The Cold Storage Chronicle
Threat Intelligence · Defensive Guide

Drainer kits are sold like SaaS. Here's the attack — and how it dies.

Dark-web forums openly advertise “drainer kits” for the TON ecosystem and others: full setup materials, video guides, Telegram bot logging, multi-wallet support. Malware-as-a-service, with customer support. The best defense is understanding the four-step play they all run. Walk through it below — then flip the defenses on and run it again.

Step 1 · The lureA Telegram DM or reply-guy post: “Claim your $GRASS/TON airdrop — check your allocation!” The link leads to a pixel-perfect clone of a real project site. Press step 2 to take the bait.

✓ Your defenses (toggle, then replay)

1,000 TONWallet balance

What a drainer kit actually is

A drainer is not a hack of the blockchain — it's a hack of you. The kit bundles: a phishing site template, wallet-connect integration, a script that requests token approvals or a deceptive signature, and auto-sweep logic that transfers everything the moment you sign. Operators rent it for a revenue share (commonly 10–30% to the kit author, tracked through the kit's Telegram bot). TON-focused kits exploit the ecosystem's Telegram-native culture, where links in chats feel normal.

The critical detail: the victim signs the transaction themselves. No exploit, no brute force. One deceptive signature — often disguised as “verify wallet” or “claim” — grants transfer rights, and the sweep follows in seconds.

Red flags that precede every drain

Urgency + free money“Airdrop closes in 2 hours.” Real distributions don't rush you; scarcity is a compliance-bypass tool aimed at your reflexes.
Unsolicited linksDMs, QR codes at events, replies from lookalike accounts. Legit claims happen inside official apps/sites you navigate to yourself.
Signature you can't readIf the wallet popup shows opaque hex or asks for “setApprovalForAll” / unlimited spend for a simple “claim,” it's the trap itself.
“Check eligibility” requiring connect + signReading balances never requires a signature. Eligibility checks that demand one are harvesting approvals.

The defense stack, in order of value

  1. Segregate: a burner wallet with pocket change for mints/claims; savings in a wallet that never touches dApps.
  2. Read signatures: hardware wallets force human-readable review; if you can't tell what a signature does, don't sign it.
  3. Revoke: audit token approvals monthly (revoke tools exist for every major chain) so old permissions can't be exploited later.
  4. Slow down: every drain in history needed the victim to hurry. A 60-second pause defeats a $10,000 kit.
Enjoy this tool? Build your own with Super