A long-dormant Ethereum wallet was drained of 59 ETH (~$146.8K) roughly a month ago, with on-chain trackers pointing to the "CryptoBillis" or "Ledger Drainer" phishing kit.
The victim had moved funds into a new wallet after more than four years of inactivity. The original address sat untouched for eight years and survived that stretch intact, but the recent interaction was the trigger: signing a malicious permit or approval transaction handed the drainer the right to sweep the balance.
Why it matters
This is the canonical shape of a wallet-drainer loss. Old-school holders who held through multiple cycles, then revisited the space during the recent rally, are exactly the demographic these kits hunt. Eight years of cold-storage discipline means nothing once a single signature is signed against the wrong contract.
Market impact
The $146.8K theft sits inside a broader pattern of drainers siphoning low-six-figure ETH balances from returning users. Total flows tracked to "CryptoBillis" and the overlapping "Ledger Drainer" kits now run into the tens of millions of dollars, a reminder that even untouched ETH is only safe while the keys are.
Frequently asked questions
-
What is the CryptoBillis wallet drainer?
CryptoBillis (also tracked as "Ledger Drainer") is a phishing kit sold to scammers. It tricks victims into signing malicious approvals or permit signatures, which hand the attacker the right to sweep ETH and ERC-20 tokens from the victim's wallet.
-
How did an eight-year-old ETH wallet get drained?
The funds sat untouched for eight years and survived that stretch intact. The drain happened roughly a month ago, after the owner returned to the wallet and signed a transaction, likely a permit or approval tied to a malicious dApp, that gave the drainer permission to move the balance.
-
How much was lost in this incident?
On-chain screenshots show 59 ETH drained, worth roughly $146.8K at the time. The total cumulative haul across all CryptoBillis / Ledger Drainer victims runs into the tens of millions of dollars.
-
Can a long-dormant ETH wallet be safe?
Only while the keys stay cold. The moment a wallet signs any transaction, an open allowance, expired approval, or a single malicious signature can drain the balance. Length of inactivity does not protect against a fresh attack.
-
How can ETH holders avoid a drainer?
Use a hardware wallet, revoke unused approvals via tools like revoke.cash, simulate every transaction before signing, and treat any unfamiliar dApp or approval pop-up as hostile. Never sign permit messages from unverified sites.
Lookonchain