{"id":545324,"date":"2023-01-30T07:16:43","date_gmt":"2023-01-30T04:16:43","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/monkey-drainer-linked-scammers-possibly-exposed-after-an-on-chain-quarrel\/"},"modified":"2023-01-30T07:16:43","modified_gmt":"2023-01-30T04:16:43","slug":"monkey-drainer-linked-scammers-possibly-exposed-after-an-on-chain-quarrel","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/monkey-drainer-linked-scammers-possibly-exposed-after-an-on-chain-quarrel\/","title":{"rendered":"# Monkey Drainer-linked scammers possibly exposed after an on-chain quarrel"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_84 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<label for=\"ez-toc-cssicon-toggle-item-6a2296eaf1163\" class=\"ez-toc-cssicon-toggle-label\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #dd3333;color:#dd3333\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #dd3333;color:#dd3333\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input type=\"checkbox\"  id=\"ez-toc-cssicon-toggle-item-6a2296eaf1163\" checked aria-label=\"Toggle\" \/><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-1'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/buradabiliyorum.com\/en\/monkey-drainer-linked-scammers-possibly-exposed-after-an-on-chain-quarrel\/#%E2%80%9D_Monkey_Drainer-linked_scammers_possibly_exposed_after_an_on-chain_quarrel_%E2%80%9C\" >&#8221; Monkey Drainer-linked scammers possibly exposed after an on-chain quarrel &#8220;<\/a><\/li><\/ul><\/nav><\/div>\n<h1><span class=\"ez-toc-section\" id=\"%E2%80%9D_Monkey_Drainer-linked_scammers_possibly_exposed_after_an_on-chain_quarrel_%E2%80%9C\"><\/span>&#8221; Monkey Drainer-linked scammers possibly exposed after an on-chain quarrel &#8220;<span class=\"ez-toc-section-end\"><\/span><\/h1>\n<div class=\"post-content\" data-v-5a4050f8>Blockchain security firm CertiK believes to have found the real identity of at least one scammer allegedly linked tothe \u201cMonkey Drainer\u201d phishing scam.<\/p>\n<p>Monkey Drainer is the pseudonym for a\u00a0phishing scammer(s)\u00a0that uses smart contracts to steal NFTs through a process known as &#8220;ice phishing.&#8221;\u00a0<\/p>\n<p>The individual or persons behind the phishing scam have stolen millions worth of Ether (ETH) via malicious copycat nonfungible token (NFT) minting websites to date.\u00a0<\/p>\n<p>In a Jan. 27 <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.certik.com\/resources\/blog\/1Mqlfo1UW6yHCaq1D3hlfK-exposing-wallet-drainer-scammers-zentoh-and-co\">blog<\/a>, CertiK said it found on-chain messages between two scammers involved in a recent $4.3 million Porsche NFT phishing scam and was able to link one of them to a Telegram account involved in selling the Monkey Drainer-style phishing kit.\u00a0<\/p>\n<blockquote class=\"twitter-tweet\">\n<p lang=\"en\" dir=\"ltr\">Exposing Scammers <\/p>\n<p>CertiK investigators uncovered two scammers, Zentoh and Kai, behind the Monkey Drainer kit <\/p>\n<p>This kit is sold to prospective scammers who are looking to steal user funds using Ice Phishing<\/p>\n<p>Who was involved and how? Let&#8217;s see <\/p>\n<p>\u2014 CertiK (@CertiK) <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/twitter.com\/CertiK\/status\/1619388807568302085?ref_src=twsrc%5Etfw\">January 28, 2023<\/a><\/p><\/blockquote>\n<p><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>One message revealed a person referring to themself as \u201cZentoh\u201d and referred to the person who stole the funds as \u201cKai.\u201d<\/p>\n<p>Zentoh was seemingly upset at Kai for not sending over a slice of the stolen funds. The message from Zentoh directs Kai to deposit the ill-gotten gains \u201cat our address.\u201d<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2023-01\/28b4ecf1-c3f4-4878-bcd2-9dfff11c0b10.png\"><figcaption style=\"text-align: center;\"><em>An on-chain message from a person referring to themselves as \u201cZentoh,\u201d upset they didn\u2019t receive a portion of phished funds from a person they address as \u201cKai.\u201d Image: <\/em><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.certik.com\/resources\/blog\/1Mqlfo1UW6yHCaq1D3hlfK-exposing-wallet-drainer-scammers-zentoh-and-co\"><em>CertiK<\/em><\/a><\/figcaption><\/figure>\n<p>CertiK deduced the joint wallet was the address that received the $4.3 million in stolen crypto. The firm added there is a \u201cdirect link\u201d between the joint wallet and \u201csome of the most prominent Monkey Drainer scammer wallets.\u201d<\/p>\n<figure><img decoding=\"async\" src=\"https:\/\/s3.cointelegraph.com\/uploads\/2023-01\/afa400c6-f9da-45ae-b1af-95694a9f57c3.png\"><figcaption style=\"text-align: center;\"><em>The wallet address tied to Zentoh is in turn tied to numerous addresses linked to the Monkey Drainer scam. Image: <\/em><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.certik.com\/resources\/blog\/1Mqlfo1UW6yHCaq1D3hlfK-exposing-wallet-drainer-scammers-zentoh-and-co\"><em>CertiK<\/em><\/a><\/figcaption><\/figure>\n<p>Zentoh revealed in another message the pair used Telegram to communicate. CertiK found an exact match for the pseudonym on the messaging <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a> and identified it \u201cto be running a Telegram group that sells phishing kits to scammers.\u201d<\/p>\n<p>The company found numerous other online accounts possibly linked to Zentoh, including one on GitHub that posted repositories for crypto drainer tools.<\/p>\n<p>If the links between the accounts are legitimate, it reveals the identity of a French national living in Russia.<\/p>\n<p>Cointelegraph reviewed accounts potentially related to the person and found public accounts that seemed to be interested in cryptocurrencies. Cointelegraph contacted the person but did not im<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">media<\/a>tely receive a response.<\/p>\n<p>Cointelegraph will not publish the name of the person due to privacy concerns.<\/p>\n<p><strong><em>Related: <\/em><\/strong><strong><em>Hackers take over Azuki\u2019s Twitter account, steal over $750K in less than 30 minutes<\/em><\/strong> <\/p>\n<p>Crypto wallet-draining phishing scams have unfortunately been used to great effect recently.<\/p>\n<p>The co-founder of the Moonbirds NFT collection, Kevin Rose, fell victim to such a scam that lead to over $1.1 million worth of his personal NFTs being stolen.<\/p>\n<p>The crypto wallet of the influencer known on Twitter as \u201cNFT God\u201d suffered a similar fate after they downloaded malicious software from a Google Ad search result, with ETH and high-priced NFTs pilfered from the wallet.<\/p>\n<p><template data-name=\"subscription_form\" data-type=\"defi_newsletter\"><\/template><\/div>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">News<\/a> articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/general\/\" target=\"_blank\" rel=\"noopener\">General category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/cointelegraph.com\/news\/monkey-drainer-linked-scammers-possibly-exposed-after-an-on-chain-quarrel\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8221; Monkey Drainer-linked scammers possibly exposed after an on-chain quarrel &#8220; Blockchain security firm CertiK believes to have found the real identity of at least one scammer allegedly linked tothe \u201cMonkey Drainer\u201d phishing scam. Monkey Drainer is the pseudonym for a\u00a0phishing scammer(s)\u00a0that uses smart contracts to steal NFTs through a process known as &#8220;ice phishing.&#8221;\u00a0&#8230;<\/p>\n","protected":false},"author":1,"featured_media":545325,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/s3.cointelegraph.com\/uploads\/2023-01\/26cd1261-dc89-4a20-833a-266fdae7bcce.jpg","fifu_image_alt":"","footnotes":""},"categories":[1],"tags":[74894,73157,75134,71101,72287],"class_list":["post-545324","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-general","tag-blockchain","tag-investigation","tag-phishing","tag-scams","tag-security"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/545324","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=545324"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/545324\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/545325"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=545324"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=545324"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=545324"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}