Monkey Drainer, the wallet-draining kit that quit while ahead
For roughly six months a rented phishing kit let affiliates empty MetaMask wallets for a 30% cut. In February 2023 its operator torched the servers, pointed clients at a rival, and walked.
Monkey Drainer was among the first names to turn "wallet drainer" into a household threat inside crypto. It behaved less like a lone hacker and more like a business: the developer rented a phishing kit to affiliates, who lured victims to counterfeit mint and airdrop pages, and skimmed a percentage of whatever the kit siphoned off.
Per CertiK, the operation drained at least $13 million in digital assets before it wound down. ZachXBT, the on-chain investigator who tracked it, had documented individual hits along the way, including hundreds of ETH lifted from single victims and high-value NFTs cleared out in late 2022.
A rented crime scene
The franchise model matters more than the mascot. CryptoSlate reported that Monkey's operator kept a 30% commission on funds stolen by other scammers using its kit. That arrangement, what the industry now calls drainer-as-a-service, let people with no coding ability run professional-grade phishing for a fee.
The kit's entire job was to get a victim to sign the wrong thing on a convincing fake page: a token approval, or a transfer. The counterfeit sites mimicked real projects closely enough that, once a victim approved a malicious spender or signed a transaction, the affiliate's script could sweep out tokens and NFTs in seconds.
On 28 February 2023, per CryptoSlate, the operator said it would destroy its files, servers, and devices, and would not return. In the same message it steered its customers toward a rival kit called Venom.
Why an 'exit' changes nothing
Shutdowns like this are largely cosmetic. CryptoSlate noted Monkey handed its clientele to Venom; across 2023, successor kits, MS Drainer and Pink among them, plus a wave of unnamed forks, multiplied. The brand retired, but the affiliates, the victims, and the techniques carried straight over. For victims the takeaway was blunt: recovering funds after a drainer sweep is rare, and a scammer's 'retirement' returns nothing.
**Red flags to watch for:** - Any 'claim', 'mint', or 'airdrop' page that demands a token approval or signature before it will proceed. - A wallet prompt asking you to 'approve' or 'permit' a token you have no intention of trading. - Unlimited, max-amount spend approvals; legitimate apps almost never need them. - A destination reached from a hijacked or promoted social post rather than a bookmarked, verified URL.
Practical defense has not changed since Monkey's day: treat every signature request as if it were a transaction. Use a hardware wallet, read the spender address before approving, revoke stale approvals, and keep long-term holdings in a wallet that never touches unfamiliar dapps.
— Sources: [CryptoSlate](https://cryptoslate.com/crypto-phishing-scammer-monkey-drainer-shuts-down-services/)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING