Inferno Drainer phishing-as-a-service campaign hack — November 2023
Incident facts
| Date of incident | (approximate) |
|---|---|
| Publicly disclosed | November 26, 2023 |
| Target type | Other |
| Loss | $81,000,000Published estimates range $70,000,000 to $81,000,000Price at time of incident |
| Method | Phishing signatureDrainer-as-a-service kit rented to affiliates. Victims were driven to counterfeit versions of well-known crypto sites — fake airdrop claims, mints and token pages — and prompted to connect a wallet and sign a transaction or token approval that transferred assets or granted spending allowances to the operator instead of doing what the page described. Group-IB counted more than 16,000 unique domains and upwards of 100 impersonated brands across multiple EVM networks. |
| Chains | Multiple chains |
| Outcome | Unresolved |
What happened
Inferno Drainer was a phishing-as-a-service kit rented to affiliates who used it to empty cryptocurrency wallets. Victims were led to counterfeit versions of well-known crypto sites — fake airdrop claims, NFT mints and token pages — where they were asked to connect a wallet and sign a transaction or token approval. The signature handed control of the victim's assets to the operator rather than performing the action the page described.
Group-IB found that the kit's customers ran the scheme through more than 16,000 unique domains impersonating upwards of 100 cryptocurrency brands, and that the developers kept 20 percent of each theft, rising to 30 percent in cases where they also built and hosted the phishing site.
The operators announced on 26 November 2023, in their Telegram channel, that the service was closing, saying that Inferno was closed for good and would not return. Group-IB reported that the customer panel was still reachable in January 2024, and kits trading under the name resurfaced later.
Campaign totals differ because they were compiled at different points. Scam Sniffer counted more than $70 million taken from 103,767 victims as of the shutdown announcement, then $81 million from 134,000 victims in its year-end review covering activity since March 2023. Group-IB, working from its own infrastructure analysis, put the figure at more than $80 million across November 2022 to November 2023. The higher figure is recorded as the best estimate because it is the more complete accounting and is independently corroborated by Group-IB's separate research.
No arrests connected to Inferno Drainer have been reported and none of the stolen funds is known to have been recovered.
Sources
- Group-IBSecondary · retrieved 2026-08-01
- The Block (reporting Scam Sniffer data)Secondary · retrieved 2026-08-01
- Unchained (reporting Scam Sniffer data)Secondary · retrieved 2026-08-01
- The Record (reporting Group-IB research)Secondary · retrieved 2026-08-01
Cite this
This data is published under CC BY 4.0. You may reuse it, including commercially, as long as you credit iTokenly and link back.
iTokenly Hack Registry, "Inferno Drainer phishing-as-a-service campaign hack — November 2023", iTokenly, accessed 2026-08-01, https://itokenly.com/hacks/inferno-drainerhttps://itokenly.com/hacks/inferno-drainerPermalinks never change. If an entry is renamed, the old address keeps working.
Spotted an error? Write to [email protected]. Corrections to published figures are logged on this page. See the methodology for how entries are checked.