Amid a rash of crypto scams that have pilfered millions of dollars’ worth of Ethereum NFTs from unsuspecting users’ wallets, the unknown pseudonymous entity referred to as “Monkey Drainer” has claimed a fresh cache of valuable CryptoPunks and Otherside NFTs.
Self-described “on-chain sleuth” ZachXBT—a pseudonymous Twitter user with a history of publishing data on crypto scams and controversial figures—shared Thursday evening that Monkey Drainer had stolen 520 ETH worth of NFTs from those two valuable Yuga Labs collections, which works out to roughly $800,000.
Some of the NFTs were funneled between multiple wallets and ultimately sold. Based on public blockchain data visible through Etherscan, the attacker then funneled 400 ETH through Tornado Cash, a crypto privacy tool for Ethereum that was sanctioned by the U.S. government in August and cannot legally be used by citizens.
Monkey Drainer just stole another 7 Crypto Punks and 20 Otherside NFTs worth $800k (520 ETH)
Last week, ZachXBT reported that Monkey Drainer took roughly 700 ETH worth of assets from unsuspecting users who signed malicious transactions, thinking they were opting in to free NFT airdrops. However, they were really scams promoted through impersonated Twitter accounts. When victims clicked the links and connected their wallets, their assets disappeared.
ZachXBT previously estimated that Monkey Drainer had stolen well over $3.5 million worth of crypto and NFTs. Monkey Drainer was also used for an exploit perpetrated through the hijacked Twitter account of Gabriel Leydon, CEO of Web3 gaming startup Limit Break, on Wednesday.
Social media scams are thriving in the crypto space, and NFT collectors are losing their assets to attacks perpetrated through hijacked accounts. The latest example happened last night, with dozens of NFTs and about $30,000 worth of cryptocurrency stolen through a scam shared through the account of a well-known Web3 game developer.
On Wednesday, the Twitter account of Gabriel Leydon—co-founder and CEO of Limit Break, the gaming startup behind anime-inspired Ethereum NFT project, DigiDaigaku—was...
Adding this week’s attacks to the tally brings the total estimated damage to over $4.3 million. But who, or what, is Monkey Drainer? While the drainer’s identity remains unknown, ZachXBT told Decrypt via Twitter DM that Monkey Drainer “is likely one person.”
“Monkey Drainer is likely one person with a type of [as-a-service] situation,” he said. “Many people are customers however.”
In other words, other parties may be using Monkey Drainer’s playbook to perpetrate an even wider array of scams. To further complicate the ambiguity surrounding Monkey Drainer’s identity, an influx of Twitter bots also attacked ZachXBT’s thread on the latest NFT thefts with the phrase “MONKEY DRAINER BEST – Team Monkey.”
Social media hacks are on the rise in the NFT community, and it’s rare lately to see a day or two go by without some significant project or creator’s account being compromised.
For collectors, the consequences can be significant: Users who engage with the scams shared by hacked accounts have collectively lost millions of dollars in NFT collectibles and other tokens, all because they connected their wallets to what they believed was a legitimate NFT mint or token claim.
What’s the recourse in the...
The bizarre spam comments imply that Monkey Drainer has a “team” of some kind, though it’s unclear whether Monkey Drainer is actually one person, a group of affiliates, or a group of pseudonymous strangers using Monkey Drainer’s “toolkit” for ill-gotten gains.
Web3 security firm Wallet Guard similarly believes Monkey Drainer is a type of malware-as-service, meaning the creator of the “drainer” smart contract—that is, the code that powers NFTs and decentralized applications—is selling their phishing toolkit to others.
“Monkey sells his drainer for 30% cut of an attack,” ZachXBT tweeted. “So other scammers are coming to him with these accounts.”
Monkey sells his drainer for 30% cut of an attack. So other scammers are coming to him with these accounts.
But David Schwed, COO of Web3 security firm Halborn, doesn’t think these attacks are particularly complex—even though the drainer tool is still garnering plenty of victims.
“The attacks are somewhat unsophisticated, and with some proper cyber hygiene, NFT holders can easily protect themselves,” Schwed told Decrypt via email. “For the scam to work, the NFT holders have to grant the malicious actor access to effectuate a transaction.”
The NFT space has seen a surge in these scams over the course of 2022. Many are shared through hacked social media accounts, which point to what collectors believe is a legitimate NFT mint or airdropairdrop claim. Instead, they unwittingly give full access to their wallet holdings to the attacker, and typically have their NFTs and crypto swiped before they realize it.
Monkey Drainer may be running amok across the Ethereum network for now, but at least one ethical hacker is trying to slow its reign of chaos.
Crypto browser extension PocketUniverse reported that a Discord user named “blockdev” has been able to successfully block some draining transactions that Monkey Drainer initiated by attacking the drainer’s API keys. Still, the damages from Monkey Drainer’s exploits are piling up.
He attacked their API keys! So one of Monkey's attack moves is
1) Trick you into signing a gasless OS offer that gives him your NFTs for free
2) Broadcast that offer to the ETH blockchain and 'activates' the offer to steal your assets
ZachXBT told Decrypt he believes Monkey Drainer first started around August this year, and that whoever created the exploit may face competition from other scammers looking to get in on the same kind of racket.
“I imagine in the long run they’ll need to continuously update Monkey Drainer to stay competitive otherwise new methods will gain market share,” Zach responded, when asked if the drainer could be stopped.
Daily Debrief Newsletter
Start every day with the top news stories right now, plus original features, a podcast, videos and more.
NFT Revolution
NFTs are provably unique crypto tokens that are quickly becoming increasingly popular among digital artists, gaming companies, and investors. Track the NFT revolution here.
Two years after they were inscribed on the Bitcoin blockchain, the highly anticipated Taproot Wizards Ordinals collection will go on sale on March 25, the project's creators announced Tuesday.
Taproot Wizards will consist of 2,121 Wizard NFTs, modeled after the iconic Bitcoin Wizard meme that surfaced on Reddit in 2013.
The collection will be sold in two distinct phases, the first of which will offer Wizard NFTs to those on an allowlist for 0.2 BTC, or $16,340 at today’s prices. An eligibility c...
Tech giant Sony is commemorating 25 years since the launch of Aibo, its companion robot dog, with an officially licensed soulbound NFT collection called "Entertainment Robot Aibo” on the Soneium blockchain.
The collection, which cannot be traded or transferred thanks to its soulbound nature, can be minted for free on OpenSea’s NFT marketplace, with users required only to pay a small gas fee to initiate the transaction.
In its official Discord community, Soneium’s team wrote that Aibo’s return a...
Nyan Heroes, the cat-themed hero shooter game built on Solana, announced its largest token airdrop to date on Thursday, with 6.7 million NYAN tokens (nearly $200,000) to be distributed during its upcoming Playtest 4 event.
The airdrop, running from March 26 to April 13, represents a 34% increase from the previous distribution, and allocates 250,000 tokens to the top-ranked player. The reward structure, designed by former EVE Online economy director Asimakis Reppas, features three tiers: Challeng...