Inferno Drainer
O que é Inferno Drainer?
Inferno DrainerA 2022–2023 crypto-wallet-drainer-as-a-service that emptied tens of thousands of victims' wallets by phishing them into signing token-approval transactions on fake mint and airdrop sites, before shutting down in November 2023.
Inferno Drainer was a prolific 'wallet drainer' service operating from late 2022 through November 2023 — the canonical example of the 2023-era surge in Web3 phishing. Operators of the service paid Inferno's developers a percentage of stolen funds for access to a turnkey kit: a JavaScript-based drainer payload, a phishing-site template, integration with multiple wallet protocols, and laundering through mixers and cross-chain bridges. Victims arrived at lookalike NFT-mint or token-airdrop sites (often promoted via hijacked Twitter accounts, Discord scams, and Google Ads), connected their wallet, and were prompted to sign 'mint' or 'claim' transactions that were actually unlimited ERC-20 / ERC-721 `setApprovalForAll` or `Permit` calls. The drainer then drained the approved tokens to operator-controlled addresses. Chainalysis and ScamSniffer estimated Inferno stole at least $80 million from 100,000+ victims before its operators announced shutdown in November 2023. Successor and copycat drainers — Pink Drainer, Angel Drainer, MS Drainer, AngelX — picked up the same kit-and-affiliate model and remained active through 2024–2025.
● Exemplos
- 01
A user clicks a Twitter ad for a 'free mint', signs what looks like a mint transaction, and an Inferno-powered drainer empties their ERC-20 holdings within seconds.
- 02
An NFT-focused security firm publishes the public addresses associated with the Inferno Drainer kit and integrates them into a wallet-warning extension.
● Perguntas frequentes
O que é Inferno Drainer?
A 2022–2023 crypto-wallet-drainer-as-a-service that emptied tens of thousands of victims' wallets by phishing them into signing token-approval transactions on fake mint and airdrop sites, before shutting down in November 2023. Pertence à categoria Web3 e blockchain da cibersegurança.
O que significa Inferno Drainer?
A 2022–2023 crypto-wallet-drainer-as-a-service that emptied tens of thousands of victims' wallets by phishing them into signing token-approval transactions on fake mint and airdrop sites, before shutting down in November 2023.
Como funciona Inferno Drainer?
Inferno Drainer was a prolific 'wallet drainer' service operating from late 2022 through November 2023 — the canonical example of the 2023-era surge in Web3 phishing. Operators of the service paid Inferno's developers a percentage of stolen funds for access to a turnkey kit: a JavaScript-based drainer payload, a phishing-site template, integration with multiple wallet protocols, and laundering through mixers and cross-chain bridges. Victims arrived at lookalike NFT-mint or token-airdrop sites (often promoted via hijacked Twitter accounts, Discord scams, and Google Ads), connected their wallet, and were prompted to sign 'mint' or 'claim' transactions that were actually unlimited ERC-20 / ERC-721 `setApprovalForAll` or `Permit` calls. The drainer then drained the approved tokens to operator-controlled addresses. Chainalysis and ScamSniffer estimated Inferno stole at least $80 million from 100,000+ victims before its operators announced shutdown in November 2023. Successor and copycat drainers — Pink Drainer, Angel Drainer, MS Drainer, AngelX — picked up the same kit-and-affiliate model and remained active through 2024–2025.
Como se defender contra Inferno Drainer?
As defesas contra Inferno Drainer costumam combinar controles técnicos e práticas operacionais, conforme detalhado na definição acima.
Quais são outros nomes para Inferno Drainer?
Nomes alternativos comuns: Inferno Drainer kit, Wallet drainer service.
● Termos relacionados
- web3№ 1348
Drainer de Carteira
Software malicioso ou kit de phishing que engana utilizadores de carteiras cripto para assinarem transacoes ou aprovacoes que entregam todos os tokens e NFTs valiosos.
- web3№ 912
Phishing de Permit2
O phishing de Permit2 induz um usuario Ethereum a assinar uma mensagem off-chain do Uniswap Permit2 que concede a um atacante o direito de transferir seus tokens ERC-20.
- web3№ 1155
Signature Phishing (Web3)
A Web3 phishing pattern that tricks a user into signing an EIP-712 or `personal_sign` message that authorizes the attacker to move tokens, transfer NFTs, or take wallet actions — without ever asking for a seed phrase.
- web3№ 017
Envenenamento de Enderecos
O envenenamento de enderecos planta no historico da vitima enderecos semelhantes controlados pelo atacante, para que ela depois copie e cole o errado e envie fundos ao atacante.
- web3№ 1171
Seguranca de Contratos Inteligentes
Pratica de projetar, revisar e operar programas on-chain para que nao possam ser explorados para roubar fundos, congelar a logica ou violar regras de negocio.
- web3№ 1063
Rug Pull
Golpe de saida em que os desenvolvedores de um token, colecao NFT ou protocolo DeFi drenam liquidez ou tesouraria e desaparecem, deixando os detentores com ativos sem valor.
● Veja também
- № 413EIP-712 Signing