StepDrainer
Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.
anchored·SZzQgn…wyPfSummary
StepDrainer is an active Malware-as-a-Service (MaaS) crypto wallet drainer commercially distributed within cybercriminal ecosystems. It supports more than 20 blockchain networks and abuses legitimate Web3 smart contract primitives, including Seaport and Permit v2, to present victims with convincing wallet-approval prompts. Security researchers reported in April and May 2026 that over 500 Ethereum wallets had been drained in a single 24-hour window, with losses reportedly exceeding $800,000.
Connected Entities
2 entities- 8ycauM…cP4k→mentioned with→StepDrainer(50%)
Timeline(4 events)
September 2025
Solana account 8ycauMwVE61B4uWz87B2k2G8mMK7iFjRoBHooaVAcP4k becomes active, later identified by SpiderLabs as StepDrainer's campaign configuration store.
SpiderLabs/LevelBlue research21 April 2026
Offseq Radar publishes threat intelligence report on StepDrainer, documenting its MaaS pricing, multi-chain scope, and known indicators of compromise including domains moonscan.live and scanclaw.live.
Offseq Radar23 April 2026
SpiderLabs (LevelBlue) publishes detailed technical analysis of StepDrainer as part of a broader report on converging crypto drainer threats, documenting Solana on-chain configuration, 3,000+ domains, OpenClaw impersonation, and IOCs.
SpiderLabs/LevelBlue1 May 2026
Cryptonews.net and Cryptopolitan report that over 500 Ethereum wallets were drained within a 24-hour period, with losses reportedly exceeding $800,000. Funds were reportedly laundered via ThorChain.
Cryptonews.net / CryptopolitanDecision Log
- hash: WF5TGgVFSNu7kaJeyWLVe2Pc2SCWxRU2nZ3znekGPpe
This investigation is cryptographically anchored to the Solana blockchain (1 event). 4 of 5 cited source URLs have an Internet Archive snapshot.
model: claude-sonnet-4-6
generated: 10/4/2026, 11:19:35 PM
last updated: 10/4/2026, 11:24:22 PM
avoid.net — verified advice for a post-truth world