Pink Drainer winds down after an $85 million run
The crew that hijacked verified accounts by posing as reporters said in May 2024 it was closing shop. On-chain trackers had already tied it to tens of millions in theft.
On 17 May 2024, on-chain investigator ZachXBT flagged a Telegram message from the Pink Drainer group saying it would wind down its operations and destroy its stored data. Per DailyCoin, trackers had by then linked the operation to roughly $85 million in stolen crypto.
Pink stood out less for clever contract code than for how it reached its targets. Where many kits rely on a fake mint page, Pink invested in patient, human social engineering, and that patience is what made it dangerous.
Journalists who weren't
Per BleepingComputer, Pink operators posed as reporters from outlets such as Cointelegraph and Decrypt, arranging fake interviews with project teams and influencers over one to three days to build trust before asking for anything.
The 'interview' ended at a bogus verification step. Per BleepingComputer, victims were guided to a counterfeit Carl verification bot and told to drag a malicious bookmark into their browser, which harvested their Discord token, no password or two-factor code required.
With that token, per BleepingComputer, attackers hijacked Discord servers, promoted themselves to administrator, removed the real admins, and pushed fake mints and phishing links to the followers. The same crew seized X accounts, including that of OpenAI CTO Mira Murati, to broadcast fraudulent token claims.
Retirement is not restitution
One documented wave alone hit 1,932 victims for about $3 million, per Scam Sniffer via BleepingComputer; the running total climbed from there toward the $85 million DailyCoin cited at the exit. When Pink announced it was leaving, per DailyCoin, it warned of impersonators and said it would not return, an ending that recovered nothing for anyone already drained.
**Lessons for teams and holders:** - An unsolicited 'interview' or partnership offer that ends in a verification or KYC step is a known account-takeover script. - Never drag in a bookmark or run a 'verification bot' someone sends you; that step exists to steal your session token. - A message from a verified or admin account can be an intruder; confirm any large or urgent ask on a second channel. - A drainer 'shutting down' returns no funds and stops no successors; the method outlives the brand.
Pink's real innovation was social, not technical, and that is the part that persists: the borrowed accounts, the fake reporters, and the verification-bot lure long outlasted the name attached to them.
— Sources: [DailyCoin](https://dailycoin.com/crypto-industry-relieved-as-wallet-drainer-bites-the-dust/) · [BleepingComputer](https://www.bleepingcomputer.com/news/cryptocurrency/hackers-steal-3-million-by-impersonating-crypto-news-journalists/)
NOT FINANCIAL ADVICE · VERIFY EVERYTHING