Inferno Drainer
Drainer-as-a-service live since Nov 2022; faked a Nov 2023 shutdown. Group-IB tied ~$80M to year one (Scam Sniffer dashboard: ~$87M/137k); Check Point (May 2025) found it still active, $250M+ operator-claimed.
**Inferno Drainer** is a drainer-as-a-service (DaaS) operation active since **November 2022** (per Group-IB — earlier than the "early 2023" often cited). Affiliates rent wallet-draining kits and phishing infrastructure, with the developers keeping a **20% commission** (15–20% in later variants). Group-IB documented **16,000+ unique phishing domains** impersonating **100+ crypto brands** and spoofing WalletConnect, Coinbase, and Seaport protocols, estimating **at least $80 million** stolen between Nov 2022 and Nov 2023; Scam Sniffer's Dune Analytics dashboard puts the year-one toll higher at **~$87 million from ~137,000 victims**.
The operators announced "retirement" on Telegram in **November 2023**, but Group-IB found the user panel still active into January 2024. **Check Point Research (May 7, 2025)** showed the shutdown was a deception: smart contracts deployed in September 2023 remained in use into 2025, the operators claimed **$250M+ cumulative stolen** by May 2024, and **between September 2024 and March 2025, 30,000+ wallets were drained for $9M+**, including a January 2025 Discord campaign using fake Collab.Land bots. New variants use single-use smart contracts, on-chain encrypted configs, and customer-hosted proxy C2 across **30+ EVM chains** (primarily Ethereum and BNB Chain).
In **October 2024**, Inferno announced (per Scam Sniffer) it was handing its platform to rival **Angel Drainer**, moving 2,845 ETH (~$7.5M) from its fee address — yet Check Point's 2025 research documents Inferno-branded operations continuing. **No arrests, indictments, or sanctions** against its operators are on public record as of mid-2026; attribution rests entirely on security-vendor research. Note: the $250M figure is the operators' own claim reported by Check Point; Group-IB's independent estimate (~$80M, or ~$87M per Scam Sniffer) covers only the first year.
Sources: [Check Point Research (May 2025)](https://research.checkpoint.com/2025/inferno-drainer-reloaded-deep-dive-into-the-return-of-the-most-sophisticated-crypto-drainer/) · [Group-IB (Jan 2024)](https://www.group-ib.com/blog/inferno-drainer/) · [The Hacker News](https://thehackernews.com/2024/01/inferno-malware-masqueraded-as-coinbase.html) · [The Record](https://therecord.media/inferno-drainer-cryptocurrency-scam-spoofing-blockchain-projects) · [Decrypt](https://decrypt.co/318561/inferno-drainer-malware-returns-stealing-9m-from-crypto-wallets-in-six-months)
**Official action:** None publicly (no arrests, indictments, or sanctions as of Jul 2026); vendor-documented — Group-IB Jan 2024, Check Point Research May 2025
Verify every address independently before acting · Not financial advice