Independent research by Krishanu โ€” not affiliated with tronify.rent ยท verified active 2026-09-20 ยท view evidence โ†’
๐Ÿšจ Critical โ€” Actively Exploited

tronify.rent is a live TRON wallet drainer impersonating a real energy-rental brand

Independent research by Krishanu ยท Not affiliated with tronify.rent, Tronify Energy Solutions LLC, or any Tronify-branded service

Independent technical analysis of greenbid.js, a 150KB drainer payload that requests unlimited TRC-20 approvals and sweeps TRX to attacker-controlled addresses. Every claim below is backed by a live payload download, a live C&C query, and on-chain blockchain data โ€” not assumptions. Raw files and checksums are published alongside the reports.

150,274B
Payload size, SHA-256 verified
12
C&C endpoints extracted from live payload
7
Wallet providers targeted (verified array)
$32.5K+
Confirmed on-chain USDT theft, last 30 transfers
~25
Distinct victim wallets in that window
CRITICAL โ€” ACTIVELY EXPLOITED: On 2026-09-20 we retrieved the live payload, the live C&C configuration, and on-chain blockchain records for the attacker's own addresses. Those addresses currently hold real, unspent stolen USDT/TRX, and received USDT from roughly two dozen distinct wallets in the preceding ~3 weeks alone โ€” the most recent inbound theft dated the day before this report. This is confirmed, ongoing exploitation with on-chain financial proof, not just capability. See Indicators of Compromise and the Evidence section for raw artifacts and checksums.

๐Ÿ“š The Reports

Seven reports, written for different audiences, plus the raw evidence behind every claim.

01 ยท 5โ€“10 MIN READ

๐Ÿ“‹ Executive Summary

What happened, why it's dangerous, and what to do โ€” start here.

Everyone
02 ยท 15โ€“20 MIN READ

๐Ÿ”ง Technical Architecture

How the drainer is built: components, wallet detection, gas-funding, C&C protocol.

Researchers, developers
03 ยท 10โ€“15 MIN READ

โ›“๏ธ Attack Chain

Step-by-step exploitation timeline, plus a real, on-chain-verified example.

Full attack flow
04 ยท 20โ€“30 MIN READ

๐Ÿ”ฌ Code Analysis

Function-by-function breakdown of greenbid.js, verified against the live file.

Malware analysts
05 ยท 10โ€“15 MIN READ

๐Ÿ” Indicators of Compromise

Domains, hashes, YARA rules, live attacker addresses, and hunting queries.

SOC / threat hunters
06 ยท 15โ€“25 MIN READ

๐Ÿ›ก๏ธ Defense & Remediation

Emergency recovery steps for victims, plus long-term prevention guidance.

Victims, security teams
07 ยท 15โ€“25 MIN READ

๐Ÿ’ฐ Cost & Skill Analysis

Technical skill assessment, development cost breakdown, team composition, and OPSEC evaluation.

Researchers, intel analysts
RAW EVIDENCE

๐Ÿ—‚๏ธ Evidence Locker

The actual payload, live C&C responses, and on-chain data this analysis is built on โ€” with SHA-256 checksums for every file.

Verify it yourself

๐Ÿ“Š Key Findings Summary

1. Brand squatting, not a typo-squat: "Tronify" is a real TRON energy-rental brand reportedly integrated with Trust Wallet. tronify.rent borrows that brand's trust via an unusual .rent TLD rather than misspelling anything.
2. Malicious payload: tronify.rent injects greenbid.js (150,274 bytes) from lending.fhogu.pw, which automatically drains connected wallets.
3. Token approval exploitation: Calls TRC-20 increaseApproval() for an unlimited amount, then transfers 100% of approved balances to an attacker address loaded live from C&C.
4. Attacker-funded gas ("priming") โ€” new finding: if a victim holds USDT but too little TRX for fees, the attacker's backend sends ~15 TRX to unlock the wallet before draining it.
5. On-chain proof of theft: the live C&C's current attacker addresses hold real stolen USDT/TRX and received funds from ~25 distinct wallets in the last three weeks of visible history.
6. Multi-wallet targeting: Trust Wallet, TronLink, OKX Wallet, TokenPocket, Bitget, SafePal, and WalletConnect โ€” verified from the live payload's wallet array.
7. 12 C&C endpoints, including full client-side telemetry logging (/tron/client-log) beyond just "drain" events.
8. Irreversible theft: blockchain transactions are permanent; funds are effectively unrecoverable once transferred.

๐ŸŽฏ Quick Links by Audience

For Victims

Start with Defense & Remediation for emergency steps, then Executive Summary for context.

For Security Researchers

Technical Architecture โ†’ Code Analysis โ†’ IoCs โ†’ Raw Evidence.

For Wallet Providers

IoCs for detection, Defense for UX recommendations.

For Law Enforcement / Chain Analysts

IoCs for live attacker addresses and consolidation targets, Evidence for raw on-chain data.

โš ๏ธ Critical Indicators (copy into your security tools)

Domains to block
tronify.rent
lending.fhogu.pw
Payload signature
greenbid.js โ€” 150,274 bytes
SHA-256: 0f6d64472d6369a098f403db117b1285e79b0fdac79caaa639fc0e50e5bf4416

Live attacker addresses (dated 2026-09-20 โ€” will rotate, see IoCs for the durable on-chain pattern): tronSpender TV6n8cCLmX5mRCMMNvcE1K1i87Yo9Ys5rv ยท tronSweepAddress TLv3iSnZxWghEmadLDzuAK2p5GkAwg7tpJ

๐Ÿ“š Documentation Stats

ReportRead TimeStatus
Executive Summary5โ€“10 minUpdated w/ live data
Technical Architecture15โ€“20 minUpdated w/ live data
Attack Chain10โ€“15 minUpdated w/ live data
Code Analysis20โ€“30 minUpdated w/ live data
Indicators of Compromise10โ€“15 minUpdated w/ live data
Defense & Remediation15โ€“25 minUpdated w/ live data
Cost & Skill Analysis15โ€“25 minNew โ€” cost analysis
Evidence LockerBrowse as neededRaw artifacts
Start reading โ†’
Executive Summary