Skip to main content
AVOID.NET
← Back to search
[TOPIC]

Drainer

Investigations tagged with this subject. A topic describes what a page is about — an attack type, a jurisdiction, a regulator, a named actor — as distinct from the source that produced it.

5 investigations on this topic

avoid.net/fake-hyperliquid-app0/100[CRITICAL]

A fraudulent mobile application impersonating Hyperliquid, the decentralized perpetuals exchange, was identified on the Google Play Store in November 2025 by on-chain investigator ZachXBT. The app, published under the developer name 'Tvtion Inc.', replicated Hyperliquid's branding and interface to harvest users' seed phrases, transmitting them to an external server. An Ethereum address linked to the operation has been associated with thefts exceeding $281,000; Hyperliquid has never released an official mobile application, making any such listing inherently fraudulent.

avoid.net/inferno-drainer0/100[CRITICAL]

Inferno Drainer is a scam-as-a-service (drainer-as-a-service) platform that provided phishing infrastructure and malicious wallet-draining scripts to criminal affiliates in exchange for a percentage of stolen funds. Active from November 2022 through at least early 2025, it is attributed to stealing over $80 million from approximately 137,000 victims during its initial operational phase, with operators claiming a cumulative total exceeding $250 million across all periods including a covert post-shutdown phase. It operates by luring victims to phishing websites impersonating legitimate crypto brands, tricking users into signing malicious transactions that drain wallets across multiple EVM-compatible blockchains.

avoid.net/pink-drainer2/100[CRITICAL]

Pink Drainer was a pseudonymous wallet-drainer-as-a-service operation that supplied phishing kits and malicious smart-contract infrastructure to affiliate scammers between roughly April 2023 and May 2024. Security researchers, principally Scam Sniffer and blockchain investigator ZachXBT, attribute upward of $75-85 million in stolen crypto assets across an estimated 20,000-21,000+ victims to wallets and infrastructure linked to the group before it announced its retirement in May 2024. No law enforcement agency has publicly identified or charged the individuals behind the operation, so all attributions of activity and identity in this report come from private security researchers rather than courts or regulators.

avoid.net/ton-blockchain44/100[WARNING]

TON (The Open Network) is a public layer-1 blockchain originally developed by Telegram and now deeply integrated with the Telegram messaging app under Pavel Durov's direction. It is a live, widely used network with legitimate exchanges, DeFi protocols, and hundreds of millions of Telegram Mini App users, but it has also become a recurring venue for phishing drainers, pyramid schemes, rug pulls, malware command-and-control infrastructure, and illicit Telegram-based marketplaces, in part because analytics and forensic tooling for TON lagged behind more established chains. Separately, Telegram co-founder Pavel Durov faces an unresolved criminal investigation in France opened in 2024 and, since July 2026, an in-absentia terrorism-related charge in Russia; neither has resulted in a conviction.

avoid.net/cointelegraph62/100[CAUTIONARY]

Cointelegraph is a major legitimate cryptocurrency news outlet that has been a victim of two distinct infrastructure compromises. In January 2024, attackers breached its email service provider MailerLite and sent phishing emails to subscribers using Angel Drainer malware, resulting in estimated losses of $580,000 to over $700,000 across affected platforms. In June 2025, attackers separately compromised Cointelegraph's banner advertising system to serve Inferno Drainer-linked pop-ups promoting a fake CTG token airdrop to site visitors.

avoid.net — verified advice for a post-truth world