Worked example · 2023-20
Fake DEX / clone-frontend distribution cohort — multi-chain — 2023 onward (multi-year cohort)
Summary
The fake-DEX clone-frontend class encompasses phishing campaigns whose distribution surface is paid-for inventory on a legitimate ad platform (Google Search ads, X / Twitter promoted posts, Telegram bot traffic, App Store listing) and whose lure is a counterfeit deployment of a popular DEX UI — Uniswap, PancakeSwap, Curve, Raydium, Lido, Stargate, Orbiter, DefiLlama, Zapper, Radiant, and similar platforms. The attacker-controlled UI is visually indistinguishable from the legitimate site at first glance, hosted on a typosquatted / near-miss / homoglyph domain, and connects to a wallet-drainer backend (Inferno → Angel / AngelFerno; MS Drainer; PhishLab kits) that solicits permit signatures, Approval events, or setApprovalForAll calls scoped to attacker-controlled spender contracts.
The class has four distinguishable distribution sub-surfaces:
Google Search paid ads — the highest-volume sub-class. The attacker buys keyword inventory matching the legitimate platform's name; the paid result ranks above the legitimate platform's organic result. Tracking-template misuse displays the legitimate domain to Google Ads' review surface while the click resolves to the phishing URL. Calibration anchor: MS Drainer December 2023 ($59M / 63,210 victims; 10,000+ phishing websites; targeting Zapper / Lido / Stargate / DefiLlama / Orbiter / Radiant). See
[scamsniffermsdrainer2023],[bleepingmsdrainer2023],[cointelegraphmsdrainer2023].X (Twitter) paid promoted posts — the second-highest-volume sub-class. ScamSniffer December 2023 reports six of nine paid phishing ads on their feed in late 2023 were MS Drainer instances; X paid-ad inventory has been used continuously through 2024–2026 for fake-DEX, fake-airdrop, and fake-NFT-mint campaigns. Calibration anchor: 2025-07-21 Polymarket user loss $1.23M via a fake Uniswap clone reached through a paid X / Google ad (per ScamSniffer + ZachXBT public reporting). See
[cryptonewsuniswap12m2025],[protosuniswap2025],[gateuniswap2025].Telegram bot-driven traffic — the attacker operates a Telegram channel or bot ("trade $TOKEN now," "snipe new tokens," "verify your wallet") that funnels users to the fake-DEX clone-frontend at signing time. Distinct from Cohort A's other sub-surfaces because the user trust is funnelled through a Telegram-personality / community channel rather than a paid ad placement; the lure is community-amplified rather than search-amplified. Calibration anchor: 2024–2025 Solidus Labs PumpCell (~$800K/month October 2025) and Kaspersky / Group-IB observations of 2,000% surge in Telegram phishing-bot volume late 2024 (
[kasperskytelegram2025],[bleepingtelegrambots2024]).App store fake DEX wrapper apps — counterfeit Android / iOS applications listed under previously-benign or compromised developer accounts that wrap a phishing UI inside a WebView. The fake apps prompt users to enter their 12-word mnemonic phrase under the guise of "importing your wallet to PancakeSwap / SushiSwap / Raydium / Hyperliquid." PancakeSwap notably has no legitimate mobile application (web-only at v0.1 cutoff), so any mobile app under that brand is counterfeit. Calibration anchor: Cyble Research and Intelligence Labs 2024 cohort (20+ apps, 50+ phishing-domain infrastructure, Median-framework WebView wrapping, embedded malicious URLs in privacy-policy text); 2025 Google Play removal sweep (22+ apps). See
[cyblecryptophishingapps2024],[hackreadgoogleplaypishing2024],[techradarcryptoplaystore2024].
The class-level forensic surface combines: ScamSniffer's drainer-campaign tracking and December 2023 MS Drainer publication; SlowMist's 2024 Mid-year and Annual Blockchain Security Report ($494M wallet-drainer total); BleepingComputer / Infosecurity Magazine reporting; Cyble Research and Intelligence Labs Play Store cohort write-up; Group-IB Inferno Drainer technical analysis; and per-victim public reporting via ZachXBT, Lookonchain, and SEAL Threat Intel.
Why this is structurally novel
T4.002 (Compromised Front-End Permit Solicitation) was OAK v0.1's only Technique covering fake-frontend phishing. The fake-DEX clone-frontend class is structurally distinct from T4.002 across three load-bearing dimensions:
The substrate of the fake frontend differs. T4.002 compromises a real platform's user-facing surface — DNS records (Curve August 2022, Galxe October 2023, Balancer September 2023), supply-chain JS (BadgerDAO December 2021), or BGP / hosting (Balancer parallel to DNS). The legitimate platform's domain, registrar account, hosting, or dependency tree is the compromised asset. The fake-DEX class never compromises the legitimate platform — the entire UI is hosted on a typosquatted / near-miss / homoglyph domain controlled by the attacker from the moment of deployment. The legitimate platform's threat-model surface (registrar lock, DNSSEC, ENS+IPFS pinning, supply-chain integrity) is not load-bearing for the fake-DEX class because the legitimate platform was never the substrate.
The detection-surface locus differs entirely. T4.002 detection lives at the legitimate platform's infrastructure layer — DNS canary, registrar lock, content-hash drift, BGP route monitoring (per OAK-T4.002 detection signals). Fake-DEX clone-frontend detection lives at the ad-platform's review-and-takedown layer — Google Ads' tracking-template-misuse detection, X's promoted-post review, Apple App Store / Google Play review, and Telegram's bot / channel takedown processes. The detection-tooling cohort that solves T4.002 (Cloudflare Radar, RIPE NCC route monitors, ENS+IPFS pinning enforcement) does not solve the fake-DEX class. The fake-DEX class is solved at the ad-platform side or not at all.
The accountability-chain shape differs. T4.002 incidents produce post-mortems by the affected legitimate platform (Curve, Galxe, Balancer, BadgerDAO published their own incident write-ups), authoritative reconstruction, and (typically) a public domain-recovery moment. Fake-DEX clone-frontend incidents do not — there is no legitimate platform whose security team owns the post-mortem; the legitimate platform's only public-facing role is to disclaim affiliation and warn users (Uniswap CEO's "the ad economy needs to go" public response in July 2025; PancakeSwap's recurring "we have no mobile app" notices). The accountability gap maps to the ad platform (Google, X, Apple, Google Play, Telegram), which historically does not publish incident write-ups for individual phishing-ad takedowns. The cohort is therefore documented at the threat-intel-aggregator layer (ScamSniffer, SlowMist, Cyble, Group-IB, SEAL Threat Intel) rather than at the per-incident victim-platform layer.
Three additional structural features distinguish the cohort:
The deployment-and-discovery race is operator-favourable on the ad surface. Google Ads / X Ads / App Store campaign deployment typically takes 12–48 hours from buy to placement; ad-platform-side takedown lags 24–96 hours from a credible report. The per-campaign extraction window therefore overlaps the takedown lag. ScamSniffer / SlowMist / SEAL Threat Intel ingest the campaign URLs at near-real-time but the ad platforms do not consume the threat feeds at machine-speed. The detection pipeline is mature; the takedown pipeline is the binding constraint.
The kit-substrate is shared with the T4.002 class. Inferno → Angel → AngelFerno is the dominant kit substrate across both legitimate-frontend-compromise (T4.002 — Curve, Galxe, Balancer) and fake-DEX clone-frontend (the cohort here). The
[checkpoint2023drainers]spender-cluster fingerprints recur across both classes. The structural implication is that the kit is the durable cohort-attribution fingerprint, not the distribution surface. OAK-G02 holds at the kit level even when the distribution surface differs.The legitimate-use overlap is structurally null. Unlike (e.g.) T1.001 / T1.004 (where governance-gated tax / pause authority on regulated stablecoins is a legitimate use of the same primitive), the fake-DEX clone-frontend has no legitimate analogue. A near-miss-domain hosting a copy of a legitimate DEX UI with a malicious
approvehandler is always malicious. The vetted-allowlist mitigation pattern that resolves benign edge cases in other Techniques does not apply; flagged campaigns are always malicious.
Timeline (UTC)
| When | Event | OAK ref |
|---|---|---|
| Pre-2023 | Drainer-as-a-Service category emerges (Pink, Monkey, Venom, Inferno, Angel) using DNS hijack + paid-ad distribution as parallel surfaces; the paid-ad surface is documented but not separately characterised | (foundational) |
| 2023-03 → 2023-12 | MS Drainer cohort — $59M extracted from 63,210 victims via 10,000+ phishing websites distributed primarily through Google Search ads spoofing Zapper, Lido, Stargate, DefiLlama, Orbiter Finance, Radiant; X (Twitter) ads carry six of nine MS Drainer phishing slots in ScamSniffer's late-2023 sample | T4.x candidate (paid-Google-Ads sub-class) |
| 2023-11-26 | Inferno Drainer announces shutdown of branded operation via Telegram; affiliate base / kit / paid-ad distribution channels persist into Angel / AngelFerno (see examples/2024-10-inferno-drainer-handover.md) |
(substrate continuity) |
| 2023-12 | ScamSniffer publishes MS Drainer cohort write-up; BleepingComputer, Infosecurity Magazine, Cointelegraph carry secondary coverage | (community forensic surface) |
| 2024 | Cyble Research and Intelligence Labs publishes Google Play Store cohort — 20+ counterfeit Android apps impersonating PancakeSwap, SushiSwap, Raydium, Hyperliquid, others; 50+ phishing-domain infrastructure; Median-framework WebView wrapping | T4.x candidate (App Store sub-class) |
| 2024 (full year) | Aggregate 2024 wallet-drainer ecosystem total reaches ~$494M per ScamSniffer / SlowMist (67% YoY increase, 332,000 victim addresses); fake-DEX clone-frontend distribution sub-class is the dominant per-incident shape across the cohort | T4.x candidate (cohort-scale anchor) |
| 2024-late → 2025 | 2,000% surge in Telegram phishing-bot volume per Kaspersky / Group-IB; Telegram-bot-driven traffic emerges as the third major distribution sub-surface alongside Google Ads + X Ads | T4.x candidate (Telegram-bot sub-class) |
| 2025-01 | ScamSniffer 2024 Annual Crypto Phishing Report publishes; documents Google Ads, X Ads, and Telegram as the three principal paid-traffic acquisition sources for wallet-drainer phishing | (cohort retrospective) |
| 2025-07-21 | Polymarket user loses ~$1.23M to fake Uniswap clone reached through Google Ads paid result; AngelFerno kit; ZachXBT and ScamSniffer publish per-incident reconstruction; Uniswap CEO Hayden Adams publicly calls for "the ad economy" to "go" | T4.x canonical per-incident anchor |
| 2025 | Google removes 22+ counterfeit DEX apps from Play Store across the year per multiple secondary write-ups | (takedown-side action) |
| 2026-03 | SEAL Threat Intel publishes three-week observation: 356 malicious advertisement URLs blocked targeting DeFi applications, wallets, and crypto services; the campaign trajectory continues into 2026 | (cohort persistence) |
| Continuing | The class persists into 2026 with Google / X / Apple / Google Play takedown processes lagging campaign deployment by 24–96 hours; cohort attribution remains at the kit-substrate level (Inferno / Angel / AngelFerno / MS Drainer / PhishLab) rather than per-campaign | (attribution state) |
What defenders observed
- Pre-event (ad-platform layer): Google Ads' ad-review workflow allows tracking-template configuration that displays a "verified" landing-domain to the reviewer while the click resolves to a different URL. Attackers exploit this by configuring the tracking template with the legitimate platform's domain (e.g.,
uniswap.org) while the actual click destination is the typosquatted phishing domain (e.g.,unlswap.org). Regional targeting + page-switching ("show benign content to Google's IP ranges, malicious content to victim IPs") is the documented evasion pattern (per[scamsniffermsdrainer2023],[cointelegraphmsdrainer2023]). The detection signal is a mismatch between the displayed-to-reviewer landing page and the click-resolved URL; Google's enforcement is reactive rather than at-deploy-time. - Pre-event (App Store layer): Cyble Research documents the canonical Play Store-side fingerprint — Median-framework WebView wrappers + embedded malicious URLs in privacy-policy text + previously-benign / compromised developer accounts repurposed for distribution. Apple App Store has parallel cases though less systematically documented at v0.1. The detection pipeline (static analysis of the bundle's WebView load URLs against known-bad lists) is well-characterised but operationally fails — apps slip through review and are typically removed only after community-reporting volume crosses a takedown threshold.
- At-event (UX-layer signal): the fake-DEX clone-frontend's
approve/setApprovalForAll/ permit-signature solicitation produces a wallet pre-trade simulation surface that can be intercepted by MetaMask, Rabby, Phantom, and OKX Wallet's threat-feed integrations. ScamSniffer's per-domain block lists, GoPlus's malicious-address feeds, and Wallet Guard's database are the operative threat-feeds. The block-rate varies by wallet vendor and threat-feed subscription; user-side dismissal of warnings under FOMO conditions or under attacker-applied time pressure ("airdrop ends in 10 minutes") remains the dominant residual failure mode. - At-event (on-chain layer): the fake-DEX clone-frontend's spender contracts produce calibratable per-cluster inflow signatures (per
[checkpoint2023drainers]'s spender-address fingerprinting). Once a campaign URL is associated with a known-bad spender, retroactive cohort attribution is mature. The per-cluster-inflow signal is also the basis for ad-platform-side enforcement when the threat-feed is consumed by the ad platform — but as of v0.1 cutoff, Google Ads / X Ads do not consume on-chain spender-cluster threat feeds at machine speed. - Post-event: the public-record forensic surface combined ScamSniffer's per-incident reconstruction, SlowMist's MistTrack stolen-funds analysis, ZachXBT's per-victim threads, Lookonchain's flow tracing, and SEAL Threat Intel's malicious-advertisement-URL block lists. The accountability chain is bifurcated: the ad platform (Google, X, Apple, Google Play, Telegram) faces only soft public-pressure response (Hayden Adams's July 2025 statement; ZachXBT's recurring escalations) without per-incident regulatory action; the kit-vendor (PhishLab / Pakulichev / successor cohorts) faces no public-record law-enforcement attribution at v0.1 cutoff. Per-victim recovery is rare; the forfeitable fund flows route through Tornado Cash / Railgun / cross-chain-bridge laundering (see OAK-T7.001 / T7.003).
What this example tells contributors writing future Technique pages
- Distribution surface is structurally separable from the on-chain extraction primitive. Future T4.x worked examples should record the distribution surface (Google Ads paid result; X promoted post; Telegram-bot funnel; App Store wrapper; legitimate-frontend compromise via DNS / supply-chain) as a discrete dimension separately from the on-chain extraction primitive (permit / approve / setApprovalForAll). The kit-substrate (Inferno / Angel / MS Drainer / PhishLab / AngelFerno) is durable across distribution surfaces; OAK-G02 continuity holds at the kit level. Cohort modelling should record both axes.
- Ad-platform-side enforcement is the load-bearing mitigation surface for the fake-DEX class. Detection at the threat-intel-aggregator layer is mature (ScamSniffer, SlowMist, GoPlus, Cyble, Group-IB, SEAL); the binding constraint is the ad-platform takedown pipeline. Future T4.x mitigation work should focus on (a) automated threat-feed consumption by Google Ads / X / Apple / Google Play / Telegram, (b) ad-platform tracking-template-misuse prevention, (c) regional-targeting / page-switching detection at ad-review time, and (d) standing per-platform threat-model communication (the Uniswap, PancakeSwap, Curve, Lido, Stargate, Raydium, Orbiter, Radiant teams cumulatively spend significant effort on "we don't have a mobile app / we don't run paid ads" disclaimers — these belong in a machine-readable platform-canonical-surface registry, not in scattered tweet-and-blog responses).
- The legitimate-platform side of the cohort is structurally passive. Unlike T4.002 where the affected platform's security team owns the incident response, fake-DEX clone-frontend victims have no platform-side post-mortem to anchor on. Future cohort cases should anchor on the threat-intel-aggregator layer (ScamSniffer, SlowMist, Cyble, Group-IB) as the primary source rather than expecting per-incident victim-platform reconstruction. The accountability gap is structurally informative for the v0.x Mitigations work and should be recorded as a defender-side observation rather than a citation gap.
- Mobile-app fake-DEX wrappers are a structurally distinct sub-surface. The seed-phrase-import vector (rather than the on-chain
approve/ permit vector) is the load-bearing mechanism. The realised loss shape is therefore closer to T11.x (Cold-storage seed-phrase exfiltration) than to T4.001 (Permit2 misuse) at the on-chain extraction layer; the distribution layer is fake-DEX-class, but the extraction primitive is seed-phrase capture. Future contributors should record the cross-Tactic chain (T4.x distribution → T11.x extraction) rather than collapsing both to a single Technique. - Per-cluster-inflow fingerprinting is the most durable cohort-attribution signal. Across the 2023–2026 window the kit substrate (Inferno, Angel, MS Drainer, AngelFerno, PhishLab) is more durable than per-campaign domain churn or per-affiliate distribution-surface choice. Future T4.x cohort work should anchor the attribution claim on per-cluster spender fingerprints rather than per-campaign URL lists; the URL list is a real-time block-feed input but the cluster fingerprint is the cohort-stable identifier.
Public references
[scamsniffermsdrainer2023](proposed) — ScamSniffer December 2023 MS Drainer cohort write-up: $59M / 63,210 victims / 10,000+ phishing websites / Google + X paid-ad distribution. Original ScamSniffer-Drops blog mirror: https://drops.scamsniffer.io/scam-sniffer-2024-web3-phishing-attacks-wallet-drainers-drain-494-million/[bleepingmsdrainer2023](proposed) — BleepingComputer coverage of MS Drainer Twitter ad push: https://www.bleepingcomputer.com/news/security/crypto-drainer-steals-59-million-from-63k-people-in-twitter-ad-push/[cointelegraphmsdrainer2023](proposed) — Cointelegraph MS Drainer Google Ads campaign coverage including the tracking-template-misuse and regional-targeting evasion details: https://cointelegraph.com/news/ms-drainer-scammers-used-google-ads-swipe-59-million-crypto-scam-sniffer[infosecuritymsdrainer2023](proposed) — Infosecurity Magazine secondary coverage of MS Drainer $59M: https://www.infosecurity-magazine.com/news/crypto-drainer-steals-59m-google-x/[scamsniffer2024annualreport](proposed) — ScamSniffer 2024 Annual Crypto Phishing Report: $494M wallet-drainer ecosystem total, 67% YoY increase, 332,000 victim addresses, paid-traffic distribution sub-classification. https://drops.scamsniffer.io/scam-sniffer-2024-web3-phishing-attacks-wallet-drainers-drain-494-million/[cryptonewsuniswap12m2025](proposed) — crypto.news 2025-07 coverage of $1.23M Uniswap fake-clone Google Ads loss: https://crypto.news/defi-loses-1-2m-fake-uniswap-site-phishing-scams-flood-google-ads/[protosuniswap2025](proposed) — Protos coverage of the same incident with Hayden Adams's "ad economy needs to go" public response: https://protos.com/fake-uniswap-phishing-ad-on-google-steals-traders-life-savings/[gateuniswap2025](proposed) — Gate News reconstruction of the Polymarket-using DeFi user's loss to a Google Ads fake-Uniswap result: https://www.gate.com/news/detail/18941977[cyblecryptophishingapps2024](proposed) — Cyble Research and Intelligence Labs cohort write-up: 20+ counterfeit Android apps impersonating PancakeSwap, SushiSwap, Raydium, Hyperliquid, others; 50+ phishing-domain infrastructure; Median-framework WebView wrapping. https://cyble.com/blog/crypto-phishing-applications-on-the-play-store/[hackreadgoogleplaypishing2024](proposed) — Hackread secondary coverage of the Cyble Play Store cohort: https://hackread.com/malicious-apps-google-play-users-for-seed-phrases/[techradarcryptoplaystore2024](proposed) — TechRadar coverage of the 22+ Play Store crypto-wallet-phishing apps takedown: https://www.techradar.com/pro/security/stop-using-these-22-android-crypto-and-wallet-apps-asap-or-you-risk-losing-all-your-cryptocurrency[groupibinferno2023](proposed) — Group-IB Inferno Drainer technical analysis: kit architecture, affiliate model, X / Discord / paid-ad distribution: https://www.group-ib.com/blog/inferno-drainer/[infosecurityinfernospoof2024](proposed) — Infosecurity Magazine coverage of Inferno Drainer 2024 comeback (~$80M+, 100+ spoofed brands): https://www.infosecurity-magazine.com/news/inferno-drainer-spoofs-100-crypto/[kasperskytelegram2025](proposed) — Kaspersky 2025 Telegram-scam retrospective documenting the 2,000% surge in phishing-bot volume late 2024: https://www.kaspersky.com/blog/phishing-and-scam-in-telegram-2025/54090/[bleepingtelegrambots2024](proposed) — BleepingComputer coverage of Telegram phishing bots impersonating wallet-verification services: https://www.bleepingcomputer.com/news/security/x-users-fed-up-with-constant-stream-of-malicious-crypto-ads/[cointelegraphgooglephishing2024](proposed) — Cointelegraph aggregate Google Ads crypto-phishing data ($4M+): https://cointelegraph.com/news/google-ads-data-4m-stolen-through-crypto-phishing-urls[checkpoint2023drainers]— Check Point Research drainer-cluster fingerprinting (existing incitations.bib).[slowmist2024report]— SlowMist 2024 Blockchain Security & AML Report (existing incitations.bib).[chainalysis2025rug]— broader 2025 cohort retrospective (existing incitations.bib).
Discussion
The fake-DEX clone-frontend cohort is the highest-volume paid-traffic-distributed phishing class in the 2023–2026 wallet-drainer category. T4.001 / T4.002 / T4.004 / T4.005 each capture adjacent failure modes but none captures the paid-ad-distribution-of-counterfeit-frontend class cleanly; the cohort anchors T4.008 — Fake-DEX Clone-Frontend Phishing (promoted from TAXONOMY-GAPS to canonical emerging-maturity Technique at v0.x).
The structural distinction matters because the detection surface and the mitigation surface diverge across T4.002 and the proposed T4.x:
- T4.002 mitigations rely on legitimate-platform-side infrastructure hardening (registrar lock, DNSSEC, ENS+IPFS pinning, supply-chain SRI, BGP route monitoring) — the failure mode is at the legitimate platform's substrate.
- T4.x (proposed) mitigations rely on ad-platform-side enforcement (Google Ads tracking-template-misuse prevention; X promoted-post review; App Store / Play Store binary review; Telegram bot / channel takedown) — the failure mode is at the legitimate ad-platform's substrate, while the legitimate target platform is structurally passive.
The detection-tooling cohort (ScamSniffer, SlowMist, GoPlus, Cyble, Group-IB, SEAL Threat Intel, Wallet Guard) maps imperfectly onto the OAK Technique split at v0.1 because the vendor categories collapse T4.001 / T4.002 / T4.004 / T4.005 / T4.x under labels like "wallet drainer" or "phishing campaign." Defender-tooling alignment with OAK would benefit from the explicit T4.x split because the operational mitigation pipelines diverge — the legitimate-platform-security and the ad-platform-trust-and-safety teams are organisationally distinct and in many cases work for different companies.
For OAK's broader cohort coverage, this case + the Inferno Drainer service-level write-up (examples/2024-10-inferno-drainer-handover.md) + the EIP-7702 CrimeEnjoyor cohort (examples/2025-05-eip7702-crimeenjoyor-delegation-phishing-cohort.md) collectively establish that the wallet-drainer category is structurally diverse at the distribution-surface layer while remaining structurally consistent at the kit-substrate and on-chain-extraction-primitive layers. The v0.x cohort priority is the distribution-surface dimension — the kit and extraction layers are well-covered by existing T4.001 / T4.004 / T4.005 / T13.004 work.