SubscribeBTCSCAMWallet Test
Front page / Threat Intel
highThreat Intel

Inferno Drainer and the rise of rent-a-scam crimeware

A phishing kit rented to affiliates for a cut of every theft faked its own retirement in 2023 — then came back bigger. The whole attack is one signature you can learn to withhold.

LV
Lena Vogt
Threat Intel Correspondent · JUL 21, 2026 · 4 min read
Painting: Renaissance archive · Source: Check Point Research

Most crypto theft no longer requires the thief to write a line of code. Drainer-as-a-service (DaaS) turns wallet-emptying malware into a rented product: operators build and maintain the kit, affiliates spread it, and the two sides split the proceeds. Inferno Drainer is the clearest case study of how that business runs — and how hard it is to shut down.

Group-IB, in a January 2024 report, attributed roughly $87 million in theft to Inferno from about 137,000 victims. According to Group-IB, the kit had been active since November 2022 and reached victims through more than 16,000 unique malicious domains that spoofed over 100 crypto brands, including Coinbase, WalletConnect and Seaport's Web3 connection protocols.

The affiliate economics

The "service" in drainer-as-a-service is literal. Affiliates rented the phishing infrastructure, drove traffic to the fake sites, and handed the operators a cut of everything stolen — about 20%, per Group-IB, rising to 30% when the operators also hosted the pages for them. The 2025 variants documented by Check Point Research keep a 15–20% operator commission.

That structure is why drainers scale. The people running the phishing pages never need to understand smart contracts; the people writing the malware never need to touch a victim. Each side specializes, and the rented kit does the theft.

A fake retirement, a bigger comeback

In November 2023, Inferno's operators announced a shutdown on their Telegram channel. It was a diversion. Check Point Research's May 2025 deep dive found the operation had quietly continued and grown more sophisticated, running across more than 30 EVM-compatible networks with single-use smart contracts and on-chain encrypted command-and-control configurations. From March 2025, Check Point says, a "secure proxy" layer began hiding the real infrastructure from researchers and law enforcement.

The numbers grew with it. Check Point put cumulative Inferno losses above $250 million by May 2024, calling it the largest single contributor to crypto-drainer losses. Between roughly September 2024 and March 2025 the firm tracked more than 30,000 new victim wallet addresses and at least $9 million in fresh theft. The single largest hit, on October 13, 2024, drained 107.8 billion PEPE tokens worth over $1.2 million at the time. The 2025 kit also powers Discord-based phishing, including a fake Collab.Land verification bot.

Why one signature is the whole attack

A drainer does not "hack" your wallet. It convinces you to sign a transaction that authorizes it to move your assets — a token approval, a permit signature, or a malicious contract call dressed up as "connect wallet" or "verify." Once you sign, the transfer is on-chain and irreversible. The spoofed brands — Coinbase, WalletConnect, Seaport, Collab.Land — exist only to make that one click feel routine.

That is also the good news: the entire attack collapses at the signature. If you can read what you are signing and refuse the requests you cannot explain, the rented kit has nothing to take.

Protect yourself

  • Treat every "connect wallet," "verify," or "claim" prompt as untrusted until you have confirmed the domain yourself; do not follow links from Discord DMs, X replies, or airdrop ads.
  • Read the signature request. If your wallet shows a token approval, a `Permit`, or `setApprovalForAll` that you did not intend to grant, reject it.
  • Be wary of "unlimited" approvals; set spending caps and prefer per-transaction amounts.
  • Keep long-term holdings in a hardware wallet or a separate address you never connect to unfamiliar sites.
  • Periodically review and revoke old token approvals using a reputable allowance-checker.
  • No legitimate verification bot needs a wallet-draining signature; a Collab.Land-style "verify" that asks you to sign a transfer is the scam.

As of July 2026, per Check Point Research and Group-IB, there is no public arrest, indictment or sanction against Inferno's operators. The infrastructure is still live and the model still profitable — which is exactly why the defense that matters most is the one at your own wallet.

— Sources: [Check Point Research](https://research.checkpoint.com/2025/inferno-drainer-reloaded-deep-dive-into-the-return-of-the-most-sophisticated-crypto-drainer/) · [Group-IB](https://www.group-ib.com/blog/inferno-drainer/) · [The Hacker News](https://thehackernews.com/2024/01/inferno-malware-masqueraded-as-coinbase.html) · [The Record](https://therecord.media/inferno-drainer-cryptocurrency-scam-spoofing-blockchain-projects)

The Rug Report
Every scam that mattered this week, each Sunday.

NOT FINANCIAL ADVICE · VERIFY EVERYTHING