Bitcoin wallet keys emerge from radioactive decay
Belgian federal police have targeted crypto wallets linked to offshore piracy platforms in a cross-border enforcement action, according to an official government release.
The action highlights how digital asset wallets continue to appear in law-enforcement investigations beyond the usual exchange, fraud, and darknet narratives. In this case, the focus is limited to wallets allegedly connected to designated offshore piracy targets.
That scope is important.
This should not be treated as a general crackdown on crypto wallets or ordinary self-custody. It is a targeted enforcement action tied to a specific criminal investigation.
For more details, visit the official News platform.
Digital assets are often used because they move quickly across borders.
That same feature makes them attractive in criminal investigations. Authorities can track some flows on-chain, request help from exchanges, coordinate with foreign agencies, and target wallets linked to specific alleged activity.
Wallets are not automatically criminal.
But wallets connected to illicit platforms, fraud, piracy operations, ransomware, or sanctions targets can become central evidence in enforcement cases.
Belgium’s action fits that narrower category.
Online enforcement is rarely confined to one country.
Piracy platforms, payment flows, hosting providers, wallets, domain registrars, and users may all sit in different jurisdictions. That makes international cooperation important, especially when authorities are trying to disrupt financial flows rather than only seize servers or arrest operators.
Crypto can make that process easier in some ways and harder in others.
Blockchain trails can help investigators follow funds. But offshore platforms, mixers, non-custodial wallets, and foreign exchanges can complicate recovery or seizure.
That is why official cooperation orders matter.
The key point for readers is scope.
A targeted law-enforcement action against wallets linked to alleged criminal platforms is not the same as a ban on self-custody. It does not mean ordinary users are being targeted for holding digital assets.
Crypto enforcement stories often get flattened into broad narratives.
That can mislead readers.
The correct framing is that authorities are targeting specific wallets connected to a defined investigation, not wallets as a category.
Crypto-related enforcement is no longer limited to token offerings or exchange registration.
Authorities now look at money laundering, sanctions, ransomware, fraud, market manipulation, illicit streaming, piracy, tax evasion, and terrorist financing. Digital asset wallets may appear in any of those cases if investigators believe they were used to receive, store, or move proceeds.
That broader enforcement environment matters for the industry.
It increases pressure on exchanges, analytics firms, wallet providers, and compliance teams to monitor high-risk flows.
Belgium’s action shows that crypto wallets remain part of global enforcement work.
For legitimate users, the case is not a reason to panic. For platforms and service providers, it is another reminder that blockchain payments can become traceable evidence when tied to alleged criminal activity.
The crypto industry often talks about financial freedom.
Regulators and police are equally focused on financial accountability.
This case sits where those two themes meet.
This article draws on the Belgian government release on the federal police crypto piracy enforcement action.
This article was written by the News Desk and edited by Samuel Rae.
This report is based on information released by News. at News

Timelock Account Recovery Gives Ethereum Smart Accounts A Safer Backup Route is a useful reminder that crypto coverage is not only about token prices. Sometimes the more important story is the infrastructure, regulation, security, or product layer sitting underneath the market noise.
The immediate point is straightforward: a new Ethereum Magicians proposal outlines timelock-based smart account recovery. That gives readers something concrete to work with, rather than another vague sentiment update.
The timing matters because Ethereum is already part of a wider conversation across the market. Traders want to know whether the development changes liquidity or risk. Builders want to know whether it changes what can be deployed. Compliance teams want to know whether it changes how platforms operate.
In that sense, the story is bigger than one headline. It sits inside the ongoing shift from speculative crypto cycles toward more practical questions: who can use these systems, how safe are they, and whether the underlying incentives actually work.
The best way to read it is with discipline. It is not a guarantee of immediate upside, and it should not be treated as one. But it does add a fresh data point to the way the market is thinking about Ethereum.
For Ethereum, the important part is the specific mechanism. If this is a security issue, the risk sits in dependencies and user protection. If it is a listing or product launch, the question is access and liquidity. If it is a governance or research proposal, the question is whether the idea can survive implementation.
That is where this update becomes useful. It is not just a label attached to a trend. It gives readers a way to understand what might actually change if the development gains traction.
Crypto has a habit of turning every announcement into a broad market claim. This one deserves a narrower read. The value is in seeing how it affects the users, developers, institutions, or traders closest to the issue.
There is also a caution attached. Source material can confirm that a development exists, but it cannot prove that adoption will follow. A proposal still needs support. A product still needs users. A chart still needs confirmation. A compliance tool still needs integration.
That is why the responsible reading is not to oversell the story. The stronger takeaway is that this adds to a pattern. The crypto market is steadily becoming more professional, more technical, and more sensitive to real operational details.
Readers should also watch for follow-up signals. That could mean developer feedback, exchange support, regulatory response, wallet adoption, liquidity data, or simply whether market participants continue reacting after the first headline fades.
The next stage will decide whether this remains a narrow update or becomes part of a larger market theme. In crypto, that difference matters. Plenty of stories look important for a few hours and then disappear. The ones that last usually show up again through usage, liquidity, enforcement, governance, or developer adoption.
For now, this gives the market another piece of information to weigh. It is specific enough to be useful, but still early enough that readers should keep the caveats in view.
That makes it worth covering without pretending it settles anything. The story is a signal, not a final verdict.
This report is based on information from ethereum-magicians.org.
This article was written by the News Desk and edited by Samuel Rae.

Solana’s growth story is often told through speed, fees, and developer momentum. Address growth adds another layer, but it needs to be read carefully. A higher wallet count can be encouraging, yet it does not automatically prove that a network has deeper economic activity.
That is the right way to look at the current Solana signal. The market wants to know whether user growth is sticky, whether dApps are retaining activity, and whether validators and applications are seeing enough demand to make the network’s momentum durable.
For more details, visit the official GitHub platform.
New wallets can reflect real adoption, speculative farming, airdrop behaviour, or short-term campaign activity. That is why address counts are useful, but not complete. They need to be paired with fees, transactions, DEX activity, app usage, and retention.
For Solana, the positive case is that low fees and fast execution make it easier for users to keep coming back. The challenge is proving that those users are not just passing through.
The strongest confirmation would come from broader app-level data: more users on DeFi protocols, stronger NFT or gaming activity, sustained stablecoin transfers, and fee demand that does not disappear after incentives fade.
Until then, address growth is a constructive sign, not a finished thesis. Solana has the attention. The question is how much of that attention becomes durable network value.
The practical takeaway is that Solana stories now have to be read through both market structure and product execution. A headline can create attention, but the more durable signal is whether the underlying source points to real activity, a real filing, a real integration, or a measurable change in how users and institutions behave.
That is why this development is worth separating from ordinary market noise. It gives readers a specific point to track over the next few sessions rather than a vague reason to be bullish or bearish. If follow-up data confirms the direction, the story can build. If not, it still gives the market a clearer snapshot of where attention is concentrating today.
The cleaner way to read this story is not to force it into a simple bullish or bearish box. For Solana readers, the useful part is the change in context. A new filing, integration, market signal, or regulatory step can alter how traders think about the next few sessions even when it does not instantly change price.
That is especially true after the last few volatile weeks, when crypto has been dealing with a mix of ETF flows, legal updates, exchange listings, protocol upgrades, and shifting liquidity. The market is no longer reacting to one dominant theme. It is weighing several smaller signals at once, and that makes source-backed developments more important than ordinary chatter.
For NewsBTC readers, the important question is what this changes from here. If follow-up data, filings, governance updates, or wallet movement confirm the direction, the story can develop into a larger market theme. If the next update is weak, delayed, or contradicted by new data, the market may quickly move on.
That is why the scope matters. This article is not treating the development as a guaranteed price trigger. It is treating it as a fresh signal inside a market that is trying to sort durable activity from short-term noise. The distinction is important because crypto narratives can move faster than the facts behind them.
The next thing to watch is whether this becomes part of a wider pattern. In some cases that means more institutional flows. In others it means stronger developer adoption, cleaner regulatory access, deeper exchange liquidity, or a clearer technical roadmap. Either way, the story is strongest if it is followed by measurable execution rather than another round of speculative headlines.
This article is based on Solana ecosystem materials and the source pack’s network-growth lead.
This article was written by the News Desk and edited by Samuel Rae.
This report is based on information from GitHub. at GitHub

Welcome back, aspiring investigators!
Let’s talk about something that has become one of the biggest problems in the crypto world. It’s drainers. If you haven’t heard the word before, don’t worry, you’re about to become very familiar with it. Drainers are a type of phishing attack, and they have swept through the cryptocurrency world at a truly striking pace. In fact, they are now growing so fast that they have already overtaken ransomware, both in how widespread they are and in the sheer amount of money they steal. To understand exactly how this works, we dug into the mechanics of drainers as well as the whole shadowy little market that has grown up around them. That’s what we are going to explore together today.
The basic idea behind any phishing campaign is to catch you making a mistake. Hackers want you to hand over information or access that should never leave your hands. In the specific case of drainers, the goal is a little different from classic phishing. The hacker wants to trick you into granting a smart contract permission to interact with your funds. Once you give that permission, the damage is already done. Drainers mostly go after blockchains that support smart contracts. That means they target users on Ethereum and Ethereum-like networks, such as Base, Polygon, and Optimism. But don’t think Ethereum is the only battlefield. Drainers built for Solana exist too, and a drainer aimed at Bitcoin has already made an appearance.
Imagine you want to connect your MetaMask wallet to some project’s website because you’re hoping to grab a little free crypto. Maybe you want to buy a brand-new token while it’s still cheap, before the price shoots up. You click Connect, you type in your password, and you sign a transaction that approves access to your wallet. And that, right there, is exactly the moment a drainer catches you. Instead of a legitimate contract that would let you receive tokens, the hacker gets you to sign a malicious smart contract. In doing so, you unknowingly grant permission for your funds to be transferred out. In effect, you agree, with your own hand, to give away all your money.

So how does a hacker actually pull this off? It works best with something called an airdrop, which is simply a giveaway of new tokens. Airdrops attract a swarm of people who are hoping to get a little bit of crypto that might grow tens of times in value down the road. These giveaways do genuinely happen sometimes, as a real way to promote a new token. So people have learned to trust them. In that exact moment, the user is driven by something we call FOMO, the fear of missing out on a gain.
In their rush to grab the airdrop, a person often doesn’t stop to check who actually created the page they are interacting with, or what the smart contract they are approving actually does under the hood. The website itself might be a perfect copy of the real one, built by the hacker down to the smallest detail, while the smart contract underneath does the opposite of what it promises. Instead of giving you money, it takes it.
In 2024, drainers overtook ordinary ransomware, both in how far they spread and in how much money they brought in. Now, don’t get it wrong, ransomware is still very much the scourge of large businesses. But scammers, being the opportunists they are, have rushed into this new and still relatively uncrowded niche. The very first drainers spread quietly, as scripts traded on darknet marketplaces. Back in 2022 there were 55 unique forums where you could find drainers being sold or discussed. By 2024, that number had jumped to 129 such places, more than double in just two years.

And keep in mind, that count only covers a place as niche and honestly as sparse as the dark web. Most of the real action these days happens on Telegram and Discord.
The biggest drainers active in 2024 had names like Angel, Inferno, Ping, Ace, Cerberus, Nova, Medusa, MS, CryptoGrab, and Venom. Of that whole list, mainly Angel and Ace are still active today, but a new player has stepped onto the stage, one called Vanilla. It hasn’t been studied very closely yet, because it runs on a private model that is difficult for the average scammer to even get access to.
According to Scam Sniffer, a company that closely analyzes different types of crypto fraud, total losses from drainers in 2024 added up to $494.000.000.

That figure only counts the large-scale hacks that could actually be tallied and confirmed. Since drainers mostly target ordinary, everyday users, small thefts of just a few thousand dollars here and there don’t even make it into that statistic. So the real number is almost certainly much higher.
Among the large-scale cases recorded in 2024, there were more than three hundred thirty thousand victims. The single biggest theft that year came to $55.000.000. All together, there were roughly thirty major fraudulent campaigns, which is one and a half times more than the year before, in 2023. In the first quarter of 2024 alone, drainers showed almost sixfold growth. Compare that to ransomware, which only doubled over that same stretch of time.

So what do all these numbers really mean? Well, because the barrier to entry into this line of work is so remarkably low, it has started attracting scammers who used to work in more old-fashioned territory, like email phishing, luring victims to fake bank login pages and other traditional scam types. A couple of months of this kind of work could buy an apartment, a car, and regular vacations somewhere warm like Thailand. Take one risk, and you can just walk away, or so the thinking goes. But of course, once someone gets a real taste of easy money like that, nobody actually walks away after two months. The business pulls them back in.
Think about the contrast here. A ransomware group has to negotiate with a company, arrange for payment, and handle the whole business of decryption afterward. That’s a lot of hassle and a lot of steps where things can go wrong. A drainer, on the other hand, just steals the money immediately. No negotiation needed.
Like plenty of other kinds of scams out there, drainers are distributed under what’s called a SaaS model, short for Software-as-a-Service. In this criminal corner of the internet, they’re called DaaS, meaning Drainer-as-a-Service.
There’s also a very characteristic division of labor inside these operations. You’ve got developers, who build the actual malware. You’ve got workers, the rank-and-file operatives out doing the scamming day to day. And alongside them you’ve got recruiters, traffic-generation specialists, and providers of various supporting services that keep the whole machine running. The main job, naturally, falls to the developers. They are the ones who create the malicious software and work to make it more convenient to use, easier to deploy, and easier to scale up.
So what does a hacker actually need in order to pull off a phishing campaign like this?
First, they need domains for their future sites, and these domains are usually spelled just similarly enough to the name of the real project they’re impersonating, so a distracted eye won’t catch the difference. Then they need hosting, which is simply a place to put the site once it’s built. Naturally, they also need a landing page, one designed to closely resemble the legitimate project’s real page. Underneath that landing page sits the drainer code itself, which is typically JavaScript code hosted directly on the site. On top of all that, they’ll usually build a control panel that shows them how many users have been lured in and tracks how those users are behaving on the page. And finally, hackers take their own security seriously too, relying on VPNs, proxies, and fake sockpuppet accounts to cover their tracks.

Professional hackers usually go a step further and set up a full command-and-control server, which lets them manage the drainer’s behavior remotely and adjust it on the fly.
Once all of that infrastructure is in place, all that’s left is bringing in people, actual victims to walk through the trap. That job falls to traffic arbitrage specialists, sometimes called traffic drivers. Their whole task is to funnel users toward the phishing page. They accomplish this in all sorts of ways, everything from buying Google ads to jumping directly into comment sections and posts to engage with real users. Some scammers even go so far as to clone the official support channels of legitimate projects, so a victim reaching out for help ends up talking to the scammer instead.
Put it all together, and what you get is a genuine sales funnel, a designed path that walks victims toward the trap, just like any legitimate marketing funnel would walk a customer toward a purchase.
Here’s how the profits typically get divided up. Operators, the people running the overall scheme, take home twenty to thirty percent of whatever gets stolen. The rest goes to the workers, the people directly out there scamming victims day to day. A worker’s exact cut depends on their skill level. Beginners give up thirty percent of their take to the operators, while the most experienced workers only give up ten to fifteen percent.
And how is a worker’s skill level judged? Simply by how much they have already managed to steal over time. If you’ve stolen up to $10.000 total, you’re considered a beginner. Between $25.000 and $30.000 puts you at mid-level. And starting from $100.000, usually climbing toward a million or more, you’re considered a true professional in this dark little trade.
Knowledge in this underground world gets passed around among workers through tutorials. A tutorial itself becomes an item that gets bought, sold, and traded, almost like a piece of merchandise. Entire communities have formed just to gain access to these tutorials, treating them like valuable trade secrets. The writing style of these tutorials makes it fairly clear that AI tools were used to help put them together.
Broadly speaking, the same traffic-driving scheme used in ordinary, everyday phishing applies here too, just adapted for the world of crypto. A worker is essentially doing the same job as any online advertising specialist would. Their goal is simply to increase the number of people clicking through to the phishing page. That means hunting for users who are genuinely interested in Web3 and DeFi projects, people who hold crypto wallets and who are drawn to airdrops, token swaps, and exchanges.

This whole process involves demographic analysis and geolocation analysis, essentially the same ordinary targeting techniques that any advertiser in any industry would recognize. Workers also handle what they call “site design,” which really just means cloning the pages of existing, trusted projects. They’ll even use classic marketing techniques like A/B testing to see which fake page tricks more people.
Now let’s walk through a few high-profile examples of drainer thefts.
Arkham is a company that provides on-chain analytics, and it’s a genuinely popular tool for tracking transactions. Traders rely on it, for instance, to check an asset’s price and see exactly where it’s trading across different platforms.
Back in 2023, Arkham’s owners launched their own token along with an airdrop of coins to celebrate. But hackers saw an opportunity and created numerous fake profiles on X specifically to redirect users toward phishing pages containing a drainer. Remarkably, these bot accounts proved quite resilient and managed to avoid being banned for a long stretch of time. They mimicked Arkham’s real activity closely and spread malicious links far and wide.
A huge number of these fake sites were created during the campaign, and each one typically had a lifespan of just weeks, or a couple of months at most. Angel’s software allowed a hacker to copy landing pages quickly and place them on brand-new domains almost instantly. The whole process has been simplified so much that a worker only needs to type a few commands into a conversation with a Telegram bot in order to deploy an entirely new phishing site.
An even bigger impact can be achieved by a hacker hijacking the real, verified account of some authoritative company, or even a government organization.

And that’s what happened with the United States Securities and Exchange Commission, or the SEC. On January 9, 2024, its account on X was compromised through a technique called SIM swapping, which basically means reissuing a SIM card tied to the phone number linked to that account. Officials, unfortunately forgetting about basic security hygiene, hadn’t even enabled multi-factor authentication on the account.
Lately, the SIM-swapping community and the drainer community have grown noticeably closer, almost like two neighboring criminal industries starting to collaborate. Swappers now routinely supply drainers with freshly hijacked accounts to use.
The hackers behind this attack posted that the SEC had officially approved investing in Bitcoin without needing to buy crypto directly on an exchange like Binance or Coinbase. This caused an immediate stir, because investors had been waiting a long time for exactly this kind of decision from the SEC, and many expected it to be announced any day. Following the fake post, the hackers urged people to claim an “official SEC airdrop” on a special site that contained a drainer.
That single fake post even caused a real spike in Bitcoin’s price. It rose by a full thousand dollars, just from a fake tweet.
Scammers, as it turns out, wouldn’t really be scammers if they didn’t also scam each other. At one point, the developer behind the Pink Drainer felt like he was getting close to being unmasked, so he decided to get out of the game entirely and cash out his loot. Here’s the catch, though. You can’t just sell crypto obtained through a scam outright. To actually withdraw the funds, a scammer first has to launder the money, or else an exchange might get suspicious and freeze it before it ever reaches a real bank account.
To avoid enabling things like terrorism financing, or simply to stay within the law, exchanges use a system of scoring and refuse to accept “dirty” crypto. This scoring system is called an AML score, short for anti-money-laundering. There are plenty of laundering methods out there, and while trying one of them, Pink Drainer’s own developer ended up getting scammed himself. He fell for one of the simplest kinds of fraud imaginable called address poisoning.
Here’s how it works. Hackers generate crypto addresses that closely resemble a victim’s real address, and then they send that victim a tiny amount of crypto, just enough so that the lookalike address shows up in the victim’s transaction history.

From the user’s side, here’s what it looks like in practice. You send, say, one hundred dollars to some other wallet, maybe an exchange you use regularly. Then, five or ten minutes later, you receive a few tiny transfers that appear to come from that very same wallet. But in reality, they only come from a similar-looking address, one that might share, say, an identical start and end to the real address, while the middle is different.
The hacker is betting that on your next transfer, you’ll simply scroll through your history, pick the most recent address you see, and send your money not back to yourself, but straight into the hacker’s pocket. And that’s exactly how Pink Drainer got caught in his own kind of trap. He picked what looked like the last transaction in his history and sent ten ETH, worth about $15.000 at the time, straight to some unknown “colleague” who was never really his colleague at all.
Because draining is so easy and profitable, this type of scam is not going away anytime soon. If anything, the ways malicious payloads get delivered will only keep getting more sophisticated from here. Drainers are increasingly setting their sights on younger blockchains too. On Ethereum-based networks, it’s steadily getting harder for hackers to operate, since protective measures keep appearing that they have to find new ways to bypass. On Solana, though, no such protections really exist yet, which makes it a much softer target. New kinds of drainers will keep emerging as well. Some scammers have already started building actual apps for Google Play and the App Store, moving beyond simple websites and into places millions of people trust by default. So stay alert out there, and think twice before you click any button, especially one promising you free money. If it feels too good to be true, in crypto more than almost anywhere else, it usually is.
If you’re interested in cryptocurrency forensics, we have a dedicated training called Bitcoin and Cryptocurrency Forensics. You will get to dive into blockchain analysis and cryptocurrency investigations, learning the skills needed to become a cryptocurrency forensic analyst. You can buy the training separately or attend it live on September 15-17 at 3 PM UTC.
The post Cryptocurrency Drainers: How Hackers Steal Cryptocurrency first appeared on Hackers Arise.