Hasty Briefsbeta

Bilingual

Would you like a drainer served at the very top of DuckDuckGo?

13 hours ago
  • A fake Tronscan blockchain explorer appeared as the #1 search result on DuckDuckGo, prompting users to connect their wallet and leading to a drainer.
  • Attackers exploit SEO on Bing and DuckDuckGo to rank phishing sites high, using gateway domains that silently redirect to rotating phishing pages.
  • The drainer scans victims' wallets after connection, requesting approval for unlimited TRC-20 tokens and claiming TRX via smart contracts.
  • KYT/AML tools failed to flag attacker addresses, showing low risk scores, enabling potential laundering of stolen funds through licensed exchanges.
  • Phishing sites also target other web3 products like Solscan, Phantom, and Etherscan using Github Pages or website builders for hosting.
  • The drainer uses server-side transaction requests based on user balances, with hardcoded attacker wallets and contract addresses.
  • The author emphasizes the need for better detection by AML tools and raises awareness about operational security risks in crypto.
  • The investigation was triggered accidentally while testing an address spellchecker for Tron, leading to discovery of a previously unknown phishing campaign.