StepDrainer drains crypto wallets across +20 networks
A malware-as-a-service called StepDrainer is stealing crypto from wallets across more than 20 blockchains — notably targeting Ethereum wallets — by displaying fake Web3 wallet approval pop-ups and abusing tools like Seaport and Permit v2. Researchers also identified EtherRAT, a related Windows malware vector. On-chain analysis shows over 500 Ethereum wallets were drained within 24 hours, with attackers siphoning over $800K and routing funds via ThorChain. Market impact: higher security risk could reduce user confidence in on‑chain interactions, weigh on short‑term trading activity for affected chains (Ethereum, BNB Chain) and increase demand for tighter wallet hygiene and contract-approval tools. Exchanges and DeFi platforms may see heightened scrutiny and potential temporary outflows as users revoke approvals and move assets to cold storage.