Join our Newsletter — 33% off our NHI Course
Home› FAQ› Threats, Abuse & Incident Response› What are the signs that a crypto drainer…
Threats, Abuse & Incident Response

What are the signs that a crypto drainer is also running on the endpoint?

← Back to all FAQ
By NHI Mgmt Group Editorial Team Updated October 11, 2026 Domain: Threats, Abuse & Incident Response

Look for script-based payload execution, unusual reads of secret-bearing files, and outbound HTTPS posts to webhook-style endpoints. When those signals appear alongside suspicious wallet activity, the campaign is likely collecting data locally as well as abusing on-chain permissions.

How to tell whether the drainer is running locally, not just draining the wallet

A purely on-chain drain can succeed without leaving much endpoint evidence, so the giveaway is a local execution pattern that lines up with the wallet activity. Scripted payloads, unexpected file reads, and outbound requests to a webhook or command endpoint suggest the attacker is harvesting data on the machine before, during, or after transaction abuse.

The key distinction is timing and coordination. If the browser, shell, or another script host is active around the same window as suspicious approvals or transfers, the endpoint is likely part of the kill chain rather than just a passive victim.

Look for process trees that make little business sense, temporary scripts dropped into user-writable locations, and browser or document activity that suddenly touches secret-bearing files, wallet extensions, seed material, configuration caches, or token stores.

Endpoint clues that point to local collection

Endpoint collection usually leaves a small but recognizable footprint. A drainer that is also running locally often reads from files and directories that contain authentication material, then sends the output onward in a compact request pattern instead of large exfiltration bursts.

Search for script engines, shell interpreters, JavaScript execution outside normal application paths, and suspicious child processes launched from office documents, browsers, archive handlers, or installers. The more the activity resembles a short-lived grab-and-forward routine, the more likely the endpoint is doing more than supporting the blockchain transaction.

Network telemetry matters here too. Repeated HTTPS posts to webhook-style destinations, paste-style endpoints, or newly seen collector URLs are a strong sign that the local host is packaging stolen data for remote use. That is especially suspicious when the traffic coincides with wallet approvals, extension access, or unexpected signing prompts.

Why these signals matter for defenders

These indicators point to a blended intrusion pattern, not a single event. The attacker is often using the endpoint to discover what can be stolen, while the wallet or browser session provides the authority needed to complete the fraud. That makes containment more urgent because the same host may expose secrets, sessions, and transaction intent.

Once local collection is confirmed, the question shifts from “Was a wallet drained?” to “What else was captured from this machine?” That can include browser cookies, cloud session material, wallet recovery data, password stores, API keys, or other secret-bearing files that broaden the blast radius beyond the blockchain loss.

For teams that monitor endpoint activity, the useful pattern is not any single indicator in isolation. It is the combination of script execution, file access to secret locations, and outbound posting to a command or webhook endpoint, especially when that sequence appears near wallet manipulation.

Risk and Threat Considerations

Local drainers raise the risk from a single wallet event to a broader endpoint compromise. The same execution chain that steals wallet-related data can also expose browser sessions, developer secrets, and other material that supports follow-on access or repeat theft.

Failure mechanism: The attacker abuses local script execution to read sensitive files and then forwards the harvested material over normal-looking HTTPS traffic, which can blend into routine browser or application communications.

Impact: Defenders may miss the local compromise until after approvals or transfers occur, at which point credential rotation, wallet review, and endpoint cleanup all become necessary.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-53 Rev 5 sets the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
MITRE ATT&CKT1059 — Command and Scripting InterpreterScript-based payload execution is a core local execution pattern in this endpoint-abuse scenario.
T1119 — Automated CollectionReading secret-bearing files and packaging them for export matches automated local collection behavior.
T1041 — Exfiltration Over C2 ChannelOutbound HTTPS posts to webhook-style endpoints indicate data being sent to attacker-controlled infrastructure.
Recommendation — Map script execution to T1059 and hunt for suspicious interpreter chains and child-process spawning. Treat repeated secret-file reads as collection activity and search for staged harvesting workflows. Trace webhook-like HTTPS destinations as C2-linked exfiltration and contain the host quickly.
NIST SP 800-53 Rev 5AU-6 — Audit Review, Analysis, and ReportingCorrelating process, file, and network events is essential to confirm local drainer activity.
SI-4 — System MonitoringContinuous monitoring is needed to detect script execution, secret reads, and suspicious webhook posts.
Recommendation — Correlate endpoint and proxy logs to reconstruct the local steal-and-send sequence. Alert on unusual interpreter activity, secret-file access, and suspicious outbound HTTPS patterns.

Practitioner Guidance

What to verify: Correlate process execution, file access, and outbound requests in the same time window, then confirm whether the accessed paths include browser profile data, wallet artifacts, secrets, or other sensitive local stores.

Decision rule: If you can tie wallet abuse to script execution plus secret-file access, treat the host as compromised, not merely noisy, and prioritize isolation before deeper forensics.

What good looks like: You should be able to explain which process touched which sensitive file, which destination received the data, and whether the activity was user-initiated, extension-driven, or injected by another process.

Practitioner takeaway: A drainer that runs locally is not just stealing value, it is using the endpoint as part of the theft workflow, so containment must focus on the host, the wallet, and any exposed secrets together.

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.

NHIMG Editorial Note
Reviewed and updated by the NHIMG editorial team on October 11, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org