Minted to Empty
This one was over before the client finished her coffee. A “free companion mint” hosted on Pelliron Universal ↗ asked her to sign a single approval. Ninety seconds later the drainer had swept two chains. When she reached us, the wallet was bare — but the cash-out had not finished, and that gap is where we work.
Last Known Position
Priya is thirty-four, a motion designer in Toronto who had been minting art for two years. She knew her way around a wallet. The trap was not technical naivety — it was a compromised Discord. A moderator account she trusted posted a surprise “holder companion drop,” linking to Pelliron Universal, a platform dressed to look like the marketplace she used daily, on a domain one character off the real one.
Pelliron asked her to connect and claim. The popup did not ask her to buy anything. It asked her to sign.
Point of No Return
Buried in the request was a setApprovalForAll — a blanket permission letting an unknown contract move every token in her wallet. She approved it the way most people approve a cookie banner. The drainer fired at once, sweeping her ETH-chain assets and then bridging to clear her Polygon holdings on the same authorization.
It never charged me anything. That is what fooled me. Free things do not feel like theft until the wallet is empty.
Recovery Track
Revoke before chasing
The moment Priya reached us we walked her through revoking the malicious approval and moving the two assets the drainer had missed into a clean wallet. Stop the bleed before tracing what is gone.
Identify the kit
The contract signature matched a drainer-as-a-service template we had catalogued from other Pelliron Universal victims. A known kit means known cash-out behaviour.
Track both chains to the bridge
We followed the ETH-chain sweep and the Polygon sweep separately to the bridge that consolidated them, then on to the laundering wallets the operators favour.
Tag the centralized exit
A meaningful slice was sent to a centralized exchange to cash out. We mapped that deposit address to Priya’s stolen tokens and built a freeze request with full chain provenance.
Freeze, verify, return
The exchange froze the deposit pending verification. After proof of ownership, the seized portion came back — partial, because the rest dispersed through self-hosted wallets we could trace but not seize.
CAD $33,500 of $71,200 returned. One approval did the damage; disciplined revocation and a fast freeze recovered everything that reached an exchange.
Warning Lights
- A “free” mint that asks you to sign setApprovalForAll is a drainer — claiming never needs blanket token access.
- Links posted by a Discord moderator are not safe; server takeovers are routine.
- Read the signature request, not the dollar amount — the danger is the permission, not the gas.
- A domain one character off the real marketplace is a clone, lock icon and all.
- Surprise “holder-only” drops manufacture the urgency that stops you checking the contract.
Signed something you should not have?
Revoke first, then send us the wallet and the transaction. We will trace where the drainer took it.
Open a Case