A wallet drainer is malicious code, usually delivered through a phishing website or a fake token claim, that tricks a victim into signing a transaction that hands control of their crypto assets to an attacker. This isn’t a hypothetical threat. It’s an active criminal industry with named operations, known operators, and a documented history of takedowns that never quite stops the underlying activity. This guide walks through five real cases, how each was actually discovered and disrupted, and what the pattern across all of them means for anyone holding crypto today.
| 83% Drop
Wallet drainer losses fell from $494 million in 2024 to $83.85 million in 2025, according to Scam Sniffer data. Real progress, but still tens of millions stolen every year Source: Scam Sniffer, Group-IB, and SlowMist annual reporting |
Case 1: Inferno Drainer, the $80 Million Operation Caught by Researchers, Not Police
Inferno Drainer ran from November 2022 to November 2023 as a scam as a service operation, meaning the people who built the drainer software rented it out to affiliates who kept 80 percent of what they stole while the operators took a 20 percent cut. It’s estimated to have stolen more than $80 million from roughly 137,000 victims, using more than 16,000 phishing domains that impersonated over a hundred real crypto brands and projects.
Here’s the part worth understanding about how this got caught. It wasn’t a law enforcement raid. It was Group-IB’s High-Tech Crime Investigation unit, a private cybersecurity research team, publishing a detailed technical exposure of the operation’s infrastructure in January 2024, two months after the operators had already announced their own shutdown. The public research made it dramatically harder for the same operators to relaunch under the same identity, but it didn’t end the underlying threat. Inferno Drainer’s code and reputation resurfaced in 2025, and in just six months it struck more than 30,000 wallets and stole over $9 million more.
Case 2: Monkey Drainer, Shut Down by a Single Independent Investigator
Monkey Drainer was one of the earliest scaled drainer operations, and it shut down voluntarily in March 2023 after independent on chain investigator ZachXBT published a public investigation identifying the operator. This case is worth including specifically because it shows that formal law enforcement isn’t the only force that disrupts these operations. A single researcher, working publicly and sharing findings openly, applied enough pressure and public exposure that the operator chose to announce a shutdown via Telegram rather than continue operating under scrutiny.
Case 3: Pink Drainer, $85 Million and 21,000 Victims Before a Quiet Retirement
Pink Drainer is linked to more than $85 million stolen from over 21,000 victims before announcing its own wind down in 2024. Like Inferno, it operated as a service, meaning the technical skill barrier for running a drainer campaign was almost nonexistent for affiliates, who mainly needed to drive traffic to phishing pages through hacked social media accounts, paid ads, or spam. The retirement of both Pink and Inferno within roughly the same period didn’t reduce the total number of active drainer campaigns much, since the affiliate pool simply migrated to whichever kit was still available.
Case 4: Angel Drainer and the Ledger Connect Kit Supply Chain Attack
Angel Drainer’s most notable moment wasn’t a phishing site at all. On December 14, 2023, attackers compromised Ledger’s Connect Kit, a piece of legitimate, widely used code that many real crypto applications rely on to let wallets connect to them. Because the compromised code was distributed through official channels, a large number of genuine, reputable applications briefly served malicious code to their own users without either the applications or the users doing anything wrong on the surface. This is a meaningfully different attack pattern than a fake website, since it demonstrates that even careful users interacting only with applications they already trusted could still have been exposed, at least for the narrow window before the compromise was identified and reverted.
Case 5: The September 2025 Case That Shows Even Experienced Users Get Caught
In September 2025, a long time DeFi trader with a wallet tied to years of activity on respected protocols lost $6.5 million in a single incident. The attack began through a phishing link shared in a community channel, and the actual theft happened through a single malicious permit approval, a type of signature that grants a smart contract ongoing permission to move specific tokens on a wallet’s behalf. That one approval looked routine at the moment it was signed. The attackers then chained that permission across multiple contracts, moving funds in quick bursts before the victim could intervene.
This case matters because the victim wasn’t a beginner. Long standing wallet history and familiarity with major protocols didn’t prevent the loss, because the vulnerability wasn’t a lack of crypto experience. It was a single signature, requested in a moment that felt ordinary, that granted more access than the victim understood they were granting.

The Pattern Across Every Case
None of these five cases involved a stolen private key or password in the traditional sense. Every one of them worked by getting the victim to actively sign something, a wallet connection, a token approval, a permit signature, that handed the attacker legitimate on chain permission to move funds. This is why so much wallet security advice now focuses on what you’re approving, not just what you’re clicking. A phishing site doesn’t need to steal your credentials if it can convince you to sign a transaction that does the same job with your own authorization attached to it.
How These Operations Actually Get Disrupted
- Independent researchers publishing public investigations, as with ZachXBT and Monkey Drainer, which can pressure an operator into shutting down even without a formal arrest
- Cybersecurity firms exposing infrastructure through detailed technical reports, as Group-IB did with Inferno Drainer, which damages an operation’s ability to relaunch under the same identity
- Real time threat detection platforms that flag malicious addresses within hours of new activity, as Hypernative did within a day of Inferno Drainer’s 2025 resurgence
- Formal law enforcement action, which does happen but has been the least common disruption mechanism across these particular cases compared to research and detection based approaches
The honest takeaway from this list is that no single mechanism reliably ends drainer activity. Every major shutdown in this article was followed, eventually, by a successor kit or a resurgence of the same one. That’s the reason personal defense habits, covered in more depth in our Spoke article on checking a wallet address before sending funds, matter regardless of which drainer kit happens to be active this month.
What To Do If You Think You’ve Been Drained
- Revoke any active token approvals immediately using a tool like Etherscan’s Token Approval Checker or Revoke.cash, since a drainer may have left standing permissions even after the initial theft.
- Move any remaining assets to a new wallet with a freshly generated seed phrase, rather than continuing to use the compromised one.
- Document the transaction hashes and the phishing site or approval request that led to the loss.
- Report the malicious address to Chainabuse and, if a specific drainer kit is identifiable, to the security firms that track them.
- For significant losses, a professional blockchain tracing investigation can follow where funds moved after the drain, particularly useful if they touched a centralized exchange at any point.
Frequently Asked Questions
Why don’t takedowns permanently stop these operations?
Most drainers operate as a service, meaning a small team builds the software and a much larger pool of affiliates runs campaigns using it. Removing one kit or one operator doesn’t remove the affiliate pool, which typically migrates to whichever kit is still available.
Who actually catches these operations, if not mainly law enforcement?
Independent researchers publishing public investigations and cybersecurity firms exposing technical infrastructure have driven several of the most significant disruptions in this space, sometimes more directly than formal law enforcement action.
What is a permit signature, and why is it dangerous?
A permit signature grants a smart contract ongoing permission to move specific tokens from your wallet without requiring a new approval each time. Signing one for a malicious contract can hand an attacker standing access to your funds through a single, easily overlooked action.
Can experienced crypto users still fall for these scams?
Yes. The September 2025 case in this article involved a trader with years of wallet history and familiarity with major protocols. The vulnerability wasn’t inexperience, it was a single signature that granted more access than intended.
What’s the single most useful habit for avoiding a drainer?
Read what you’re actually signing before approving it, and periodically revoke old token approvals you no longer need, since a forgotten standing permission can be exploited long after you’ve stopped thinking about it.
Related Reading
Parent Hub: Cryptocurrency Investment Scams, How They Work
Sibling Spoke: How to Check If a Crypto Wallet Address Is Linked to a Scam
Pillar guide: Investment Scams, The Complete Guide
Free Case Assessment: free-case-assessment
Contact Support via WhatsApp: WhatsApp

