Open account

StepDrainer drains crypto wallets across +20 networks

A malware-as-a-service called StepDrainer is stealing crypto from wallets across more than 20 blockchains — notably targeting Ethereum wallets — by displaying fake Web3 wallet approval pop-ups and abusing tools like Seaport and Permit v2. Researchers also identified EtherRAT, a related Windows malware vector. On-chain analysis shows over 500 Ethereum wallets were drained within 24 hours, with attackers siphoning over $800K and routing funds via ThorChain. Market impact: higher security risk could reduce user confidence in on‑chain interactions, weigh on short‑term trading activity for affected chains (Ethereum, BNB Chain) and increase demand for tighter wallet hygiene and contract-approval tools. Exchanges and DeFi platforms may see heightened scrutiny and potential temporary outflows as users revoke approvals and move assets to cold storage.

Category

Ethereum

Sentiment

Bearish

Event

Security incident

Reading time

1 min