Noir Wallet Drainer Uses DNS to Keep Fake Crypto Pages Working

Daniel Zimmermann
6 Min Read
A golden pen opens a wallet vault like a permission key
A signature can authorize token spending.

A fake cryptocurrency voting page led Infoblox researchers to a wallet-drainer kit that brands itself as Noir. Its trick is not to demand a recovery phrase: it turns a wallet interaction into permission for an attacker to spend tokens. The October 9 report also explains how deployed scam pages can keep working after their backend changes—by asking DNS for the current destination. [1]

The vote is the doorway; the permission is the loss

In the observed flow, connecting a wallet first reveals its public address. That step alone does not hand over funds. Noir’s backend then considers the address, network and portfolio to prepare requests for that particular wallet. The next prompt may be a signature, several bundled approvals or individual approval transactions.

This is where the meaning of the interaction changes. A visitor thinks about a vote, a reward or an eligibility check; the wallet request can instead authorize token spending. Keeping a private key secret does not make every signed request safe. MetaMask’s signature-phishing guidance explains how authorization signatures can be used to move tokens without a later, separate confirmation from the user. [3]

Infoblox found that Noir submits each captured signature or approval immediately. An attacker-side relayer can exercise the permission from its own infrastructure, rather than waiting for the visitor to finish the entire sequence. The important question is what a request permits, not whether the screen looks like an ordinary payment.

Infoblox diagram of the Noir wallet-permission flow and DNS backend lookup
Infoblox’s schematic: wallet connection, permission capture and attacker-side transfer, with DNS selecting the backend. Source: Infoblox Threat Intel. Open the image for the full-size diagram.

The source diagram separates the initial connection, permission capture and attacker-side transfer. It is a schematic of the kit’s logic, not evidence that every visitor or every wallet was drained instantly. Infoblox did not publish a victim count or total loss.

One DNS answer can redirect deployed lures

The other revealing discovery sits behind the page. Noir’s loader queries a TXT record at _r.noir[.]black through three DNS-over-HTTPS endpoints in parallel, using the first valid answer. That answer names the current backend pool; the researchers observed a host on Cloudflare Pages.

DNS normally helps software locate services. Here, a text record acts as live configuration. The scam page can stay where it is while the operator changes which pool it loads. A separate API request can supply a fallback pool, and the returned configuration selects an imported interface or a full-window frame.

The cache lasts 60 seconds. Comments in the shipped code explain that a longer cache had kept sending visitors to retired infrastructure. Noir also clears a failing cached host and retries. This is operational maintenance: removing one backend may interrupt the service without removing the lure pages that can obtain its replacement. It does not establish a compromise of Google’s or Cloudflare’s DNS services.

The kit leaves a developer’s repair notes behind

Infoblox’s researchers found comments about failed hosts after DNS rotation, an origin revealed in a wallet prompt, and pages going white when framed incorrectly. An operator can also collect a phone-side debug trace. Together with multiple lure themes and per-deployment configuration, these details point to a maintained service rather than one static fake page.

The researchers considered AI assistance likely because of the unusually explanatory comments. A human could have written them; the report does not prove that an AI system built Noir. The concrete finding is the working permission-and-routing architecture, regardless of how its author wrote the comments.

An empty connected-apps list is not a permission check

At the end of its flow, Noir disconnects the WalletConnect session. That removes a conspicuous entry from the wallet’s connected-applications list. It does not make that list a reliable inventory of previously granted spending authority.

If you only connected and did not authorize anything further, remove the connection through your wallet’s trusted controls. If you approved spending, inspect the relevant token, network and authorized contract using the wallet provider’s documented process. MetaMask distinguishes disconnection from revocation: existing token approvals remain until revoked, and revocation is an on-chain transaction with a network fee. [2]

Save the site address and relevant transaction hashes before investigating. Revoking a token allowance does not reverse a completed transfer or guarantee that every other signature-based authorization has disappeared. Use official wallet guidance for the specific request you signed, rather than a “recovery” service that asks for your seed phrase.

Our earlier fake xStocks and Pendle voting investigation describes the reward-to-permission lure. Noir adds a specific infrastructure lesson: a scam’s visible page, its current server and its spending authority can have different lifetimes.

The decisive boundary is authorization. A page can lose its backend and return with another one; a wallet can disconnect while a token approval remains. Judge the permission itself before signing.

References

  1. Infoblox Threat Intel. “When a Wallet Drainer Asks DNS Where to Go.” October 9, 2026. Noir investigation.
  2. MetaMask. “How to revoke smart contract allowances/token approvals.” Help Center, accessed October 9, 2026. Approval revocation.
  3. MetaMask. “Signature phishing.” Help Center, accessed October 9, 2026. Signature permissions.
Share This Article
With a strong background in consumer safety and fraud prevention, Daniel specializes in providing actionable tips and advice to users. His focus is on helping individuals understand the risks of interacting with fraudulent sites and services
Leave a Comment

AI Assistant

Hello! 👋 How can I help you today?