In the past year, Wallet Drainers have plagued the crypto community. These are mostly phishing malware. The internet security program Scam Sniffer estimates that fake websites have stolen $295 million from 324,000 people. Malicious methods include compromising authorized Discord and Twitter accounts. They attack project interfaces or libraries by spamming Twitter comments, using Google or Twitter ads, and sending private message phishing campaigns. Unfortunately, these deceptive methods have succeeded in tricking consumers into authorizing dangerous transactions, causing significant financial harm.

Airdrops and Hacks Fuel Surge in Wallet Drainer Thefts
Scam Sniffer’s surveillance shows Wallet Drainers stole $7 million on March 11. Due to fake websites impersonating Circle and abusing USDC exchange rate fluctuations, activity increased. The Arbitrum Discord compromise on March 24 coincided with an airdrop, which increased activity.
Everything from airdrops to hacking correlates with theft increases. After ZachXBT revealed Monkey Drainer, they resigned after six months. Venom then controlled most of its customers. Later groups included MS, Inferno, Angel, and Pink. Venom ceased its services in April, but most phishing gangs found replacements.
Inferno Drainer embezzled $81 million in nine months, compared to Monkey Drainer’s $16 million in six months. A 20% premium helps those who drain their wealth make $47 million selling their services.
Scam Sniffer Distributes 100,000 Domains to Combat Threats
Phishing is on the rise, and when one perpetrator stops, another starts. Angel appears to be Inferno’s replacement. Multiple phishing signatures target different assets, culminating in $50 million in damages. Phishing signatures like Permit, Permit2, Approve, Increase Allowance, and others generate these losses.
The attackers are using smart contracts to improve their approaches. Inferno used multicall to bypass wallet security checks and speed up asset transfers. They use create2 or create functions to dynamically generate temporary addresses, making it difficult for security systems to block them.
Scam Sniffer has reviewed nearly 12 million URLs to identify and classify 145,000 as hazardous to address this growing threat. The platform actively distributes its 100,000-domain blacklist to Chainabuse and other platforms. Scam Sniffer also partners with trusted platforms to protect users and secure Web3 for the next billion users.

