216.73.216.226

Silent Crypto Wallet Takeover Unlimited USDT Approval Exploitation via Trust Wallet QR Code Phishing

· Published 15/04/2026 17:16 · Modified 15/04/2026 17:28

Export JSON

Essential information

Published
15/04/2026 17:16
Modified
15/04/2026 17:28
Tags
2026-04-15 bnb smart chain crypto drainer deep link exploitation drainer-as-a-service qr code phishing telegram bot token approval abuse trust wallet usdt
Related entities
3 observables, 21 techniques (mitre)

Description

An active campaign targets users through malicious QR codes distributed via Telegram, exploiting deep link mechanisms to redirect victims to Netlify-hosted phishing domains. The attack masquerades as a legitimate transfer interface but covertly triggers an ERC-20 approve() transaction, granting unlimited token allowance to an attacker-controlled contract on . This enables persistent fund drainage without further victim interaction. The modular drainer architecture uses config.js for control parameters and main.js for execution logic, with integrated infrastructure providing real-time transaction monitoring. Analysis confirms 52 transaction notifications indicating active exploitation. The campaign employs social engineering through a deceptive dollar-one illusion where victims believe they are initiating small transactions while actually granting unlimited wallet access. Multiple cloned phishing domains demonstrate scalable deployment within a Drainer-as-a-Servic

External references