2026-08-01 · Web3 Security
The person who writes a wallet drainer and the person who finds you are almost never the same person, and a smart contract pays them both the moment your signature clears. This article is about the business that arrangement created: the vendors, the commission rates, the support channels, the exit announcements that were not exits, and the fact that nobody running one has ever been publicly charged. The mechanism, meaning what an approval and a permit signature authorise, sits in Approval phishing and the drainer economy.
Case file
| Field | Value |
|---|---|
| Business model | Drainer-as-a-service. Operators build the kit, affiliates supply victim traffic, a profit-sharing contract splits proceeds automatically |
| Named kits | Inferno, Angel, Pink, Monkey, MS, Venom, Ace, Nova (CryptoGrab), Rublevka, Eleven, Vanilla |
| Operator’s cut | 10% to 40% observed on chain, most commonly 20% (He et al., IMC ’25). Rates by vendor below |
| Measured scale | $135.0m, being $23.1m to operators and $111.9m to affiliates, across 76,582 victim accounts. Ethereum profit-sharing transactions only, March 2023 to April 2025 (He et al., IMC ’25) |
| Concentration | Angel, Inferno and Pink took 93.9% of measured profits; 14 operator accounts took 75.7% of operator profits (He et al.) |
| Typical victim loss | 83.5% of victim accounts lost under $1,000 (He et al.) |
| Support offered | Telegram channels and bots, admin panels, affiliate tiers, tutorials, hosted sites, landing-page generators, cloaking, 24/7 support |
| Court, docket, prosecution | Not established. No operator of a named drainer kit has been publicly charged anywhere |
| Posture as of 1 August 2026 | Active. Inferno was the most active family SEAL Intel observed in October 2025; Rublevka’s Solana campaign stood at about $8.2m in February 2026 (Recorded Future) |
| Defensive action | Treat the delivery channel rather than the brand as the signal, and report phishing pages |
What the record shows
How the split works
Bowen He and seven co-authors at Zhejiang University and BlockSec published the first systematic measurement of this business at the ACM Internet Measurement Conference in October 2025. They joined the operators’ Telegram groups, obtained the toolkits, then traced payouts on chain across 1,910 profit-sharing contracts, 56 operator accounts, 6,087 affiliate accounts and 87,077 transactions, with three analysts manually validating 44.8% of them.
Their pipeline has four steps. An operator advertises the revenue model and links a Telegram group. An affiliate joins, shows access to traffic, and supplies an Ethereum address. The operator compiles a drainer keyed to that address. The affiliate deploys and promotes phishing pages, and when a victim signs, a contract makes two transfers in fixed proportions with no manual step.
The proportions are readable on chain. Across 5,099 profit-sharing transactions from 30 contracts, the authors record operator shares of 10%, 12.5%, 15%, 17.5%, 20%, 25%, 30%, 33% and 40%, with 20% alone accounting for 46.0%. They state why the operator takes the smaller half: “Operator accounts receive a smaller share of the profits to incentivize and attract affiliates.” The Security Alliance, writing on 7 October 2025, adds the variable: “Profits are split between operators and affiliates at an average of 20/80, with operators taking more or less commission depending on the overall profitability of the affiliate.”
What each vendor charged
Inferno. Group-IB, which read the operation’s administrative panel, records the terms as “Of the stolen assets, 20% is transferred to Inferno Drainer developers and 80% to customers”, plus 30% where the developers also built and hosted the site. Scam Sniffer had reported the same two rates independently on 19 May 2023, writing that Inferno’s own announcement described “a model that only charges 20% and 30% of the site-building fee”.
Angel. Ledger’s own security incident report of 20 December 2023 states what Ledger saw on chain after the @ledgerhq/connect-kit compromise: “the funds stolen are being split: 85% to the exploiter and 15% to Angel Drainer, which could be seen as a malware as a service.” Ledger’s report gives no dollar total. SlowMist, on 17 October 2023, had found Angel advertising in English and Russian on different terms: “24/7 support, a deposit of $40,000, a 20% fee, support for multiple chains and NFTs, and an automatic site cloning tool.” The advertised rate and the observed rate are not the same number.
MS. Scam Sniffer, on 21 December 2023, puts this kit at approximately $58.98 million from about 63,210 victims and distinguishes its model: “unlike other Wallet Drainers that are fully managed and charge a 20% fee. They sell the source code and additional value-added modules.” Blur phishing signatures were a paid add-on.
Venom. Scam Sniffer, on 3 April 2023, records a recruitment drive from 20 March offering “a 15% cut” to people who could message the administrators of well-known crypto project Discord servers. [Q]
Nova. CertiK, on 27 February 2024, records the vendor CryptoGrab “typically dividing proceeds in a 70/30 split between the provider and the affiliate”, running a customer relationship management platform and offering “personal managers” to buyers.
Rublevka. Recorded Future’s Insikt Group, on 4 February 2026, records an April 2025 recruitment post advertising “a starting percentage of 75% and 80% for ‘experienced users’”, read by Insikt Group as a shift toward “expanding the pool of workers rather than extracting maximum income from any individual affiliate”.
The kits, and what the on-chain measurement says
| Kit | Operator’s cut | Ethereum profit | Window |
|---|---|---|---|
| Monkey | Not established | $12.972m (SlowMist) | Aug 2022 to Feb 2023 |
| Venom | Not established | $1.3m, 491 victims. $27m multichain per Scam Sniffer | Apr to Aug 2023 |
| Angel | 15% observed, 20% advertised | $53.1m, 37,755 victims | Apr 2023 to present |
| Inferno | 20%, or 30% hosted | $59.0m, 32,740 victims | May 2023 to Nov 2024 |
| Pink | Not established | $14.7m, 2,814 victims | Apr 2023 to May 2024 |
| MS | Sold outright | Not in dataset | Mar to Dec 2023 |
| Nova | About 30% | Not in dataset | From Jan 2024 |
| Rublevka | 25%, 20% experienced | Not in dataset | 2023 to present |
Every profit figure and window above except Monkey’s comes from He et al. and inherits that study’s scope: Ethereum profit-sharing transactions, March 2023 to April 2025. Kits predating March 2023, running mainly on other chains, or selling outright fall outside it. Monkey’s figure is SlowMist’s, published 10 February 2023: “The overall profit generated through phishing is estimated to be around $12.972 million.”
The number nobody measured
Inferno’s headline total is the clearest case of a figure travelling further than its evidence, and Group-IB does not claim it. Its own sentence reads: “As reported by Scam Sniffer, at least USD $80 million in assets was stolen as a result of Inferno Drainer’s activity.” Coverage crediting the figure to Group-IB attributes it to the wrong firm.
Scam Sniffer’s own published Inferno figure is different. Its 19 May 2023 report gives $5.9 million from about 4,888 victims and carries an appended update: “The stolen amount increased to ~$75 million after half a year.” Blockaid, on 3 January 2024, gives the number a third provenance, describing Inferno as a group that “boasts about its $80M+ in revenues”. He et al. measured $59.0 million on Ethereum. Four sources, four numbers, one repeated headline, and the domain counts diverge the same way: more than 16,000 per Group-IB, “nearly 1000” per Blockaid.
The support desk
Group-IB found Inferno’s panel compiling a UUID-tagged JavaScript file per customer, which is how researchers separate one affiliate’s traffic from another’s. Angel and Inferno both ran levelling systems keyed to cumulative profit, per He et al., Angel’s tiers at $100,000, $1 million and $5 million, Inferno’s at $10,000, $100,000 and $1 million, with Inferno paying a randomly selected qualifying affiliate 0.5 to 3 ETH by tier each period and 1 BTC to the top earner. Angel and Pink wanted documented traffic and prior experience from applicants. Inferno asked only that an applicant understand what a drainer is and supply an Ethereum address, with tutorials for those who did not know how to launch a site.
Insikt Group’s February 2026 account of Rublevka lists six affiliate-facing channels, among them a closed group chat with 6,821 members, a profits channel with 3,093 subscribers, a channel carrying updates to the drainer and the affiliate programme, and a bot handling applications and campaign administration in English, Russian and Chinese with no human involved. Free hosting, cloaking and DDoS protection come with it.
Countermeasures get answered in product. Scam Sniffer documented drainers adopting CREATE2 on 12 November 2023, generating a fresh contract address for every malicious signature so that a wallet checking the spender against known-bad lists finds an address with no history. Its 2024 annual report lists four working bypasses, among them XSS used to get around wallet blocklists and false results fed to transaction simulation. Check Point Research, on 7 May 2025, found Inferno hiding its command server address inside encrypted Binance Smart Chain contracts and routing traffic through a proxy script installed on the affiliate’s own server.
Shutdowns that were not shutdowns
Inferno’s developers announced a shutdown in their Telegram channel in November 2023. Group-IB found the customer panel still live into January 2024, moved to a new domain. Check Point Research states the outcome plainly: “Despite publicly shutting down in late 2023, Inferno Drainer remained fully operational. Smart contracts deployed in 2023 continued to be used into 2025.” Check Point attributes more than 30,000 victim wallets and at least $9 million in losses to Inferno in the six months before 7 May 2025. He et al. record its profit-sharing activity running to November 2024.
Scam Sniffer’s 2024 annual report tracks the market share behind those events. Through the first half of 2024, Angel held 42%, Pink 28% and Inferno 22%. Pink announced its exit at the end of May 2024 and Inferno absorbed its share. At the end of October 2024 Inferno announced that Angel had taken over, and the year closed with Inferno and Angel together at 45%, Acedrainer at 20% and newer kits at 25%. He et al. independently place the end of Pink’s profit-sharing activity in May 2024 and Inferno’s in November 2024.
Nova’s vendor went in a different direction. CryptoGrab incorporated CRYPTOGRAB LIMITED in England and Wales, company number 15422095, on 17 January 2024, which CertiK reported as an attempt to obtain extended validation certificates and look legitimate. The Companies House register records what followed: the officer’s and controlling person’s registered address replaced with the Companies House default address in Cardiff on 25 October 2024, a first Gazette notice for compulsory strike-off on 10 December 2024, and dissolution by compulsory strike-off on 4 March 2025.
No prosecution
There is no publicly reported criminal charge against the operator of any named drainer kit, in any jurisdiction. A CourtListener full-text search of federal dockets for “wallet drainer” returns 21 results, none of them a drainer-kit prosecution. No security firm cited in this article reports an arrest, a charge or an indictment in its work on these operations, though several published operator handles years ago.
What the record contains instead is infrastructure work. Blockaid named its wallet partnerships as the reason Inferno’s operators discussed shutting down, having read the reasoning in the group’s internal Telegram chat. The Security Alliance describes “SEAL Intel’s efforts over the past year to collaborate with Web2 and Web3 partners to neutralize centralized Inferno Drainer infrastructure where possible”, plus a separate operation blocking hundreds of Rublevka-controlled domains. Chainalysis’s Operation Spincaster, run with 12 public sector agencies and 17 exchanges across six countries, passed more than 7,000 leads on about $162 million of losses and produced account closures and frozen funds.
He et al. state the structural reason the criminal route stays closed: 83.5% of victim accounts lost under $1,000, and “many victims may choose not to gather evidence or report the incidents to authorities due to the time and effort required, which they may perceive as disproportionate to their losses.”
What I think is going on
The split is the product. Everything else follows from it.
Once the payout is a fixed proportion executed by a contract, the operator has no reason to ever touch a victim, run an ad account, or know which brand is being impersonated this week. He ships a JavaScript file and a smart contract and collects a percentage. What that leaves is an ordinary software business with an ordinary software business’s central problem: affiliate acquisition. He et al. found 6,087 affiliate accounts against 56 operators. If you were running that, you would price to recruit too.
Watch what happened to the price. Inferno charged 20% in 2023. Rublevka’s 2025 post starts affiliates at 25% and drops to 20% once they prove out, and SEAL says the commission moves with how profitable the affiliate is. The competition is for the person with a Telegram audience, because the code is the cheap part. Angel’s advertised $40,000 deposit is the only entry cost anywhere in the record, and it buys 24/7 support and a site cloning tool. Set that against a levelling system paying 1 BTC to the top earner of the period and you are looking at a channel programme.
The numbers deserve more suspicion than they get. Blockaid’s line is the one that should stop people: Inferno boasted the $80 million itself, which would make the most-cited statistic in this field a criminal operation’s own marketing. The one measurement with a stated method and a manual validation pass behind it, He et al.’s $59.0 million, is the number nobody quotes, probably because it is smaller and arrived two years late. Pink is worse. Coverage days apart gives $75 million and $85 million, both tracing to a Dune dashboard and a Telegram retirement message, with no method published behind either, which is why Pink’s total is missing from the record above.
The aggregate is still real. It is a lower bound assembled from incompatible scopes, which makes this a nine-figure annual industry of unknown exact size.
Now the empty row in the case file, which is the part that bothers me most.
Group-IB read the panel. Scam Sniffer watched a seller rename himself from pakulichev to Phishlab. Recorded Future named the LolzTeam account that launched Rublevka and named its administrators. SEAL published a video interview in which Eleven Drainer’s top affiliate collects a BMW M4 and explains why he agreed to appear on camera: he had, in his own account, “not violated any laws of the Russian Federation nor acted against Russia.” Three years of that, and no charge anywhere.
Prosecutorial indifference does not explain it. I think the model defeats the way fraud is prosecuted, whether by design or by accident. A case needs a victim whose loss justifies the work, and 83.5% of these victims lost under a thousand dollars. It needs conduct located somewhere, and the conduct is split across a developer in one country, an affiliate in another, a registrar in a third and a victim in a fourth. It needs a defendant whose acts add up to the offence, and the affiliate model is very good at ensuring each participant did one small, deniable, remotely performed part. The strongest thing any state has done to a drainer vendor on the public record is the Companies House entry above: CryptoGrab put its name on the UK register, and fourteen months later the registrar struck it off for not filing a confirmation statement.
On the Illicit Finance desk the same dollar figures produce indictments, forfeitures and sentencing dates, and what those cases have that this one lacks is a defendant who did the whole thing.
So do not wait for enforcement to change the arithmetic here. It is not going to, on any timeline that matters to you.
What reduces your exposure
The mechanism defences (reviewing and revoking approvals, checking Permit2’s two layers, refusing any request you cannot read as words) sit in the approval phishing article and decide whether a signature costs you anything. What follows comes out of the business model instead. None of it makes you safe, and each item removes one route in while leaving the others open.
The delivery channel is bought, and the brand tells you nothing. Scam Sniffer groups the traffic into four sources: compromised project Discord servers and X accounts, organic traffic through airdrop pages and expired Discord invites, paid advertising on Google, X and Telegram, and direct messages. Group-IB counted more than 100 impersonated crypto brands for Inferno, and Recorded Future found Rublevka shipping more than 35 ready-made landing pages inside its bot. The logo is the product, so recognising it is not information. Reach any page that will ask for a signature by typing the domain or using your own bookmark, and treat arriving there from an advertisement, a direct message or a link posted in a chat as a reason to stop.
A reputable host is no longer evidence of anything. The Security Alliance documents affiliates serving clean landing pages from sites.google.com, re-registering domains of defunct legitimate protocols, and loading payloads from GitHub through a public CDN. Scam Sniffer names Cloudflare, Vercel and IPFS as the common deployment targets. A padlock, a familiar CDN and a plausible domain are all purchasable, and extended validation certificates were why one vendor incorporated a UK company.
Report the page even when your own loss is small. This is the only item here that changes the aggregate rather than your position. Part of why this industry runs unprosecuted is that 83.5% of victims lose under $1,000 and reasonably conclude that reporting is not worth the afternoon. Chainabuse and the Security Alliance both take reports, and Chainalysis’s Operation Spincaster turned that class of data into 7,000 leads and frozen funds. Reporting will not recover your money. It shortens the life of the domain, the one cost affiliates reliably pay.
All of it assumes the request reaches you through a screen you can inspect, which the Ledger Connect Kit incident shows is not guaranteed, and none of it addresses what happens once a valid signature exists.
Sources
- Bowen He, Yufeng Hu, Zhuo Chen, Yuan Chen, Ting Yu, Rui Chang, Lei Wu and Yajin Zhou, “Unmasking the Shadow Economy: A Deep Dive into Drainer-as-a-Service Phishing on Ethereum”, Proceedings of the 2025 ACM Internet Measurement Conference, Madison WI, 28 to 31 October 2025.
https://doi.org/10.1145/3730567.3764476 - Ledger, “Security Incident Report”, 20 December 2023.
https://www.ledger.com/blog/security-incident-report - Companies House, CRYPTOGRAB LIMITED, company number 15422095, overview and filing history.
https://find-and-update.company-information.service.gov.uk/company/15422095 - Group-IB, “Inferno Drainer Scam: Crypto Wallet Draining Malware Explained”, 16 January 2024.
https://www.group-ib.com/blog/inferno-drainer/ - Check Point Research, “Inferno Drainer Reloaded: Deep Dive into the Return of the Most Sophisticated Crypto Drainer”, 7 May 2025.
https://research.checkpoint.com/2025/inferno-drainer-reloaded-deep-dive-into-the-return-of-the-most-sophisticated-crypto-drainer/ - Recorded Future, Insikt Group, “Rublevka Team: Anatomy of a Russian Crypto Drainer Operation”, CTA-2026-0204, 4 February 2026.
https://www.recordedfuture.com/research/rublevka-team-anatomy-russian-crypto-drainer-operation - Security Alliance, “The State of Drainers Vol. 1”, 7 October 2025.
https://securityalliance.org/news/2025-10-drainers-vol-1 - Blockaid, “Putting Inferno Drainer Group Out of Business”, 3 January 2024.
https://www.blockaid.io/blog/putting-inferno-drainer-group-out-of-business - CertiK, “Crime Incorporated: CryptoGrab’s UK Business Registration”, 27 February 2024.
https://www.certik.com/resources/blog/crime-incorporated-cryptograbs-uk-business-registration - SlowMist, “Cracking the Code: Unveiling the Deceptive ‘Angel Drainer’ Phishing Gang”, 17 October 2023.
https://slowmist.medium.com/cracking-the-code-unveiling-the-deceptive-angel-drainer-phishing-gang-proactive-strategies-to-3ade2bbfd45c - SlowMist, “Analysis of Monkey Drainer NFT Phishing Group”, 10 February 2023.
https://slowmist.medium.com/slowmist-analysis-of-monkey-drainer-nft-phishing-group-e4e269634854 - Scam Sniffer, “$5.9 Million Stolen By Scam as a Service Provider Called Inferno Drainer”, 19 May
- Read via the Internet Archive, snapshot 15 February 2025.
- Scam Sniffer, “New Scam as a Service Provider: Venom Drainer”, 3 April 2023. Internet Archive, snapshot 3 April 2023.
- Scam Sniffer, “From Google to X Ads: Tracing the Crypto Wallet Drainer’s $58 Million Trail”, 21 December 2023. Internet Archive, snapshot 19 January 2025.
- Scam Sniffer, “Wallet Drainers Starts Using Create2 Bypass Wallet Security Alert”, 12 November
- Internet Archive, snapshot 19 January 2025.
- Scam Sniffer, “2024: Web3 Phishing Attacks, Wallet Drainers Drain $494 Million”, 3 January 2025. Internet Archive, snapshot 6 January 2025.
- Scam Sniffer, “2025: Crypto Phishing Losses Fall 83% to $84 Million”, 3 January 2026. Internet Archive, snapshot 3 January 2026.
- Chainalysis, “Operation Spincaster”, 18 July 2024.
https://www.chainalysis.com/blog/operation-spincaster/ - CourtListener REST API v4, full-text search of federal dockets, queried 1 August 2026.
https://www.courtlistener.com/api/rest/v4/search/
On the Scam Sniffer citations. The firm’s research site, drops.scamsniffer.io, now redirects to a HawkHost account-suspended page. Every Scam Sniffer figure above was read from an Internet Archive snapshot, and there is no live copy to check the archived text against.
Related on this desk
- Bybit: the largest theft in the asset class — what a compromised signing surface costs at institutional scale.
Disclosure. Max Avery is affiliated with Digital Ascension Group (DAG). Investment advisory services are offered through DAG Wealth, an SEC-registered investment adviser (CRD No. 328627). Registration does not imply a certain level of skill or training. DAG is not a law firm and does not provide legal or tax advice. Custody arrangements with third-party independent qualified custodians reduce certain risks but do not eliminate them. Nothing here is investment, legal, or tax advice, or a recommendation to buy or sell any asset. This article describes matters of public record; charges are allegations and defendants are presumed innocent unless and until proven guilty.