logo

One Scan to Zero: The QR Code Trap Wiping Trust Wallets via Telegram

ID: c2a01d7c-4b64-550b-9f49-1e3ef13ee104

STIX ID: report--c2a01d7c-4b64-550b-9f49-1e3ef13ee104

Feed Name: securityonline.info

Threat Score
75/100

Date Published: 2026-04-20

Date Updated: 2026-04-23

Author: Ddos

...
...

A Cyfirma analysis describes an active QR code-based drainer campaign on Telegram that leverages Trust Wallet deep links to Netlify-hosted phishing pages; victims are tricked into signing ERC-20 approve() transactions that grant attackers unlimited token allowance, enabling persistent wallet draining. The operation is modular and marketed as Drainer-as-a-Service, uses Telegram bots for real-time monitoring, and researchers observed evidence of active exploitation (at least 52 transaction notifications). Users are advised to verify requests, audit and revoke unlimited approvals, and be wary of Netlify-hosted USDT interfaces.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.