Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

Google Contacts borrows a handy iPhone trick to make sharing your number easier

17 July 2026 at 16:37
Google is rolling out a small but useful update to the Contacts app on Android that makes it much easier to find and share your own contact details. Instead of digging through settings or creating a separate contact for yourself, you’ll now see a dedicated ‘Your Info’ card at the very top of your contacts […]

Rheinmetall wins nearly $1.1 billion UK training deal

13 July 2026 at 04:40
German defense giant Rheinmetall has secured a contract worth just under €1 billion (roughly $1.1 billion) for its role in overhauling how the British Army trains its soldiers, part of a broader £2 billion (approximately $2.7 billion) government program that will replace traditional live exercises with a blended system of virtual, synthetic and data-driven training […]

Cryptocurrency Drainers: How Hackers Steal Cryptocurrency

7 July 2026 at 10:25

Welcome back, aspiring investigators! 

Let’s talk about something that has become one of the biggest problems in the crypto world. It’s drainers. If you haven’t heard the word before, don’t worry, you’re about to become very familiar with it. Drainers are a type of phishing attack, and they have swept through the cryptocurrency world at a truly striking pace. In fact, they are now growing so fast that they have already overtaken ransomware, both in how widespread they are and in the sheer amount of money they steal. To understand exactly how this works, we dug into the mechanics of drainers as well as the whole shadowy little market that has grown up around them. That’s what we are going to explore together today.

The basic idea behind any phishing campaign is to catch you making a mistake. Hackers want you to hand over information or access that should never leave your hands. In the specific case of drainers, the goal is a little different from classic phishing. The hacker wants to trick you into granting a smart contract permission to interact with your funds. Once you give that permission, the damage is already done. Drainers mostly go after blockchains that support smart contracts. That means they target users on Ethereum and Ethereum-like networks, such as Base, Polygon, and Optimism. But don’t think Ethereum is the only battlefield. Drainers built for Solana exist too, and a drainer aimed at Bitcoin has already made an appearance.

Imagine you want to connect your MetaMask wallet to some project’s website because you’re hoping to grab a little free crypto. Maybe you want to buy a brand-new token while it’s still cheap, before the price shoots up. You click Connect, you type in your password, and you sign a transaction that approves access to your wallet. And that, right there, is exactly the moment a drainer catches you. Instead of a legitimate contract that would let you receive tokens, the hacker gets you to sign a malicious smart contract. In doing so, you unknowingly grant permission for your funds to be transferred out. In effect, you agree, with your own hand, to give away all your money.

scam ads
A selection of AI-enabled scam trends. Source: Elliptic

So how does a hacker actually pull this off? It works best with something called an airdrop, which is simply a giveaway of new tokens. Airdrops attract a swarm of people who are hoping to get a little bit of crypto that might grow tens of times in value down the road. These giveaways do genuinely happen sometimes, as a real way to promote a new token. So people have learned to trust them. In that exact moment, the user is driven by something we call FOMO, the fear of missing out on a gain.

In their rush to grab the airdrop, a person often doesn’t stop to check who actually created the page they are interacting with, or what the smart contract they are approving actually does under the hood. The website itself might be a perfect copy of the real one, built by the hacker down to the smallest detail, while the smart contract underneath does the opposite of what it promises. Instead of giving you money, it takes it.

Drainers Are Gaining Momentum

In 2024, drainers overtook ordinary ransomware, both in how far they spread and in how much money they brought in. Now, don’t get it wrong, ransomware is still very much the scourge of large businesses. But scammers, being the opportunists they are, have rushed into this new and still relatively uncrowded niche. The very first drainers spread quietly, as scripts traded on darknet marketplaces. Back in 2022 there were 55 unique forums where you could find drainers being sold or discussed. By 2024, that number had jumped to 129 such places, more than double in just two years.

crypto scam is growing

And keep in mind, that count only covers a place as niche and honestly as sparse as the dark web. Most of the real action these days happens on Telegram and Discord.

The biggest drainers active in 2024 had names like Angel, Inferno, Ping, Ace, Cerberus, Nova, Medusa, MS, CryptoGrab, and Venom. Of that whole list, mainly Angel and Ace are still active today, but a new player has stepped onto the stage, one called Vanilla. It hasn’t been studied very closely yet, because it runs on a private model that is difficult for the average scammer to even get access to.

According to Scam Sniffer, a company that closely analyzes different types of crypto fraud, total losses from drainers in 2024 added up to $494.000.000.

crypto report 2024

That figure only counts the large-scale hacks that could actually be tallied and confirmed. Since drainers mostly target ordinary, everyday users, small thefts of just a few thousand dollars here and there don’t even make it into that statistic. So the real number is almost certainly much higher. 

Among the large-scale cases recorded in 2024, there were more than three hundred thirty thousand victims. The single biggest theft that year came to $55.000.000. All together, there were roughly thirty major fraudulent campaigns, which is one and a half times more than the year before, in 2023. In the first quarter of 2024 alone, drainers showed almost sixfold growth. Compare that to ransomware, which only doubled over that same stretch of time.

crypto growth rate vs ransomware

So what do all these numbers really mean? Well, because the barrier to entry into this line of work is so remarkably low, it has started attracting scammers who used to work in more old-fashioned territory, like email phishing, luring victims to fake bank login pages and other traditional scam types. A couple of months of this kind of work could buy an apartment, a car, and regular vacations somewhere warm like Thailand. Take one risk, and you can just walk away, or so the thinking goes. But of course, once someone gets a real taste of easy money like that, nobody actually walks away after two months. The business pulls them back in.

Think about the contrast here. A ransomware group has to negotiate with a company, arrange for payment, and handle the whole business of decryption afterward. That’s a lot of hassle and a lot of steps where things can go wrong. A drainer, on the other hand, just steals the money immediately. No negotiation needed. 

Like plenty of other kinds of scams out there, drainers are distributed under what’s called a SaaS model, short for Software-as-a-Service. In this criminal corner of the internet, they’re called DaaS, meaning Drainer-as-a-Service.

There’s also a very characteristic division of labor inside these operations. You’ve got developers, who build the actual malware. You’ve got workers, the rank-and-file operatives out doing the scamming day to day. And alongside them you’ve got recruiters, traffic-generation specialists, and providers of various supporting services that keep the whole machine running. The main job, naturally, falls to the developers. They are the ones who create the malicious software and work to make it more convenient to use, easier to deploy, and easier to scale up. 

How the “Company” Is Built

So what does a hacker actually need in order to pull off a phishing campaign like this?

First, they need domains for their future sites, and these domains are usually spelled just similarly enough to the name of the real project they’re impersonating, so a distracted eye won’t catch the difference. Then they need hosting, which is simply a place to put the site once it’s built. Naturally, they also need a landing page, one designed to closely resemble the legitimate project’s real page. Underneath that landing page sits the drainer code itself, which is typically JavaScript code hosted directly on the site. On top of all that, they’ll usually build a control panel that shows them how many users have been lured in and tracks how those users are behaving on the page. And finally, hackers take their own security seriously too, relying on VPNs, proxies, and fake sockpuppet accounts to cover their tracks.

scam websites
Source: Elliptic

Professional hackers usually go a step further and set up a full command-and-control server, which lets them manage the drainer’s behavior remotely and adjust it on the fly.

Once all of that infrastructure is in place, all that’s left is bringing in people, actual victims to walk through the trap. That job falls to traffic arbitrage specialists, sometimes called traffic drivers. Their whole task is to funnel users toward the phishing page. They accomplish this in all sorts of ways, everything from buying Google ads to jumping directly into comment sections and posts to engage with real users. Some scammers even go so far as to clone the official support channels of legitimate projects, so a victim reaching out for help ends up talking to the scammer instead.

Put it all together, and what you get is a genuine sales funnel, a designed path that walks victims toward the trap, just like any legitimate marketing funnel would walk a customer toward a purchase.

How the Money Is Split

Here’s how the profits typically get divided up. Operators, the people running the overall scheme, take home twenty to thirty percent of whatever gets stolen. The rest goes to the workers, the people directly out there scamming victims day to day. A worker’s exact cut depends on their skill level. Beginners give up thirty percent of their take to the operators, while the most experienced workers only give up ten to fifteen percent.

And how is a worker’s skill level judged? Simply by how much they have already managed to steal over time. If you’ve stolen up to $10.000 total, you’re considered a beginner. Between $25.000 and $30.000 puts you at mid-level. And starting from $100.000, usually climbing toward a million or more, you’re considered a true professional in this dark little trade.

Driving Traffic

Knowledge in this underground world gets passed around among workers through tutorials. A tutorial itself becomes an item that gets bought, sold, and traded, almost like a piece of merchandise. Entire communities have formed just to gain access to these tutorials, treating them like valuable trade secrets. The writing style of these tutorials makes it fairly clear that AI tools were used to help put them together.

Broadly speaking, the same traffic-driving scheme used in ordinary, everyday phishing applies here too, just adapted for the world of crypto. A worker is essentially doing the same job as any online advertising specialist would. Their goal is simply to increase the number of people clicking through to the phishing page. That means hunting for users who are genuinely interested in Web3 and DeFi projects, people who hold crypto wallets and who are drawn to airdrops, token swaps, and exchanges.

scammers sending text messages
Sample texts (lifted verbatim from actual cases) from pig butchering scammers. Source: Elliptic

This whole process involves demographic analysis and geolocation analysis, essentially the same ordinary targeting techniques that any advertiser in any industry would recognize. Workers also handle what they call “site design,” which really just means cloning the pages of existing, trusted projects. They’ll even use classic marketing techniques like A/B testing to see which fake page tricks more people.

Now let’s walk through a few high-profile examples of drainer thefts.

The Attack on Arkham Intelligence

Arkham is a company that provides on-chain analytics, and it’s a genuinely popular tool for tracking transactions. Traders rely on it, for instance, to check an asset’s price and see exactly where it’s trading across different platforms.

Back in 2023, Arkham’s owners launched their own token along with an airdrop of coins to celebrate. But hackers saw an opportunity and created numerous fake profiles on X specifically to redirect users toward phishing pages containing a drainer. Remarkably, these bot accounts proved quite resilient and managed to avoid being banned for a long stretch of time. They mimicked Arkham’s real activity closely and spread malicious links far and wide.

A huge number of these fake sites were created during the campaign, and each one typically had a lifespan of just weeks, or a couple of months at most. Angel’s software allowed a hacker to copy landing pages quickly and place them on brand-new domains almost instantly. The whole process has been simplified so much that a worker only needs to type a few commands into a conversation with a Telegram bot in order to deploy an entirely new phishing site.

The Attack on the SEC

An even bigger impact can be achieved by a hacker hijacking the real, verified account of some authoritative company, or even a government organization.

SEC

And that’s what happened with the United States Securities and Exchange Commission, or the SEC. On January 9, 2024, its account on X was compromised through a technique called SIM swapping, which basically means reissuing a SIM card tied to the phone number linked to that account. Officials, unfortunately forgetting about basic security hygiene, hadn’t even enabled multi-factor authentication on the account.

Lately, the SIM-swapping community and the drainer community have grown noticeably closer, almost like two neighboring criminal industries starting to collaborate. Swappers now routinely supply drainers with freshly hijacked accounts to use.

The hackers behind this attack posted that the SEC had officially approved investing in Bitcoin without needing to buy crypto directly on an exchange like Binance or Coinbase. This caused an immediate stir, because investors had been waiting a long time for exactly this kind of decision from the SEC, and many expected it to be announced any day. Following the fake post, the hackers urged people to claim an “official SEC airdrop” on a special site that contained a drainer.

That single fake post even caused a real spike in Bitcoin’s price. It rose by a full thousand dollars, just from a fake tweet.

Scamming the Scammers

Scammers, as it turns out, wouldn’t really be scammers if they didn’t also scam each other. At one point, the developer behind the Pink Drainer felt like he was getting close to being unmasked, so he decided to get out of the game entirely and cash out his loot. Here’s the catch, though. You can’t just sell crypto obtained through a scam outright. To actually withdraw the funds, a scammer first has to launder the money, or else an exchange might get suspicious and freeze it before it ever reaches a real bank account.

To avoid enabling things like terrorism financing, or simply to stay within the law, exchanges use a system of scoring and refuse to accept “dirty” crypto. This scoring system is called an AML score, short for anti-money-laundering. There are plenty of laundering methods out there, and while trying one of them, Pink Drainer’s own developer ended up getting scammed himself.  He fell for one of the simplest kinds of fraud imaginable called address poisoning. 

Here’s how it works. Hackers generate crypto addresses that closely resemble a victim’s real address, and then they send that victim a tiny amount of crypto, just enough so that the lookalike address shows up in the victim’s transaction history.

generating custom ETH wallet addess
An example of a custom ETH wallet address generator used for address poisoning. Source: Elliptic

From the user’s side, here’s what it looks like in practice. You send, say, one hundred dollars to some other wallet, maybe an exchange you use regularly. Then, five or ten minutes later, you receive a few tiny transfers that appear to come from that very same wallet. But in reality, they only come from a similar-looking address, one that might share, say, an identical start and end to the real address, while the middle is different.

The hacker is betting that on your next transfer, you’ll simply scroll through your history, pick the most recent address you see, and send your money not back to yourself, but straight into the hacker’s pocket. And that’s exactly how Pink Drainer got caught in his own kind of trap. He picked what looked like the last transaction in his history and sent ten ETH, worth about $15.000 at the time, straight to some unknown “colleague” who was never really his colleague at all.

Conclusion

Because draining is so easy and profitable, this type of scam is not going away anytime soon. If anything, the ways malicious payloads get delivered will only keep getting more sophisticated from here. Drainers are increasingly setting their sights on younger blockchains too. On Ethereum-based networks, it’s steadily getting harder for hackers to operate, since protective measures keep appearing that they have to find new ways to bypass. On Solana, though, no such protections really exist yet, which makes it a much softer target. New kinds of drainers will keep emerging as well. Some scammers have already started building actual apps for Google Play and the App Store, moving beyond simple websites and into places millions of people trust by default. So stay alert out there, and think twice before you click any button, especially one promising you free money. If it feels too good to be true, in crypto more than almost anywhere else, it usually is.

If you’re interested in cryptocurrency forensics, we have a dedicated training called Bitcoin and Cryptocurrency Forensics. You will get to dive into blockchain analysis and cryptocurrency investigations, learning the skills needed to become a cryptocurrency forensic analyst. You can buy the training separately or attend it live on September 15-17 at 3 PM UTC.

The post Cryptocurrency Drainers: How Hackers Steal Cryptocurrency first appeared on Hackers Arise.

The missing 500 million: Cosmic bombardment melted Earth's first crust

5 July 2026 at 06:55

Earth is the only planet we know of with buoyant, silica-rich continents. But, despite decades of research, geologists still don't agree on how they formed. "The continents started appearing around about four billion years ago—that's the oldest continental rock we know about,” said Tim Johnson, a geologist at Curtin University in Perth, Australia. “The Earth is four and a half billion years old, so why they started appearing then is unknown, as is the mechanism to make that continental crust."

Johnson and his colleagues are now arguing that the formation of continents on Earth was caused largely by an intense, sustained barrage of asteroid impacts that kept the early crust hot and thin enough to make buoyant continents possible. In short, the lands we live on are here because of ancient bombardment from space.

Plates and plumes

The problem with studying the formation of continents is that the geological evidence of this process is almost gone. The oldest known continental-type rocks crystallized around 4.03 billion years ago, right at the end of the Hadean eon (the earliest era in Earth’s history, spanning the first 500 million years of its existence). Rare basaltic rocks date back about 4.2 billion years, and a handful of the oldest zircon crystals push the record back to 4.4 billion years. Beyond that, there's hardly anything else. So, scientists looking into the origin of continents had to rely largely on educated guesses. “There are huge debates about what was going on in the early Earth, because the data is so scarce,” Johnson said.

Read full article

Comments

© NASA's Goddard Space Flight Center Conceptual Image Lab

When the Quote Becomes Calldata. The Fork Tests Whether It Holds.

30 June 2026 at 10:22
A note on turning a Uniswap quote into API-native calldata, then replaying that transaction against pinned mainnet state.

Part I stopped at the quote layer: route legs, output amounts, API-reported priceImpact, and blockNumber. It recorded what the router proposed. At larger sizes, that proposal became a spread of pools and intermediate hops, not a single price.

A desk sizing an exit acts on that quote; so does a risk pipeline that reads priceImpactas a risk number. On a centralized venue, a mistake there usually stays inside an operator’s scope: an order cancelled, a fill refunded, a replacement issued. Once the quote becomes calldata, there is no venue operator between the user and pool execution, and the failure boundary moves from router proposal to encoded constraints. The quote alone cannot tell whether the next problem is invalid transaction construction, wallet authorization, gas estimation, state drift, ordering, or the final fill.

Part I sliced the quote layer; this post slices one execution layer: build the transaction from the quote, replay it against pinned mainnet state, and check whether the proposal survives, and where the route’s complexity ends up. A valid quote does not mean valid calldata; a successful same-state replay does not mean a mined receipt.

Readable quote, executable calldata

A /quote response can show expected output, minimumAmount, route structure, and blockNumber, but none of those fields execute by themselves. The trade becomes executable only when /swap returns a TransactionRequest: to, data, value, gasLimit, and encoded router instructions.

The chain enforces only what the transaction encodes-most importantly the minimum output condition. Expected output and priceImpact are display fields, not the bytes the Universal Router will run.

Quote evidence, swap calldata, and controlled fork replay with live mainnet ordering and MEV outside the measurement boundary
Fig. 1. Quote evidence vs transaction evidence. The quote records what the router proposed; `/swap` materializes calldata; fork replay tests that calldata against pinned state. Ordering, MEV, fee payment, and inclusion sit outside this article.

The replay is a same-state execution check for the /swap artifact, not a live fill. Fork setup and measured fields are in the run section below.

Uniswap’s Trading API exposes this directly by separating from :

POST /quote
→ POST /swap with the returned quote
→ save TransactionRequest
→ fork at quote.blockNumber
→ seed wallet balance and approvals
→ send API-native calldata
→ measure output-token delta, minimumAmount, and gas

Shell references: quote_to_swap.shand replay_swap.sh.

The fork replay run

Run ID: 20260619Tpart2v1

I collected nine cells: USDC → WETH, AAVE, and MKR at $100, $10k, and $1M. Routing was Uniswap classic ( CLASSIC); protocols V2/V3/V4 via BEST_PRICE; UniswapX excluded.

For each cell I POSTed /quote, then POSTed /swap with the returned quote object and archived both responses. /swap used allowance-based calldata from the Trading API-not SDK reconstruction from route JSON. API simulateTransaction succeeded on all nine cells.

Each cell was replayed on a fresh Anvil mainnet fork at that cell’s quote.blockNumber (blocks 25,350,126-25,350,128), with archive RPC state. I seeded a fixed test wallet with ETH for gas, USDC via anvil_setStorageAt, and USDC → Permit2 → Universal Router approvals. Replay sent exact API-native /swap calldata to the router at 0x66a989...8Af.

A signed-permit collection ( 20260619Tpart2v0) failed fork replay when permit sigDeadline preceded the pinned quote-block timestamp. That comparison run is archived; the primary evidence is the allowance path above.

Measured per row: fork_status, fork_output_amount, fork_vs_quote_bps, fork_meets_minimum, fork_gas_used, and api_simulation_status.

What the grid shows

All nine cells replayed at pinned state, cleared minimumAmount, and matched the quote at 0 bps: the expected baseline for same block, same pool state, same calldata.

Nine-cell fork replay panel for WETH, AAVE, and MKR at 100, 10k, and 1M USDC input sizes
Fig. 2. Fork replay panel: WETH / AAVE / MKR × $100 / $10k / $1M. Each cell reports fork status, fork vs quote (bps), `minimumAmount` pass/fail, and gas used. Run `20260619Tpart2v1`; same-state replay matched the quote at 0 bps.

WETH $100 routed through a single V3 hop. Fork gas was 140,975-the simple control.

MKR $1M showed quote-layer output deterioration in Part I. Its seven-hop transaction still replayed at 0 bps and cleared the minimum.

AAVE $1M: fragmented route, same-state pass

Part I flagged AAVE for route fragmentation and summary-field ambiguity. At $1M the quote carried 13 pool legs across five parallel paths (V2/V3/V4 mix). /swap returned 14,366 bytes of calldata. Fork gas was 2,386,700-roughly 17× the WETH $100 control.

AAVE one-million-dollar quote route dependency graph with five parallel paths and thirteen pool legs
Fig. 3. USDC → AAVE at $1M: five parallel paths, 13 pool legs, V2/V3/V4 mix. Side panel: quote block 25,350,127, quoted output, `minimumAmount`, fork status. The route looked fragmented at quote time; it did not become a deterministic same-state failure.

Pilot panel: what route stress becomes

The nine-cell replay is a controlled check, but it is too small to say much about route stress more generally. I therefore ran a pilot panel over 28 snapshot labels, 10 assets, and five input sizes: 1,400 intended cells. This was a pipeline pilot, not a historical backtest.

The pilot produced 977 successful /quote + /swap rows. The strongest pattern was payload size: hop count versus calldata bytes had a Pearson correlation of 0.935; path count versus calldata bytes was 0.917.

Pilot panel scatter plot showing route hop count against calldata bytes, with marker size indicating USDC input size
Fig. 4. Pilot panel: 1,400 intended cells; 977 successful `/quote` + `/swap` rows plotted. Hop count versus calldata bytes (Pearson r = 0.935). Marker size is USDC input size; descriptive, not causal.

From that panel I selected 118 stress rows for fork replay. Ninety replayed successfully at pinned state. The remaining 28-all high-complexity SHIB rows-stopped at eth_estimateGas.

Three of those I direct-sent on fresh pinned forks with a 12M gas cap; all three executed at roughly 7M gas and cleared minimumAmount. The timeout was an estimator artifact, not an EVM failure-but that check covers only 3 rows. The remaining 25 still need the same follow-up.

What a fork replay result actually means

The first all-green table raised a scope question: was this evidence, or only a same-state sanity check? Treating replay as one test stopped working once the non-receipts came from different layers.

Where the evidence stopped: CRV at configuration, COMP/LDO at quote availability, signed-permit at wallet authorization, SHIB at gas estimation then direct-send success, AAVE at same-state EVM fork execution
Fig. 5. Where the evidence stopped across 118 selected stress-row replays. CRV stopped at configuration, COMP/LDO at quote availability, the signed-permit path at wallet authorization, SHIB at gas estimation before direct-send replay, and AAVE at same-state EVM fork execution. A single pass/fail column would erase those distinctions.

A non-receipt is not one failure class. Configuration, authorization, estimation, and EVM execution fail at different boundaries.

Closing

Part I stopped at the quote. Here, same-state replay held, route complexity showed up in calldata size, and three SHIB estimator timeouts became roughly 7M-gas executions on bounded forks.

The harder part is keeping the labels straight: estimator timeout, authorization failure, configuration error, and EVM execution are different boundaries, even when all of them produce no mined receipt.

The next falsifiable check is narrow: direct-send the remaining 25 SHIB rows with bounded gas on pinned forks. Inclusion, ordering, MEV, state drift, and realized fill still need receipt-level evidence.

Appendix: sources

This post was originally published on my personal blog: https://egpivo.github.io/2026/06/30/when-the-quote-becomes-a-transaction.html


When the Quote Becomes Calldata. The Fork Tests Whether It Holds. was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

❌
❌