Discover how hacker group Pink Drainer stole $3 million in crypto through phishing attacks, posing as journalists on Discord & Twitter

Continue reading
ScamSniffer, a threat intelligence firm, analyzed a seris of hacking incidents involving Twitter & Discord and identified a common thread connecting all of them—a group is known as Pink Drainer.
Further investigation revealed that nearly all Discord hacks in the past month could be attributed to this group. By examining stolen data across various chains, including Mainnet, Arbitrum, BNB, Polygon, and Optimism, ScamSniffer estimates that Pink Drainer has managed to steal approximately $3 million in assets, affecting nearly 1,932 victims.
Several Discord hacks linked to Pink Drainer, involves Evomos, Starknet ID, LiFi, OpenAI CTO and more. These incidents highlight the broad scope of Pink Drainer's activities and their potential threat to the cryptocurrency community.
Pink Drainer leverages social engineering attacks to gain access to projects. Through careful impersonation of journalists from reputable media outlets like Decrypto and Cointelegraph, the threat actors deceived their victims. This involved interviewing victims for 1-3 days, culminating in KYC authentication as the final step in Discord-related phishing techniques.

*Fake Decrypt page hosting an interview form (ScamSniffer)*
Pink Drainer guided Discord admins to open a deceitful Carl verification bot and add bookmarks with malicious code. These bookmarks contained a seemingly innocent button labeled "Drag Me," which, in reality, executed malicious JavaScript code capable of stealing the user's Discord Token. Following these steps would result in the theft of the relevant Discord token, granting the threat actors unauthorized access.
To delve deeper into the technical intricacies of this method, you can consult the comprehensive report by SlowMist titled "How Scammer Utilized Malicious Bookmarks to Infiltrate NFT Project Discords."
Once Pink Drainer successfully gains permission, they take further measures to prolong their control over the compromised accounts. The steps involve removing admins, setting the malicious account as admin, and committing violations that block the main account on Discord. These tactics make it challenging to remove phishing messages from Discord Servers, ensuring the threat actors maintain their foothold.

*Victim Count & Losses*
Data analysis reveals Pink Drainer's successful $3 million asset theft, impacting around 1,932 victims across various chains. The breakdown of the stolen funds reveals $2.43 million on the Mainnet and $350,000 on Arbitrum. These figures highlight the severity of Pink Drainer's threat and emphasize the need for enhanced security measures within the cryptocurrency community.
To learn more about the statistics surrounding Pink Drainer's activities, please visit the ScamSniffer platform.
Pink Drainer was first brought to light by Taylor Monahan through ScamSniffer's on-chain monitor bot. The victim, `0xf529127107c91bbf6c141304718491a437fb2f5f`, experienced losses of around $320,000 in NFTs, including Otherside Koda (x8), BoredApeYachtClub (x1), MutantApeYachtClub (x1), and Otherdeed (x11). The assets were subsequently transferred to an address identified as `pink-drainer.eth` a few hours later. This incident served as the catalyst for naming the threat actor `Pink Drainer`.


The activities of Pink Drainer, a hacker group specializing in impersonation phishing attacks, have resulted in substantial financial losses within the cryptocurrency community. By compromising Discord and Twitter accounts, the threat actors have successfully stolen approximately $3 million in assets, affecting almost 2,000 victims. Their utilization of social engineering techniques, particularly through the impersonation of journalists, underscores the need for enhanced awareness and vigilance among users. As Pink Drainer continues to operate, high-profile digital asset holders must exercise caution and verify the authenticity of communications from media outlets and official sources.
Investors must be skeptical of promotions by seemingly legitimate accounts, cross-verifying information through official channels before acting.
Estée Lauder reveals a data breach caused by an Oracle E-Business Suite flaw, exposing sensitive data and prompting security response measures.