Threats Tagged 'smart contract'
View all threats tagged with 'smart contract'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'smart contract'
Click on any threat for detailed analysis and mitigation recommendations
StepDrainer is a Malware-as-a-Service (MaaS) platform engineered to steal digital assets from cryptocurrency wallets, including fungible tokens and high-value NFT collections. The malware supports more than 20 blockchain networks and incorporates multiple draining techniques, particularly abusing ERC-20 token permissions and NFT approval mechanisms. The platform includes automated asset transfer capabilities, compatibility with widely used mobile wallets, and encrypted logging via Telegram channels for attacker monitoring. StepDrainer is commercially distributed within cybercriminal ecosystems, with pricing models ranging from approximately $750 for full source code access to $150 for a shared version that imposes a 20% commission on successful thefts. Join the discussion | AlienVault OTX General | 04/21/2026, 08:26:23 UTC Added: 04/21/2026, 09:31:05 UTC |
A series of cryptocurrency scams have been uncovered where threat actors distribute malicious smart contracts disguised as trading bots to drain user wallets. The campaign has stolen over $900,000 US and employs multiple obfuscation techniques to conceal the attacker's wallet address. Leveraging aged YouTube accounts and curated comment sections, the scams create a false sense of legitimacy. The smart contracts, written in Solidity, use various methods to hide the attacker's Externally Owned Account. Distribution occurs through YouTube videos explaining the contracts as trading arbitrage bots, with some videos showing signs of being AI-generated. The most successful scam yielded approximately $902,000 US from a single attacker address. Join the discussion | AlienVault OTX General | 08/05/2025, 13:21:58 UTC Added: 08/05/2025, 13:47:43 UTC |
Showing 1 to 2 of 2 results