Vanilla Drainer (DaaS)
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·21MTz1…zxSTSummary
Vanilla Drainer is a Drainer-as-a-Service (DaaS) criminal platform first documented in October 2024 that provides phishing kits and malicious smart contract infrastructure to affiliate fraudsters in exchange for a 15-20% commission on stolen proceeds. Blockchain investigator Darkbit attributed at least $5.27 million in cryptocurrency thefts to the service within a three-week window in mid-2025, and the Security Alliance (SEAL) identified Vanilla Drainer as one of the two primary drainer families deployed via Google Ads malvertising campaigns that stole more than $1.27 million between March 13-30, 2026. No operators have been publicly identified and no law enforcement actions against the service have been confirmed as of mid-2026.
Connected Entities
1 entities- + 2 more
Timeline(10 events)
October 2024
Earliest thefts attributed to Vanilla Drainer infrastructure observed on-chain according to Darkbit's retrospective analysis.
CoinTelegraph / Darkbit8 December 2024
Vanilla Drainer's first known public advertisement posted on underground forums, claiming an 'advanced algorithm' capable of bypassing Blockaid fraud detection. The advertisement has since been removed.
CoinTelegraph / Darkbit15 July 2025
Start of the confirmed three-week window during which Darkbit tracked at least $5.27 million in thefts attributed to Vanilla Drainer across four major incidents.
FinanceFeeds / DarkbitJuly 2025
Darkbit links Vanilla Drainer to $2.19 million in July 2025 losses, comprising over 30% of the month's total phishing losses.
FinanceFeeds / Darkbit5 August 2025
Largest single Vanilla Drainer incident: a victim loses $3.09 million in stablecoins. Operators receive an estimated $463,000 commission at approximately 17%.
CoinTelegraph / FinanceFeeds5 August 2025
Darkbit publishes thread on X attributing $5.27 million in thefts to Vanilla Drainer and identifying fee wallet 0x9d3...E710d holding approximately $2.23 million.
Darkbit on X7 October 2025
Security Alliance (SEAL) publishes 'State of Drainers Vol. 1,' naming Vanilla Drainer among four actively monitored drainer families alongside Inferno, Rublevka, and Eleven.
Security Alliance Radar9 February 2026
Ethereum Foundation and SEAL announce 'Trillion Dollar Security' initiative, funding a dedicated security engineer to combat wallet drainers including Vanilla Drainer.
CoinTelegraph13 March 2026
SEAL begins tracking a wave of malicious Google Ads campaigns deploying Vanilla Drainer and Inferno Drainer payloads impersonating Uniswap (41% of URLs), Morpho Finance (31%), and other DeFi protocols.
Security Alliance Radar30 March 2026
SEAL's documented March 13-30 campaign window closes with $810,929 in directly attributed losses and $1,274,259 in total including victim-reported incidents. SEAL has blocked 356+ malicious ad URLs.
Security Alliance RadarDecision Log
- hash: C9Swpv1xN9wHJdSw7yBvVkwCqi4eePw8kwRDr5RqmF3s
- hash: 2d2CgPbmhcn2jCA3nXJqx2xAgLTrCw9scTKVKTvp26ke
- hash: 869yKHEA1hatrVB7b9VyGM7hCHQFUx5HEnw5GZhKXDS8
This investigation is cryptographically anchored to the Solana blockchain (3 events). 12 of 16 cited source URLs have an Internet Archive snapshot.
model: claude-code-investigator
generated: 6/7/2026, 11:29:35 PM
last updated: 8/2/2026, 12:32:47 PM
4 viewsavoid.net — verified advice for a post-truth world