Angel Drainer (AngelX)
Drainer-as-a-service toolkit active since 2023; drained $25M+ from ~35,000 wallets, shut down July 2024 after de-anonymization, then relaunched as AngelX and absorbed rival Inferno Drainer.
**Angel Drainer** emerged in 2023 as a "drainer-as-a-service" phishing toolkit sold to scammers for a cut of stolen funds (reportedly ~20% commission). Affiliates lure victims to fake dApp sites that trick them into signing malicious token approvals. By February 2024, security firm Blockaid counted **over $25 million drained from nearly 35,000 wallets** across 12 months of operation. On February 12, 2024, the group exploited Etherscan's automatic verification of Safe vault contracts to lend legitimacy to malicious Permit2 signatures, draining **$403,000 from 128 wallets** in one campaign; researchers also linked the group to the December 2023 Ledger Connect Kit supply-chain attack.
On **July 16, 2024**, hours after investigators at Match Systems announced they had de-anonymized members of the operation, Angel Drainer's Telegram channel declared its services suspended. The retirement lasted weeks: Blockaid detected a test instance on August 29 and the group relaunched as **AngelX** on August 31–September 1, 2024, with a new command-and-control dashboard, seed-phrase-theft capability, stronger cloaking against security vendors, and new support for TON and Tron. More than 300 malicious dApps were deployed within days of launch.
On **October 19, 2024**, rival Inferno Drainer announced it was handing its codebase and operations to the Angel team (per Scam Sniffer, which tracked 2,845 ETH, roughly $7.5M, moved out of Inferno's fee address); analysts noted prior code overlap between the two and suspected the handover partly masked existing shared control. In **February 2025**, Recorded Future's Insikt Group documented the "Crazy Evil" traffer gang still deploying Angel Drainer alongside the StealC and AMOS stealers. No arrests, indictments, or sanctions tied to Angel Drainer's operators have been made public; the latest verified reporting (early 2025) shows the toolkit lineage still in criminal circulation.
Sources: [Cointelegraph (Feb 2024)](https://cointelegraph.com/news/angel-drainer-attack-gnosis-safe-vault-contract-etherscan), [Blockaid Threat Report: AngelX (Sep 2024)](https://www.blockaid.io/blog/threat-report-angelx), [Cointelegraph via TradingView (Jul 2024 shutdown)](https://www.tradingview.com/news/cointelegraph:c432c956f094b:0-angel-drainer-reportedly-shuts-down-after-devs-potentially-identified/), [BeInCrypto (Oct 2024 Inferno handover)](https://beincrypto.com/angel-drainer-takes-over-infernos-tools/), [The Hacker News (Feb 2025)](https://thehackernews.com/2025/02/crazy-evil-gang-targets-crypto-with.html)
**Official action:** None public (no indictments or sanctions); vendor-documented — Blockaid/Check Point research; Match Systems de-anonymization forced temporary shutdown July 2024
Verify every address independently before acting · Not financial advice