SubscribeBTCSCAMWallet Test
Front page / Threat intel
highThreat intel

The $59 million ad buy: how MS Drainer rode Google and X to victims

Scam Sniffer traced 63,000 victims to fake DeFi front-ends served as paid search and social posts. The clicks were real; the destinations were counterfeits wired to a drainer kit.

JR
Jules Renner
Community Manager · DEC 21, 2023 · 4 min read
Painting: Renaissance archive · Source: BleepingComputer

Most drainer coverage fixates on the smart-contract trickery at the end of the con. MS Drainer's operators demonstrated that the front of the funnel matters just as much: they did not wait for victims to wander in, they bought the traffic.

Per Scam Sniffer, whose findings were reported in December 2023, MS Drainer-linked sites stole about $59 million from 63,210 victims over roughly nine months beginning in March 2023. Researchers counted more than 10,000 phishing sites tied to the single kit, per BleepingComputer.

Paid ads as a delivery system

The lures ran as ordinary ads on Google Search and on X, sitting directly above or beside real results. Per BleepingComputer, the counterfeit pages impersonated well-known DeFi brands including Zapper, Lido, Stargate, DefiLlama, Orbiter Finance, and Radiant, names users already trusted.

On Google, per BleepingComputer, the crew abused an ad tracking-template loophole so the visible URL looked legitimate while quietly redirecting to a counterfeit. On X, most of the phishing ads Scam Sniffer observed were posted from compromised 'verified' accounts, renting their built-in credibility.

Regional targeting and page-switching helped the ads slip past review: auditors and visitors in different locations could be served different pages, so what a reviewer saw was not always what a victim got.

A kit anyone could rent

MS Drainer was a product, not a private tool. Per BleepingComputer, the kit sold for around $1,500, with optional modules at $500 to $1,000 and a 20% cut of whatever affiliates stole. The pricing put a professional theft engine within reach of anyone willing to pay, and individual losses ran into the millions; one victim lost $24 million in Ether.

**How to stay off the funnel:** - Do not click sponsored or ad results for wallets and DeFi apps; type the address or use a saved bookmark. - A 'verified' badge on the account running an ad tells you nothing about where the link goes. - Re-check the address bar after any redirect; drainers depend on look-alike domains. - If a familiar app suddenly asks to connect and approve tokens right after you clicked an ad, stop and reassess.

The uncomfortable lesson, per Scam Sniffer's findings, is that the ad platforms' own machinery, search placement, verified badges, and tracking templates, was quietly repurposed into the distribution layer for the theft.

— Sources: [BleepingComputer](https://www.bleepingcomputer.com/news/security/crypto-drainer-steals-59-million-from-63k-people-in-twitter-ad-push/) · [Hackread](https://hackread.com/hackers-stole-59-million-crypto-google-x-ads/)

The Rug Report
Every scam that mattered this week, each Sunday.

NOT FINANCIAL ADVICE · VERIFY EVERYTHING