Skip to main content
AVOID.NET
← Back to search
[TOPIC]

Angel Drainer

Investigations tagged with this subject. A topic describes what a page is about — an attack type, a jurisdiction, a regulator, a named actor — as distinct from the source that produced it.

3 investigations on this topic

avoid.net/ledger58/100[CAUTIONARY]

Ledger is a France-based manufacturer of hardware cryptocurrency wallets (Nano S, Nano X, Stax, Flex) and maker of the Ledger Live companion app, reportedly securing over $100 billion in client assets across more than 7 million devices sold and preparing a US IPO targeting a valuation above $4 billion. The company has a strong core security record for its hardware products but has been repeatedly implicated in data-handling and supply-chain incidents: a 2020 breach of its own e-commerce/marketing database exposed roughly 1 million emails and 270,000 physical addresses, leading to years of phishing and alleged extortion attempts against customers and an ongoing US class action; a December 2023 npm supply-chain compromise via a former employee's account led to roughly $600,000 in DeFi losses; a May 2023 product announcement ('Ledger Recover') triggered a major trust backlash over perceived key-extraction capability; and in January 2026 a breach at third-party processor Global-e exposed customer order data. Separately, third parties impersonating Ledger — including a fraudulent 'Ledger Live' app that passed Apple App Store review in April 2026 — have caused further customer losses that Ledger did not directly control.

avoid.net/porkbun62/100[CAUTIONARY]

Porkbun LLC is a legitimate ICANN-accredited domain registrar founded circa 2014-2015, headquartered in Sherwood, Oregon, and managing over 3.45 million domains. While the company is not itself a scam operation, it has attracted scrutiny from the crypto security community — including on-chain investigator ZachXBT — for hosting phishing infrastructure linked to Angel Drainer and Inferno Drainer wallet-draining services, including fake Ledger sites. Third-party tracking platforms document hundreds of flagged phishing domains registered through Porkbun and allege that the company's abuse-response enforcement has been inadequate, with a majority of reported domains remaining active after formal abuse reports.

avoid.net/cointelegraph62/100[CAUTIONARY]

Cointelegraph is a major legitimate cryptocurrency news outlet that has been a victim of two distinct infrastructure compromises. In January 2024, attackers breached its email service provider MailerLite and sent phishing emails to subscribers using Angel Drainer malware, resulting in estimated losses of $580,000 to over $700,000 across affected platforms. In June 2025, attackers separately compromised Cointelegraph's banner advertising system to serve Inferno Drainer-linked pop-ups promoting a fake CTG token airdrop to site visitors.

avoid.net — verified advice for a post-truth world