Guglielmo Anfossianfossi.systemsBook a call

Drainer

A malicious toolkit, typically consisting of website scripts and smart contracts, designed to steal assets from victims' addresses by tricking them into authorising transactions or signing malicious messages. Common techniques include token approvals, permit signatures, deceptive NFT marketplace orders, and, on supported networks, malicious transactions or account delegations. Drainers are often deployed through fake websites, airdrops or mint pages. Unlike malware that steals private keys or compromises a device, a drainer typically exploits actions the victim is tricked into authorising, leaving on-chain transactions or other cryptographic evidence that can be investigated.

Drainers are frequently operated under a drainer-as-a-service model, in which the kit provider receives a percentage of the stolen proceeds. This revenue split may be visible on-chain and can link separate incidents to the same drainer service, though not necessarily to the same affiliate. Transfers of the remaining proceeds may help identify the individual campaign operator or link incidents associated with the same affiliate.

Essays

  • The Strings Stay Public (Why Tracing Is Not Enough)

    “In the Inferno Drainer case, thousands of addresses were exploited by the same malware contracts in the same way.”

    · Methods · 5 min read

  • A Scam Made to Measure

    “At the high end sits the bespoke work: drainers and malicious approvals.”

    · Victims · 5 min read

  • Welcome to Constraints

    “If you're starting today, begin with the episodes that came before this one: Episode -4: Inside Inferno Drainer.”

    · Methods · 3 min read

  • Inside Inferno Drainer

    “The malware was Inferno Drainer.”

    · Investigations · 3 min read