Security alert: wallet compromised by drainer kit using fake USDT/airdrop tokens and fraudulent claim pages designed to steal signatures.
Security & Exploits ·
A wallet was targeted by a drainer kit deploying fake USDT and airdrop tokens paired with fraudulent claim pages designed to harvest transaction signatures. The attack leveraged social engineering tactics—prompting users to authorize permits or authenticate token transfers that were never legitimately initiated—to gain access to funds without explicit transfers.
Drainer kits exploit a common user behavior: many participants approve token contracts before receiving them, or sign permit functions to reduce transaction friction. Attackers capitalize on this by creating spoofed airdrop landing pages and counterfeit token contracts that request these same signature types, then using those authorizations to drain connected wallets. The affected address has been flagged with a public warning.
The advisory underscores a core defense: never signing for tokens not directly purchased, and migrating holdings to a fresh wallet if any unauthorized permit or auth signature has been submitted. The specific scope of funds at risk in this instance—whether partial or total wallet compromise occurred—and the timing of discovery relative to the attack remain unclear.