Inferno Drainer
Inferno Drainer 是什么?
Inferno DrainerA 2022–2023 crypto-wallet-drainer-as-a-service that emptied tens of thousands of victims' wallets by phishing them into signing token-approval transactions on fake mint and airdrop sites, before shutting down in November 2023.
Inferno Drainer was a prolific 'wallet drainer' service operating from late 2022 through November 2023 — the canonical example of the 2023-era surge in Web3 phishing. Operators of the service paid Inferno's developers a percentage of stolen funds for access to a turnkey kit: a JavaScript-based drainer payload, a phishing-site template, integration with multiple wallet protocols, and laundering through mixers and cross-chain bridges. Victims arrived at lookalike NFT-mint or token-airdrop sites (often promoted via hijacked Twitter accounts, Discord scams, and Google Ads), connected their wallet, and were prompted to sign 'mint' or 'claim' transactions that were actually unlimited ERC-20 / ERC-721 `setApprovalForAll` or `Permit` calls. The drainer then drained the approved tokens to operator-controlled addresses. Chainalysis and ScamSniffer estimated Inferno stole at least $80 million from 100,000+ victims before its operators announced shutdown in November 2023. Successor and copycat drainers — Pink Drainer, Angel Drainer, MS Drainer, AngelX — picked up the same kit-and-affiliate model and remained active through 2024–2025.
● 示例
- 01
A user clicks a Twitter ad for a 'free mint', signs what looks like a mint transaction, and an Inferno-powered drainer empties their ERC-20 holdings within seconds.
- 02
An NFT-focused security firm publishes the public addresses associated with the Inferno Drainer kit and integrates them into a wallet-warning extension.
● 常见问题
Inferno Drainer 是什么?
A 2022–2023 crypto-wallet-drainer-as-a-service that emptied tens of thousands of victims' wallets by phishing them into signing token-approval transactions on fake mint and airdrop sites, before shutting down in November 2023. 它属于网络安全的 Web3 与区块链 分类。
Inferno Drainer 是什么意思?
A 2022–2023 crypto-wallet-drainer-as-a-service that emptied tens of thousands of victims' wallets by phishing them into signing token-approval transactions on fake mint and airdrop sites, before shutting down in November 2023.
Inferno Drainer 是如何工作的?
Inferno Drainer was a prolific 'wallet drainer' service operating from late 2022 through November 2023 — the canonical example of the 2023-era surge in Web3 phishing. Operators of the service paid Inferno's developers a percentage of stolen funds for access to a turnkey kit: a JavaScript-based drainer payload, a phishing-site template, integration with multiple wallet protocols, and laundering through mixers and cross-chain bridges. Victims arrived at lookalike NFT-mint or token-airdrop sites (often promoted via hijacked Twitter accounts, Discord scams, and Google Ads), connected their wallet, and were prompted to sign 'mint' or 'claim' transactions that were actually unlimited ERC-20 / ERC-721 `setApprovalForAll` or `Permit` calls. The drainer then drained the approved tokens to operator-controlled addresses. Chainalysis and ScamSniffer estimated Inferno stole at least $80 million from 100,000+ victims before its operators announced shutdown in November 2023. Successor and copycat drainers — Pink Drainer, Angel Drainer, MS Drainer, AngelX — picked up the same kit-and-affiliate model and remained active through 2024–2025.
如何防御 Inferno Drainer?
针对 Inferno Drainer 的防御通常结合技术控制与运营实践,详见上方完整定义。
Inferno Drainer 还有哪些其他名称?
常见的别称包括: Inferno Drainer kit, Wallet drainer service。
● 相关术语
- web3№ 1348
钱包窃取器(Wallet Drainer)
通过钓鱼或恶意脚本诱骗加密钱包用户签署交易或授权,从而一次性转走所有代币与 NFT 的攻击工具。
- web3№ 912
Permit2 钓鱼
Permit2 钓鱼是诱骗以太坊用户对 Uniswap Permit2 的链下消息进行签名,从而把转移其 ERC-20 代币的权限授予攻击者。
- web3№ 1155
Signature Phishing (Web3)
A Web3 phishing pattern that tricks a user into signing an EIP-712 or `personal_sign` message that authorizes the attacker to move tokens, transfer NFTs, or take wallet actions — without ever asking for a seed phrase.
- web3№ 017
地址投毒
地址投毒是在受害者的交易历史中混入与正常地址首尾相似但由攻击者控制的「相像」地址,使其日后复制时误选并把资金转给攻击者。
- web3№ 1171
智能合约安全
通过设计、审查和运维链上程序,防止其被利用以盗取资金、冻结逻辑或违反业务规则的实践。
- web3№ 1063
Rug Pull(抽地毯/卷款跑路)
代币、NFT 项目或 DeFi 协议的开发者抽走流动性或金库资金后消失,使持有者持有的资产瞬间归零的退出诈骗。
● 参见
- № 413EIP-712 Signing