01
Drainer infrastructure
Contract addresses reused across campaigns.
Phishing
Modern crypto phishing uses fake mint pages, permit signatures, and session hijacks—not just password forms.
Victims sign malicious transactions or reveal exchange credentials through cloned interfaces.
Losses may occur in seconds via automated sweeper bots.
Email, X DM, or sponsored ad promising airdrops.
Malicious dApp requests token approvals or seed entry.
Automated transfer to operator wallets.
Drained assets are swapped and bridged rapidly.
01
Contract addresses reused across campaigns.
02
Follow outbound from victim wallet.
Never provide a seed phrase, private key, or authentication code to anyone claiming they can recover funds—including parties who contact you unsolicited. Legitimate investigators do not need wallet secrets to begin a case review.
Often yes on public marketplaces until laundered.