StepDrainer MaaS Platform Targeting Multi-Chain Crypto Wallets — Offseq Radar","type":"research","url":"https://radar.offseq.com/threat/stepdrainer-maas-platform-targeting-multi-chain-cr-8e2c0d64"}]},{"content":"According to Cryptopolitan and Cryptonews.net reporting from May 2026, over 500 Ethereum wallets were drained within a single 24-hour window, with attackers reportedly siphoning more than $800,000 in crypto assets. Stolen funds were subsequently swapped via ThorChain, a cross-chain liquidity protocol that has been used as a laundering rail in multiple crypto theft incidents. On-chain analysis cited in those reports indicated that many targeted wallets had been inactive for more than seven years, suggesting the operators systematically scanned for dormant but funded addresses. These figures have not been independently corroborated by a Tier 1 source and should be treated as reported estimates. The Offseq Radar threat report separately notes that no specific exploits in the wild have been formally confirmed in its own analysis.","heading":"Reported Victim Impact and Financial Losses","severity":"critical","sources":[{"credibility":2,"name":"StepDrainer drains crypto wallets across +20 networks — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/stepdrainer-crypto-wallets-20-networks/"},{"credibility":2,"name":"StepDrainer drains crypto wallets across +20 networks — Cryptonews.net","type":"news_article","url":"https://cryptonews.net/news/security/32793104/"},{"credibility":2,"name":"StepDrainer MaaS Platform Targeting Multi-Chain Crypto Wallets — Offseq Radar","type":"research","url":"https://radar.offseq.com/threat/stepdrainer-maas-platform-targeting-multi-chain-cr-8e2c0d64"}]},{"content":"StepDrainer belongs to a documented category of Drainer-as-a-Service (DaaS) tools that commoditize crypto theft by selling ready-made kits to operators. SpiderLabs characterizes it as part of a converging threat ecosystem in which drainer kits, phishing infrastructure, and laundering rails are increasingly combined into hybrid attack chains. StepDrainer is operationally and commercially distinct from other named platforms such as Inferno Drainer, Monkey Drainer, and Angel Drainer, though it employs overlapping technical primitives (Seaport, Permit v2) common across the DaaS market.","heading":"Relationship to Broader Drainer Ecosystem","severity":"medium","sources":[{"credibility":2,"name":"Crypto Drainers as a Converging Threat — SpiderLabs/LevelBlue","type":"research","url":"https://www.levelblue.com/blogs/spiderlabs-blog/crypto-drainers-as-a-converging-threat-insights-into-emerging-hybrid-attack-ecosystems"},{"credibility":2,"name":"The Rise of Drainer-as-a-Service — SentinelOne","type":"research","url":"https://www.sentinelone.com/blog/the-rise-of-drainer-as-a-service-understanding-daas/"}]}],"sources_used":[{"credibility":2,"name":"Crypto Drainers as a Converging Threat — SpiderLabs/LevelBlue","type":"research","url":"https://www.levelblue.com/blogs/spiderlabs-blog/crypto-drainers-as-a-converging-threat-insights-into-emerging-hybrid-attack-ecosystems"},{"credibility":2,"name":"StepDrainer MaaS Platform Targeting Multi-Chain Crypto Wallets — Offseq Radar","type":"research","url":"https://radar.offseq.com/threat/stepdrainer-maas-platform-targeting-multi-chain-cr-8e2c0d64"},{"credibility":2,"name":"StepDrainer drains crypto wallets across +20 networks — Cryptopolitan","type":"news_article","url":"https://www.cryptopolitan.com/stepdrainer-crypto-wallets-20-networks/"},{"credibility":2,"name":"StepDrainer drains crypto wallets across +20 networks — Cryptonews.net","type":"news_article","url":"https://cryptonews.net/news/security/32793104/"},{"credibility":2,"name":"The Rise of Drainer-as-a-Service — SentinelOne","type":"research","url":"https://www.sentinelone.com/blog/the-rise-of-drainer-as-a-service-understanding-daas/"}],"summary":"StepDrainer is an active Malware-as-a-Service (MaaS) crypto wallet drainer commercially distributed within cybercriminal ecosystems. It supports more than 20 blockchain networks and abuses legitimate Web3 smart contract primitives, including Seaport and Permit v2, to present victims with convincing wallet-approval prompts. Security researchers reported in April and May 2026 that over 500 Ethereum wallets had been drained in a single 24-hour window, with losses reportedly exceeding $800,000.","timeline":[{"date":"2025-09","event":"Solana account 8ycauMwVE61B4uWz87B2k2G8mMK7iFjRoBHooaVAcP4k becomes active, later identified by SpiderLabs as StepDrainer's campaign configuration store.","source":"SpiderLabs/LevelBlue research","source_url":"https://www.levelblue.com/blogs/spiderlabs-blog/crypto-drainers-as-a-converging-threat-insights-into-emerging-hybrid-attack-ecosystems"},{"date":"2026-04-21","event":"Offseq Radar publishes threat intelligence report on StepDrainer, documenting its MaaS pricing, multi-chain scope, and known indicators of compromise including domains moonscan.live and scanclaw.live.","source":"Offseq Radar","source_url":"https://radar.offseq.com/threat/stepdrainer-maas-platform-targeting-multi-chain-cr-8e2c0d64"},{"date":"2026-04-23","event":"SpiderLabs (LevelBlue) publishes detailed technical analysis of StepDrainer as part of a broader report on converging crypto drainer threats, documenting Solana on-chain configuration, 3,000+ domains, OpenClaw impersonation, and IOCs.","source":"SpiderLabs/LevelBlue","source_url":"https://www.levelblue.com/blogs/spiderlabs-blog/crypto-drainers-as-a-converging-threat-insights-into-emerging-hybrid-attack-ecosystems"},{"date":"2026-05-01","event":"Cryptonews.net and Cryptopolitan report that over 500 Ethereum wallets were drained within a 24-hour period, with losses reportedly exceeding $800,000. Funds were reportedly laundered via ThorChain.","source":"Cryptonews.net / Cryptopolitan","source_url":"https://cryptonews.net/news/security/32793104/"}]},"v":1}Verify offline (run on your own machine)python -m src.verify_decision 4fb52d68-4bfb-411a-a8b9-16f763bf9400
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine —
python -m src.verify_decision <event_id>.