Top

Singapore police suggest hardware wallets to combat malware

Policy & Regulation·February 02, 2024, 3:12 AM

The Singapore Police Force (SPF) and the Cyber Security Agency of Singapore (CSA) have jointly issued an advisory to raise awareness about the escalating use of cryptocurrency drainers in cyberattacks.

 

The advisory aims to inform citizens about the threat and provide recommendations to protect against such attacks, with a specific emphasis on utilizing hardware wallets for enhanced security. Cryptocurrency drainers represent a form of malware that specifically targets crypto wallets. These malicious tools are often employed in phishing attacks to illicitly extract funds from users' wallets without proper authorization.

https://asset.coinness.com/en/news/38365430f808a1c538e2831346c3e8d0.webp
Photo by Junrui Wu on Unsplash

Drainer-as-a-service threat

Of particular concern are commercial crypto draining kits, which empower less experienced cyber-criminals with sophisticated malware at no upfront costs. Operating on a drainer-as-a-service (DaaS) model, attackers share a predetermined percentage of the stolen funds with the service provider.

 

The SPF and CSA underscored that crypto-drainer-related attacks typically originate from phishing campaigns. These campaigns commonly involve infiltrating verified social media accounts or dispatching fraudulent emails to users from compromised databases of major service providers.

 

Unsuspecting victims who click on phishing links are redirected to counterfeit trading websites that prompt them to connect their Web3 wallets. Subsequently, a malicious smart contract is injected into the victim's system, enabling hackers to withdraw funds without additional authorization.

 

MS Drainer and Inferno Drainer

While no such attacks have been reported in Singapore to date specifically, the advisory acknowledges the rising recognition of this threat among hackers. Notably, an off-the-shelf crypto drainer called MS Drainer contributed to hackers stealing $59 million worth of cryptocurrency in 2023.

 

Last month, Singapore-based cyber security firm Group-IB produced a report concerning the Inferno Drainer operation. According to the company’s research, the malware operation led to the theft of $80 million in digital assets globally, until the developers behind it shut it down last November.

 

In December, the Pink Drainer hacking group notched up another victim, to the tune of $4.4 million in LINK tokens. Last week blockchain security firm Scam Sniffer reported that $10 million in digital assets had been stolen in phishing-related incidents over the course of just five days.

 

Hardware wallets

To counteract these threats, Singapore authorities recommend the use of hardware wallets as a security measure against wallet drainer attacks. Additionally, the advisory instructs crypto investors to conduct thorough research before engaging with cryptocurrency services or platforms. Singaporeans are encouraged to report any suspicious incidents related to crypto drainers or phishing attacks to both relevant authorities and crypto service providers.

 

In the event of a security breach, victims are urged to revoke any suspicious token approvals and promptly transfer their remaining funds to a different, secure wallet address to prevent further losses. This proactive approach aims to empower individuals with the knowledge and tools needed to navigate the risks associated with crypto drainers and foster cybersecurity awareness within the cryptocurrency ecosystem.

 

As the threat landscape evolves relative to digital assets, this advisory serves as a valuable resource to educate citizens about the risks posed by crypto drainers.

 

 

More to Read
View All
Web3 & Enterprise·

Jun 16, 2025

KuCoin Thailand moves to full platform launch

Seychelles-headquartered global crypto exchange KuCoin has announced the full launch of its affiliate in Thailand. KuCoin Thailand was first presented by KuCoin back in April. The affiliate company emerged through a rebranding of local digital asset exchange, ERX. The renamed entity continues to be operated by ERX Company Ltd., while benefiting as a KuCoin affiliate from its global market presence and global exchange infrastructure.Photo by Bradley Prentice on UnsplashERX platform users onboardedSince that initial announcement, the exchange has been operated by onboarding users on an invite-only basis. All of the original ERX platform users have been ported across to KuCoin Thailand. In a statement published to its website on June 13, KuCoin Thailand pointed out that it is moving on from that invite-only phase to fully launch the platform.  It asserted that the platform is fully licensed by Thailand’s Securities and Exchange Commission (SEC) and it has now proceeded to full launch with no further access restrictions. In tandem with the full public launch of the platform, the company indicated that it was running a special rewards initiative with a prize pool of one million Thai Baht ($30,845) and introducing a new brand mascot named “Kuku.” In a press release, KuCoin claimed that “this marks the first fully regulated local digital asset exchange under KuCoin's brand,” contributing towards the company’s goal “to build fast, secure, and user-friendly infrastructure for crypto users” globally. Strengthening KuCoin’s presence in Southeast AsiaKuCoin CEO BC Wong described the launch as “a significant milestone in [the company’s] global compliance journey.” He added: “From being the first global exchange to register with India's FIU to now launching the first local compliant platform in Thailand, this marks a significant step toward strengthening our presence in the fast-growing markets of South East Asia.” In discussion with Cointelegraph, the KuCoin CEO provided an insight into how the company is approaching global growth while focusing on local market considerations. He stated: “While KuCoin Global supports a wide range of products for international users, we plan to expand locally in line with regulations and market demand.” Wong confirmed that the newly branded entity facilitates crypto spot trading for its users, with Thai Baht-based on and off ramps. Regulator & police enforcementThailand’s SEC moved to block five cryptocurrency platforms from accessing investors resident in Thailand late last month. The exchanges, OKX, Bybit, CoinEx, XT.com and 1000X.Live, were deemed to have been offering their services in Thailand on an unlicensed and unauthorized basis. In addition to blocking access, criminal complaints have been filed against all five exchanges. Thai police have also been busy recently with crypto-related enforcement. Last month, a Vietnamese woman was arrested on the basis of her alleged involvement in a crypto-related scam that saw 2,600 victims lose a total of $300 million. On June 12, Bangkok-based news platform Khaosod English reported that a Chinese man had been arrested in connection with a $6 million Bitcoin fraud case.

news
Policy & Regulation·

Oct 29, 2025

EU bans Ruble-backed stablecoin A7A5 in latest round of Russia sanctions

The European Council has banned all transactions within the European Union (EU) involving the Russian Ruble-backed stablecoin A7A5, according to a press release published Oct. 23. The prohibition targets the stablecoin itself, its developer, its Kyrgyzstan-based issuer, and the operator of a platform that facilitates major A7A5 trades. The package also takes aim at Russian crypto exchanges.Photo by Christian Lue on UnsplashAdditional banking restrictionsThis measure is part of a broader set of economic sanctions against sectors the EU stated assist the Russian invasion of Ukraine, including energy, finance, and defense industries. As part of this financial clampdown, the EU will also impose a ban on five additional Russian lenders starting Nov. 12. One of those lenders, Alfa-Bank, recently began offering Bitcoin buying and selling services, according to an X post by journalist Pete Rizzo. The European body said the new crypto measures address Russia’s increasing use of digital assets to circumvent existing sanctions. Russian banks were cut off from the SWIFT international payment system in early 2022, following the onset of the Russo-Ukrainian war. Reports of Russia using cryptocurrency to finance malign activities have surfaced previously. Earlier this month, Sławomir Cenckiewicz, the head of the Polish National Security Bureau (BBN), told the Financial Times that Russia has employed crypto to finance attacks on EU countries. Cenckiewicz said that a network of agents recruited by Russia’s GRU military intelligence agency and uncovered in Poland in 2023 had been substantially funded with cryptocurrency. Reflecting this concern, lawmakers in Poland’s lower house approved a bill in September to strengthen national crypto oversight, a move also expected to help curb Russian funding channels. Cenckiewicz noted that Polish intelligence agencies are closely monitoring the legislation to prevent loopholes that allow foreign actors to support agents using digital assets. Russia’s evolving crypto policyThe EU’s action comes as Russia itself is attempting to refine its own cryptocurrency rules. According to the Moscow Times, Russia's central bank wants to limit cryptocurrency use strictly to cross-border payments within an experimental legal regime (ELR). The institution continues to reject recognition of cryptocurrency as a legal means of payment and has advocated banning its use for domestic payments and retail investment, while permitting trading only for high-net-worth individuals through licensed platforms. Russia’s finance ministry has expressed a more flexible view, pointing to the scale of crypto adoption among the public. Earlier this year, the central bank estimated that domestic crypto transactions exceeded 1 trillion rubles (about $12.4 billion) per month, and that as of March, wallets linked to Russian users held roughly 827 billion rubles (about $10.2 billion). The finance ministry and the central bank have agreed to tighten supervision of the crypto market, with officials expecting to finalize the new framework before the end of the year. 

news
Policy & Regulation·

Apr 07, 2023

Korean Crypto Exchange Group Installs Separate Division to Prevent Money Laundering

Korean Crypto Exchange Group Installs Separate Division to Prevent Money LaunderingThe Digital Asset Exchange Alliance (DAXA), a group of five major Korean crypto exchanges, announced yesterday that it has installed a division to prevent money laundering.©Pexels/Anna TarazevichAML division’s roleThe anti-money laundering (AML) division will devise suspicious transaction report types, create guidelines to assess risks at virtual asset service providers, and hold various seminars.With the new AML division installed, DAXA now has five divisions, the other four of which are responsible for trading support, market monitoring, compliance monitoring, and education.Improving listing and delisting guidelinesDAXA also plans to improve listing and delisting guidelines that exchanges can share.DAXA vice chairman Kim Jae-jin said long-term efforts are required to build a healthy virtual asset ecosystem, calling for exchanges’ stronger voluntary compliance.

news
Loading