Inferno Drainer
Inferno Drainer とは何ですか?
Inferno DrainerA 2022–2023 crypto-wallet-drainer-as-a-service that emptied tens of thousands of victims' wallets by phishing them into signing token-approval transactions on fake mint and airdrop sites, before shutting down in November 2023.
Inferno Drainer was a prolific 'wallet drainer' service operating from late 2022 through November 2023 — the canonical example of the 2023-era surge in Web3 phishing. Operators of the service paid Inferno's developers a percentage of stolen funds for access to a turnkey kit: a JavaScript-based drainer payload, a phishing-site template, integration with multiple wallet protocols, and laundering through mixers and cross-chain bridges. Victims arrived at lookalike NFT-mint or token-airdrop sites (often promoted via hijacked Twitter accounts, Discord scams, and Google Ads), connected their wallet, and were prompted to sign 'mint' or 'claim' transactions that were actually unlimited ERC-20 / ERC-721 `setApprovalForAll` or `Permit` calls. The drainer then drained the approved tokens to operator-controlled addresses. Chainalysis and ScamSniffer estimated Inferno stole at least $80 million from 100,000+ victims before its operators announced shutdown in November 2023. Successor and copycat drainers — Pink Drainer, Angel Drainer, MS Drainer, AngelX — picked up the same kit-and-affiliate model and remained active through 2024–2025.
● 例
- 01
A user clicks a Twitter ad for a 'free mint', signs what looks like a mint transaction, and an Inferno-powered drainer empties their ERC-20 holdings within seconds.
- 02
An NFT-focused security firm publishes the public addresses associated with the Inferno Drainer kit and integrates them into a wallet-warning extension.
● よくある質問
Inferno Drainer とは何ですか?
A 2022–2023 crypto-wallet-drainer-as-a-service that emptied tens of thousands of victims' wallets by phishing them into signing token-approval transactions on fake mint and airdrop sites, before shutting down in November 2023. サイバーセキュリティの Web3 とブロックチェーン カテゴリに属します。
Inferno Drainer とはどういう意味ですか?
A 2022–2023 crypto-wallet-drainer-as-a-service that emptied tens of thousands of victims' wallets by phishing them into signing token-approval transactions on fake mint and airdrop sites, before shutting down in November 2023.
Inferno Drainer はどのように機能しますか?
Inferno Drainer was a prolific 'wallet drainer' service operating from late 2022 through November 2023 — the canonical example of the 2023-era surge in Web3 phishing. Operators of the service paid Inferno's developers a percentage of stolen funds for access to a turnkey kit: a JavaScript-based drainer payload, a phishing-site template, integration with multiple wallet protocols, and laundering through mixers and cross-chain bridges. Victims arrived at lookalike NFT-mint or token-airdrop sites (often promoted via hijacked Twitter accounts, Discord scams, and Google Ads), connected their wallet, and were prompted to sign 'mint' or 'claim' transactions that were actually unlimited ERC-20 / ERC-721 `setApprovalForAll` or `Permit` calls. The drainer then drained the approved tokens to operator-controlled addresses. Chainalysis and ScamSniffer estimated Inferno stole at least $80 million from 100,000+ victims before its operators announced shutdown in November 2023. Successor and copycat drainers — Pink Drainer, Angel Drainer, MS Drainer, AngelX — picked up the same kit-and-affiliate model and remained active through 2024–2025.
Inferno Drainer からどのように防御しますか?
Inferno Drainer に対する防御は通常、上記の定義で述べたとおり、技術的統制と運用上の実践を組み合わせます。
Inferno Drainer の別名は何ですか?
一般的な別名: Inferno Drainer kit, Wallet drainer service。
● 関連用語
- web3№ 1348
ウォレットドレイナー
暗号資産ウォレット利用者を騙してトランザクションや承認を署名させ、保有するトークンと NFT を根こそぎ奪う悪意あるソフト/フィッシングキット。
- web3№ 912
Permit2 フィッシング
Permit2 フィッシングは、Ethereum ユーザーを騙して Uniswap Permit2 のオフチェーンメッセージに署名させ、攻撃者に被害者の ERC-20 トークン移転権限を与える攻撃です。
- web3№ 1155
Signature Phishing (Web3)
A Web3 phishing pattern that tricks a user into signing an EIP-712 or `personal_sign` message that authorizes the attacker to move tokens, transfer NFTs, or take wallet actions — without ever asking for a seed phrase.
- web3№ 017
アドレスポイズニング
アドレスポイズニングは、被害者の取引履歴に攻撃者が用意した類似アドレスを混入させ、後でコピー&ペースト時に誤って攻撃者へ送金させる手口です。
- web3№ 1171
スマートコントラクトセキュリティ
オンチェーンプログラムを設計・レビュー・運用し、資金の盗難、ロジックの停止、想定外のルール違反に悪用されないようにする実践。
- web3№ 1063
ラグプル
暗号資産トークン・NFT・DeFi プロトコルの開発者が流動性やトレジャリーを引き抜いて姿を消し、保有者の資産を実質無価値にする出口詐欺。
● 関連項目
- № 413EIP-712 Signing