OAK — OnChain Attack Knowledge

Worked example · 2024-10

Inferno Drainer service ecosystem — multi-chain — operating ~2022 through November 2023 (Telegram-announced shutdown; affiliate / kit re-emergence under successor branding)

Attribution
pseudonymous — no public actor attribution at OAK v0.1 cutoff.
Loss
the 2023 wallet-drainer ecosystem total (across Inferno and peer services — Angel, Pink, Monkey, Venom) was approximately ~$494M in user losses (per SlowMist 2024 report). This figure is an ecosystem aggregate, not Inferno-specific. Inferno was a major contributor within that ecosystem total; the largest single per-victim theft attributed to Inferno or its affiliates was ~$55.48M. Per-incident losses across the thousands of affiliate-run campaigns are not individually itemized at the OAK v0.1 cutoff.
Operating period
approximately 2022 through November 26, 2023 (Telegram-announced shutdown of the branded operation; affiliates / kit / tooling re-emerge under successor branding through 2024).
OAK Techniques observed
OAK-T4.001 (Permit2 Authority Misuse, primary), OAK-T4.002 (Compromised Front-End Permit Solicitation, occasional), OAK-T4.004 (Allowance / Approve-Pattern Drainer), OAK-T7.001 (Mixer-Routed Hop) shifting toward OAK-T7.003 (Cross-Chain Bridge Laundering) through 2024, OAK-T8.001 (Common-Funder Cluster Reuse) at the service-infrastructure layer, OAK-T8.002 (Cross-Chain Operator Continuity, broadly construed) for the affiliate / infrastructure persistence across the Inferno → successor brand-retirement event.
OAK-G02 attribution
Inferno Drainer was the canonical dominant named drainer-service through its active window within OAK-G02 — see actors/OAK-G02-drainer-services.md.
Status
Inferno announced shutdown of branded operations via Telegram on November 26, 2023; concurrent fee-collection-address outflow event; the kit, affiliate base, and laundering-route tooling subsequently re-surfaced under successor branding (Angel Drainer / OAK-S02 absorbing the largest share of affiliate continuity through 2024).
Key teaching point
Inferno Drainer is the canonical service-level demonstration that, in the Drainer-as-a-Service category, service-infrastructure persistence is a stronger attribution signal than operator-name persistence. The November 2023 branded-operation shutdown and subsequent 2024 re-emergence under successor branding (Angel Drainer) demonstrated that the drainer kits, affiliate base, spender-address clusters, and laundering-route packaging were not retired — only the brand was. Defenders relying on operator-name watchlists will systematically underperform defenders relying on infrastructure-cluster watchlists across brand-retirement events.

Timeline (UTC unless noted)

When Event OAK ref
~2022 Commercial drainer services proliferate alongside Permit2 adoption; Inferno Drainer enters the market as one of several operators (Pink, Monkey, Venom, Angel) T4.001 (Permit2 signature phishing — service emergence)
2022 → 2023 Inferno becomes the dominant named operator in the drainer-service category; recurring on-chain spender addresses become observable enough for wallet-side warning lists and exchange deposit-screening rules T8.001 (common-funder cluster reuse at service-infrastructure layer)
2023 Wallet-drainer ecosystem total reaches ~$494M (SlowMist 2024 report); Inferno a major contributor; largest single per-victim theft ~$55.48M T4.001 + T4.004 (Permit2 and approve-pattern extraction at service scale)
2023-11-26 Inferno announces branded-operation shutdown via Telegram; concurrent fee-collection-address outflow event visible on-chain T8.002 (brand retirement — infrastructure persists)
2024 Inferno's kit, affiliate base, and laundering-route tooling re-emerge under successor branding (Angel Drainer / OAK-S02 absorbing largest share of continuity); parallel persistence in Pink (OAK-S03), Venom (OAK-S05), and new entrants Vanilla / Chick T8.002 (cross-chain operator continuity via infrastructure persistence)
2024 Laundering-rail shift observed: T7.001 (Tornado Cash) baseline with progressive substitution toward T7.003 (cross-chain bridge laundering) for sophisticated operators T7.003 (laundering-rail evolution at service level)
Continuing Inferno's infrastructure-level continuity across brand-retirement events remains the canonical demonstration that per-infrastructure attribution beats per-brand attribution in the OAK-G02 category (canonical service-level reference — infrastructure persistence)

Summary

Inferno Drainer was, through 2023, the dominant commercial phishing-as-a-service operator in the OAK-G02 category. It is included in the OAK examples corpus as a service-level worked example — distinct from a per-incident example because the Technique chain plays out across thousands of per-affiliate-per-victim incidents over the service's active period rather than as a single dated event with a named victim and a named amount. The framing follows examples/2023-02-jaredfromsubway-mev.md: operator-profile rather than incident-timeline.

The November 26, 2023 Telegram-announced shutdown of Inferno's branded operation is, from a defender's perspective, the most informative single event in the operator's lifecycle — not because it changed the underlying attack flows (it did not), but because it demonstrated, on the public record, that drainer-service infrastructure (kit, affiliate base, laundering routes) persists across operator-brand retirement events. That demonstration — affiliates and tooling re-surfacing under Angel Drainer (OAK-S02) and parallel successors over 2024 — is the canonical case for treating service-infrastructure continuity as the durable attribution surface in this category, as flagged on the OAK-G02 actor page.

Operating-period overview

Rather than an incident timeline, this example characterises the service across its active window:

  • ~2022 — emergence. Commercial drainer services proliferate alongside Permit2 adoption. Inferno Drainer enters the market as one of several service operators (alongside Pink, Monkey, Venom, Angel, others). The economic model is consistent across the category: ready-made drainer kits (cloned UIs, signature-phishing flows, laundering-route packaging) provided to affiliates; affiliates run per-victim phishing; service operator collects a cut.
  • 2023 — service maturation and dominance. Per [checkpoint2023drainers], recurring on-chain spender addresses associated with Inferno (and peer services) become observable enough that wallet-side warning lists and exchange-side deposit-screening rules begin to track them. Permit (EIP-2612) and Permit2 signature-phishing flows become the dominant Technique within the category, with setApprovalForAll (NFT) and standard approve flows as recurring alternatives. Inferno is the dominant single named operator within the OAK-G02 cohort; the largest single per-victim theft attributed to Inferno or its affiliates in this window was ~$55.48M.
  • November 26, 2023 — branded-operation shutdown. Inferno announced via Telegram that it was shutting down its branded operation; a concurrent fee-collection-address outflow event was visible on-chain. The drainer kit, affiliate base, and laundering-route tooling were not retired with the brand — they progressively re-surfaced under successor branding through 2024.
  • 2024 — successor continuity. Through 2024 the affiliate / kit / spender-cluster continuity migrated primarily to Angel Drainer (OAK-S02) with parallel persistence in Pink (OAK-S03), Venom (OAK-S05), and newer entrants Vanilla / Chick. The 2023 wallet-drainer ecosystem total of ~$494M (per [slowmist2024report]) is the 2023 collective figure across all drainer operators; per-operator decomposition for the 2024 successor cohort is not separately published at high enough fidelity to attribute to a single named successor at confirmed strength.
  • Post-shutdown attribution guidance. Per [slowmist2024report] and the OAK-G02 actor page, post-November-2023 drainer activity should be attributed at the service-infrastructure level (spender-cluster, funder-graph, routing-contract bytecode) rather than at the named-operator level. OAK-G02 makes this guidance explicit; the Inferno → successor-cohort persistence is its primary justification.

What defenders observed (ecosystem-level signals)

These are signals visible to defenders watching the category, not signals reconstructed from any single victim's transaction graph:

  • Per-spender-cluster inflow concentration. Recurring Inferno-associated spender addresses produced calibratable inflow signatures over the active window — suitable for inclusion in wallet-vendor warning lists, exchange-side deposit screening rules, and OAK-T8.001 funder-graph models. Per [checkpoint2023drainers], the canonical observation is that on-chain spender re-use across affiliate campaigns is more durable than per-affiliate-domain rotation.
  • Permit / Permit2-signature volume share. A large share of attributed phishing volume across the category routed through permit-class signatures ([slowmist2024report]); this is the empirical base rate behind OAK-T4.001 being listed as the primary Technique on the OAK-G02 actor page.
  • Allowance-pattern flows as the alternate path. OAK-T4.004 remained an active alternate flow when affiliates targeted protocols or wallets without convenient permit-signature surfaces; this is documented in [checkpoint2023drainers] at the spender-address level.
  • DNS / hosting compromise as occasional entry vector. OAK-T4.002 cases, in which an affiliate gains DNS or hosting control over a known protocol's UI to serve a permit-solicitation page, are an occasional but recurring entry vector across the category. The 2022 Curve Finance DNS hijack documented in examples/2022-08-curve-dns-hijack.md is the canonical T4.002 case adjacent to this category, although the Curve hijack was not specifically attributed to Inferno.
  • Laundering-rail shift across 2024. Through 2024, OAK-T7.001 (Mixer-Routed Hop) remained a baseline laundering route, but the broader trend documented in [chainalysis2024dprk] and the Chainalysis 2024 laundering retrospective shows progressive substitution toward OAK-T7.003 (Cross-Chain Bridge Laundering) for sophisticated operators in the wider ecosystem. Drainer-service laundering routes through 2024 broadly track the same shift, though category-specific rail decomposition is not separately published.
  • Branded-operation shutdown signature. The November 26, 2023 fee-collection-address outflow event concurrent with the public Telegram shutdown announcement is an OAK-T8.002-like signal: not a single operator moving across chains, but the orderly wind-down of one branded service while the underlying tooling and affiliate base persist for re-emergence under successor branding (Angel Drainer / OAK-S02 absorbing the largest share of continuity through 2024).

What this example tells contributors writing future Technique pages

  • Operator-profile vs incident-timeline framing. Some Techniques and some actors are characterised by services and operators rather than by incidents. OAK-T4.001 within OAK-G02 is the clearest example — there is no canonical single Inferno incident the way there is a canonical single AnubisDAO incident; the category is empirically defined by aggregate volume across thousands of per-victim events. Future contributors writing examples for any Technique heavily used by a service-class operator should plan to publish a service-level write-up alongside (or instead of) per-incident write-ups.
  • Service-infrastructure continuity beats operator-name continuity. The Inferno (November 2023 shutdown) → Angel Drainer (2024 successor cohort) re-emergence is the canonical demonstration that, in the OAK-G02 category, infrastructure (drainer kits, spender-address clusters, affiliate base, laundering routes) is the durable entity, not the operator name. OAK-G02 makes this explicit in its discussion section. Contributors writing T8.001 and T8.002 worked examples in this category should anchor on funder-graph and infrastructure-cluster persistence, not on the brand name attached to the service in any given quarter.
  • Affiliate-attribution-difficulty caveat. Per-victim attribution in this category typically lands on the affiliate, not the service operator. Per-incident operator-of-record attributions are typically inferred-weak unless a specific affiliate has been publicly identified by an authoritative source (rare). Contributors writing per-incident examples in OAK-G02 should preserve attribution-level language and avoid claiming a specific named affiliate without a published source. The service-level write-up, by contrast, can be inferred-strong at the infrastructure-cluster layer where industry forensic providers have published consistent attribution.
  • Public industry-report aggregates are an acceptable primary source for service-level examples. When the operator's volume is continuously characterised by neutral forensic providers (SlowMist, Check Point Research, Chainalysis, Scam Sniffer), OAK accepts the aggregate retrospective as a primary reference. The equivalent of a per-victim forensic write-up at the service level is the annual ecosystem report.

Public references

  • [slowmist2024report] — canonical source for the 2023 wallet-drainer ecosystem total (~$494M across all named operators collectively; this is a 2023 ecosystem number, not an Inferno-specific figure or a 2024 figure), Inferno's ~$55.48M peak single theft, the November 26 2023 Inferno shutdown announcement, and the concurrent fee-collection-address outflow event.
  • [checkpoint2023drainers] — recurring on-chain spender addresses tied to Inferno, Angel, and successor families; documents Permit (EIP-2612), Permit2, and approve / setApprovalForAll attack flows.
  • [chainalysis2024dprk] — broader-context reference for the 2024 laundering-rail shift toward cross-chain-bridge-laundering as the dominant evolution for sophisticated operators (cited here for ecosystem context, not as a direct Inferno attribution).
  • Industry reporting on the November 26 2023 shutdown (e.g., contemporaneous coverage by Scam Sniffer, BleepingComputer, BeInCrypto) corroborates the SlowMist account; specific URLs to be added to citations.bib in a v0.x update once a single canonical source is selected.

Discussion

Inferno Drainer is the canonical service-level demonstration of OAK-G02's central thesis: in the drainer-service category, service-infrastructure persistence is a stronger attribution signal than operator-name persistence. The November 26, 2023 shutdown of the Inferno brand and the subsequent 2024 re-emergence of the affiliate base, kit, and laundering-route tooling under successor branding (Angel Drainer / OAK-S02 the most prominent continuation) is the cleanest public-record demonstration of that thesis to date. The drainer kits, the affiliate base, the spender-address clusters, the laundering-route packaging — none of these were retired. Only the brand was.

For OAK contributors, the operational implication is that defenders relying on operator-name watchlists for this category will reliably underperform defenders relying on infrastructure-cluster watchlists across handover events. The named operators in the category (Inferno, Angel, Pink, Monkey, Venom, and successors) routinely transfer operations, branding, or affiliates between each other; per-name continuity is weaker than per-infrastructure continuity. OAK's framing — Technique-level mitigations targeted at the service layer, attribution-level language calibrated to the infrastructure-cluster layer, OAK-G02 grouping at the category layer — is structured around this asymmetry.

Per-incident worked examples in this category should land on the affiliate-execution layer (the per-victim phishing transaction, the permit signature, the drained wallet) and remain explicitly inferred-weak about which named service operator was the upstream provider unless a published source establishes the link. Service-level worked examples like this one belong at the OAK-G02 layer, where industry-forensic-provider aggregates support inferred-strong attribution. The two layers should not be conflated.

Techniques demonstrated (7)