Infostealer Malware Explained: How Stolen Sessions Drain Crypto Accounts
Infostealers grab browser cookies, saved passwords, and wallet vaults in seconds. The full crypto kill chain, the 2025 takedowns, and the defenses that work.
On-chain Safety Education
Onchain Diary is an independent Web3 safety education site: 77 deep-dive articles and a 220-term glossary on crypto scams, smart contract security, and on-chain analysis. No jargon. No sign-up. No tools to install. Just the knowledge you need to stop getting rekt.
Guides, tutorials, and deep dives.
Infostealers grab browser cookies, saved passwords, and wallet vaults in seconds. The full crypto kill chain, the 2025 takedowns, and the defenses that work.
Your wallet was drained or your exchange account emptied. What you do in the next 24 hours decides whether the theft is survivable: triage the intrusion type, secure remaining assets in the right order, build the evidence package, and get freeze requests out before funds reach a mixer.
Real airdrop snapshots record on-chain state at a block height — no action from you, ever. Scam campaigns invert that mechanic with countdown timers and 'verify your wallet' pages riding real project announcements. How snapshots actually work, the deadline-pressure playbook, zombie campaigns that outlive their projects, and the rule that eligibility can always be checked without connecting a wallet.
Hardware wallets are sold as the safest way to store crypto — until the purchase itself becomes the attack. Here are the six scam patterns, real cases, and a buy-side checklist.
Fake wallet apps and malicious browser extensions pass app store review, carry five-star reviews, and harvest seed phrases from the first 'import' screen. How the distribution works, the four theft mechanisms hidden inside fake wallets, why store presence proves nothing, and the verification steps before trusting any wallet with funds.
Fake moderator DMs that install Windows malware, Telegram friends who slowly sell you a honeypot, airdrop emails from lookalike domains — how the social engineering playbook works at each step.
Reading is half. The other half is recall.
Every question is drawn strictly from the Yellow Paper's own text. No outside knowledge required — if you've read it, you can pass it.
Take the quiz → T-02Sixteen scenario questions sort you into one of sixteen security personas — hunter or prey — with a safety index and a shareable result card.
Find your type →A few terms to get you going — the full glossary has 220+.
Whether you're new to crypto or deep into DeFi, understanding how scams work is the best defense. Every guide here is free.
Start Reading →