Back to blog
dns Published: AEU DNS Newsroom

DNS Records Let Wallet Drainer Switch Attack Hosts Fast

DNS Records Let Wallet Drainer Switch Attack Hosts Fast
AI-generated image

DNS records let the Noir wallet drainer redirect fake crypto pages to replacement hosts, while deceptive spending approvals enable theft without passwords.

DNS records let a cryptocurrency wallet drainer redirect existing scam pages to replacement attack infrastructure without rebuilding them, according to an Infoblox investigation published October 9, 2026. The kit, which calls itself Noir, combines this adaptable delivery system with deceptive wallet permissions: victims can lose assets without revealing a password, private key or recovery phrase.

Infoblox discovered the kit while investigating a fake cryptocurrency voting page. Its findings show how DNS, the Domain Name System normally used to look up internet addresses, can also distribute instructions for malicious software. Noir uses a TXT record, a DNS entry containing text, to identify its active pool host, the website delivering the attack interface and connecting visitors to attacker-operated services. The researchers observed these hosts on Cloudflare Pages.

Persistent lures, replaceable attack hosts

The separation is central to the design. A fake vote, token giveaway or eligibility page remains the entry point, while the TXT record tells its loader, the code that starts the attack software, where to go next. If a pool host disappears or is blocked, changing the record can redirect already-deployed lures. DNS becomes a control plane, a channel for distributing operational instructions, rather than just an address lookup service.

In one sample, a page on listchoiseopenleaderboardseptember[.]netlify[.]app loaded k1xfns97l5w.5cgsbfh2.js. That JavaScript file, browser-executed code, held decimal character codes that were decoded and run to initialize the loader. It then requested the TXT record at _r.noir[.]black through three DNS-over-HTTPS (DoH) services simultaneously. DoH encrypts DNS requests inside HTTPS, the secure connection technology used by websites. The loader accepted the first valid answer.

The observed services were Google Public DNS and two Cloudflare endpoints, including direct access to 1.1.1.1. One returned pool domain was render-984.pages[.]dev. At the same time, the loader contacted an application programming interface (API), a software request endpoint, on noir[.]black for a configuration called “road.” This could supply a separately resolved fallback pool when direct DoH failed or was blocked. Comments described running both requests together as a way to reduce waiting time.

The returned configuration determined whether the malicious interface loaded directly into the lure or inside a transparent frame covering the entire browser view, making it appear part of the page the visitor opened. A short script from the pool loaded the engine through index.js and assembled deployment-specific settings, including a WalletConnect project ID. WalletConnect is a system for connecting wallets to applications; the identifier associates the connection with a project.

The loader retained the pool hostname in browser storage for 60 seconds, matching the TXT record's time to live (TTL), the period a DNS answer may be cached. Its comments said a previous, longer storage period kept sending visitors to dead hosts after the DNS record changed. If a host failed a readiness check, the loader deleted the stored value and tried again, prioritizing the server-provided fallback.

The dangerous step is permission, not connection alone

Initially, connecting a wallet shares its public address. That alone is not enough to steal funds. Noir sends that address, the blockchain network, the shared transaction system holding the assets, and an estimated portfolio value to its backend, the attacker-operated service handling the attack. The backend examines the holdings and returns a sequence tailored to that wallet.

The trap depends on the difference between sending an asset and authorizing someone else to spend it. Legitimate decentralized applications, services that interact with blockchain systems, use spending approvals and typed-data signatures, signed permissions over structured information. Noir exploits those same mechanisms. Depending on wallet capabilities, it can request a gasless signature, which does not require the user to pay a network transaction fee, a combined confirmation covering several approvals, or separate approval transactions.

A signature can seem less serious than a payment because the request does not itself visibly transfer the assets. Each captured signature or approval goes immediately to the backend; Noir need not wait for the victim to finish every prompt. An attacker-side relayer, a service submitting transactions, can then use the permission to move funds. The wallet may show the earlier authorization without showing the eventual theft as a straightforward outgoing transaction initiated by that wallet.

After the interaction, the kit disconnects the WalletConnect session, removing the malicious application from the wallet's connected-applications list. That disappearance is not evidence that a spending permission has been revoked. Together, the familiar connection flow, less alarming permission requests, attacker-side transfers and session cleanup can obscure what happened.

Code comments reveal maintenance and shared infrastructure

Infoblox found unusually extensive English-language comments recording design choices, dated defects, support reports and fixes. They covered dead hosts after TXT changes, a wallet prompt revealing the underlying site's origin, blank pages caused by incorrect framing and a requirement to record why a flow closed. Notes referred to a founder, distinguished visitors from operator pages and used numbered fix lists. A debugging mode offered an on-screen console and a way for operators to copy a diagnostic trace from a victim's phone.

Infoblox considers AI-assisted development likely, citing the verbose explanations and reasoning about edge cases. That remains an assessment, not proof: a human could have written the comments. The code and infrastructure also suggest a shared service rather than a single operator. Operator-specific identifiers connect lures to the backend, while common infrastructure and a shared wallet-connection project identifier help researchers group related activity. Some comments appear to address service tickets.

Observed lures included fake community votes impersonating CoinMarketCap, DexScreener and OKX; claim or airdrop pages impersonating Uniswap, Lido, Hyperliquid, Morpho, Ondo, LayerZero and MegaETH; and decentralized-exchange or swap clones. Infoblox also recorded ETH eligibility checks, desktop-browser requirement pages and spoofs of Polymarket, SpaceX/Ondo tokenized-RWA, Grass, Venice and FoxFi.

Encrypted DNS is not a safety verdict

Infoblox places Noir alongside earlier DNS control channels: Detour Dog used TXT records for affiliate redirects and information-stealer distribution, while Decoy Dog used DNS for a sophisticated remote-access system.

Terms explained

DNS
The Domain Name System helps software find internet destinations by looking up information associated with domain names.
TXT record
A DNS entry that stores text, which software can read as information or instructions.
DNS-over-HTTPS (DoH)
A method of encrypting DNS lookups using the same secure connection technology as HTTPS websites.
wallet drainer
Malicious software that tricks cryptocurrency wallet owners into granting access that enables asset theft.
time to live (TTL)
The length of time a DNS answer may be stored before it should be requested again.
relayer
A service that submits blockchain transactions, potentially using permissions someone previously granted.

How to protect yourself

  1. Open voting and token-claim pages through a project's official website or a saved bookmark, rather than a message or advertisement.
  2. Reject an unexpected wallet signature or spending request, even if it says no transaction fee is required.
  3. Before confirming, read which assets an application may spend and how much access it requests; cancel if the request does not match your intended action.
  4. If you connected to a suspicious page, use your wallet provider's official instructions to review and revoke spending permissions, not just disconnect the application.
  5. Never enter your wallet recovery phrase into a voting, giveaway or eligibility-check page.
Get private, encrypted DNS