logo svg
logo

August 2, 2026

Updated: August 2, 2026

Crypto Wallet Drainer Statistics 2026: Losses, Victims & Major Operations

Losses, victims, major operations, and methodology for wallet-drainer phishing in 2024 and 2025.

Abdalla Mohamed

Featured Image
Data note: The headline figures primarily reflect Scam Sniffer's observed EVM wallet-drainer and signature-phishing dataset. They are not a complete total for every blockchain or every form of personal-wallet theft.

Wallet-drainer phishing losses rose to $494 million across more than 332,000 affected wallets in 2024, then fell to approximately $83.85 million across 106,106 affected wallets in 2025. The decline is substantial but category-specific: it does not mean broader personal-wallet compromise disappeared.

This 2026 reference uses the latest completed annual wallet-drainer dataset, which currently covers activity through December 2025.

Crypto Wallet Drainer Statistics: Eight Numbers to Know

MetricFigure
2024 losses$494M
2024 affected wallets332K+
2025 losses$83.85M
Loss decline-83%
2025 affected wallets106,106
Wallet decline-68%
Largest 2024 incident$55.4M
Largest 2025 incident$6.5M

Coverage note: The main annual figures reflect Scam Sniffer's observed EVM wallet-drainer dataset and should not be interpreted as a complete total for every blockchain.

Quote Bank for Journalists and Researchers

Wallet Drainer Losses and Victims by Year

YearLossesAffected walletsReporting note
2023~$300M~320,000Original annual headline
2023~$295M~324,000Later comparison baseline
2024$494M332,000+Peak annual loss in cited series
2025$83.85M106,106Losses down 83%; wallets down 68%

Scam Sniffer's reports archive preserves an original 2023 headline near $300 million and 320,000 users, while later comparisons used a baseline near $295 million and 324,000. Both versions are retained to make revisions visible.

Annual Drainer Losses, 2023 to 2025:

Bar chart of observed wallet-drainer phishing losses by year, rising to $494 million in 2024 before falling to $83.85 million in 2025

Figure 1. Observed wallet-drainer phishing losses by year.

Losses rose much faster than the number of affected wallets between 2023 and 2024. This indicates that the 2024 peak was driven not only by broader campaign reach, but also by several unusually costly incidents.

Affected Wallets by Year:

Bar chart of wallets affected by drainer phishing each year, peaking above 332,000 in 2024 and falling to 106,106 in 2025

Figure 2. Affected wallets by year.

The 2025 contraction affected both dimensions of the threat. Fewer wallets were affected, but the decline in financial losses was even steeper, which points to lower average severity as well as reduced reach.

The reduction was also visible at the top end of the distribution: the largest recorded drainer loss fell sharply from 2024 to 2025.

Largest Single Incident, 2024 vs 2025:

Chart comparing the largest recorded single drainer incident, $55.4 million in 2024 against $6.5 million in 2025

Figure 3. Largest recorded drainer incident in 2024 and 2025.

Average Loss per Affected Wallet: DeepStrike Calculation

Using the published totals, the implied loss per affected wallet was approximately $1,488 in 2024 and $790 in 2025, a decline of about 47%. Financial losses therefore fell faster than the number of affected wallets, indicating a material reduction in average incident severity as well as campaign reach.

Calculation note: the 2024 wallet count is reported as more than 332,000, so the 2024 per-wallet figure should be treated as an approximate upper-bound estimate rather than an exact average.

Chart of DeepStrike's calculated implied loss per affected wallet, approximately $1,488 in 2024 falling to $790 in 2025

Figure 4. DeepStrike calculation of implied loss per affected wallet.

What Is a Crypto Wallet Drainer?

A wallet drainer is a phishing tool that tricks a user into authorizing a malicious transaction or signature. A classic drainer usually does not need an exchange login, wallet password, or seed phrase; it abuses approvals such as approve, set Approval For All, Permit, or Permit2. Seed-phrase harvesting and credential theft may occur in the same phishing ecosystem but are distinct from signature-based draining.

How Wallet Drainer Campaigns Reach Victims

Wallet-drainer campaigns depend on distribution as much as malicious code. Attackers place convincing links where users already expect project announcements, support messages, token claims, and wallet prompts.

These channels broaden the article's relevance beyond crypto security to phishing, malvertising, brand protection, community moderation, and social engineering risk.

Major Drainer Operations: Inferno and Pink

DrainerReported impactStatusPrimary evidence
Inferno Drainer>$80MShutdown announced; infrastructure persisted and brand resurfacedGroup-IB: 16,000+ domains, 100+ brands, standard 20% operator share
Pink Drainer>$85M; 21,000+ victimsRetired May 2024SlowMist 2024 Mid-year report reproduces the retirement announcement

Group-IB's Inferno Drainer investigation supports the infrastructure and service-model figures. For Pink Drainer, the SlowMist 2024 Mid-year Blockchain Security and AML Report provides a stronger research source and reproduces the retirement announcement, reporting more than $85 million stolen from over 21,000 victims.

Chart comparing reported impact and operational indicators for Inferno Drainer and Pink Drainer, including theft totals, domains, and victim counts

Figure 5. Reported impact and selected operational indicators for Inferno and Pink Drainer.

Drainer-as-a-Service: Why the Model Scaled

Drainer-as-a-Service lowered the technical barrier for affiliates by providing prebuilt scripts, phishing templates, hosting, dashboards, and operational support. Building and maintaining the core infrastructure still required technical expertise from the service operators.

Why Losses Fell in 2025

The observed decline is consistent with major brand exits, stronger wallet warnings, faster takedowns, changing market conditions, and possible migration to tactics outside the drainer classification. The dataset does not isolate the exact causal contribution of each factor.

The difference between the loss decline and the wallet-count decline is important: it shows that 2025 brought fewer victims and materially smaller losses per affected wallet.

Chart showing wallet-drainer financial losses falling 83 percent while affected wallet counts fell 68 percent between 2024 and 2025

Figure 6. Financial losses fell faster than the number of affected wallets.

The defensible conclusion is correlation, not a precise causal allocation.

Address Poisoning: Related Scam, Not a Drainer

Address poisoning manipulates transaction history so a victim copies a look-alike address. It does not rely on a malicious approval or wallet signature and therefore should not be included in wallet-drainer loss totals.

Wallet Drainers vs. Broader Wallet and Service Risk

CategoryTypical methodsCorrect interpretation
Wallet-drainer phishingMalicious approvals, Permit signatures, cloned dAppsNarrow EVM phishing category
Broader personal-wallet compromiseDrainers, malware, key/seed theft, impersonation, address poisoningWider category; not equivalent to drainers
DeFi protocol exploitProtocol logic, oracles, reentrancy, access controlSmart-contract and protocol risk
Centralized-service compromiseExchange, custody, cloud, signing, internal accessOrganizational infrastructure risk

For the wider view of how these categories add up across the ecosystem, see our crypto hacking incident statistics.

Scope map showing wallet-drainer phishing as a narrow subset within personal-wallet compromise, DeFi protocol exploits, and centralized-service compromise

Figure 7. Scope map showing where wallet-drainer phishing sits within the wider threat landscape.

Methodology Matrix

DatasetMeasuresDoes not necessarily includeBest use
Scam SnifferObserved EVM wallet-drainer and signature-phishing lossesEvery blockchain, all malware, all seed theft, exchange hacksDrainer loss and victim trends
Chainalysis personal-wallet analysisBroader theft from individual walletsDrainer-only breakdownPersonal-wallet risk across techniques
Immunefi DeFi dataExploit-driven DeFi protocol lossesMost retail phishing and centralized-exchange theftProtocol security trends
Chainalysis stolen-funds dataBroad theft across services and individualsWider illicit activity not classed as theftEcosystem-wide stolen value
Group-IB researchDrainer infrastructure and service modelComplete annual market totalsOperation-level analysis

Broader illicit-flow context for these datasets is covered in our crypto crime report.

Data Download

The accompanying CSV records annual losses, affected wallets, largest incidents, source, scope, figure status, verification date, and notes. It is designed for journalists and researchers who need the figures in a reusable format.

PeriodLossesWalletsLargest incidentStatus
2023 original$300M320K-Original headline
2023 revised$295M324K-Later baseline
2024$494M332K+$55.4MSource-reported
2025$83.85M106,106$6.5MSource-reported

How Users and Projects Can Reduce Risk

Frequently Asked Questions

How much did wallet drainers steal in 2024 and 2025?

Scam Sniffer reported approximately $494 million across more than 332,000 affected wallets in 2024 and about $83.85 million across 106,106 affected wallets in 2025.

Are wallet drainers the same as personal-wallet compromises?

No. Wallet-drainer phishing is one subset of personal-wallet compromise, which can also include malware, private-key theft, seed theft, SIM swapping, impersonation, and address poisoning.

What was the largest recorded wallet-drainer theft?

The largest cited loss was approximately $55.4 million in 2024; the largest recorded 2025 incident was approximately $6.5 million.

Why did losses fall in 2025?

Major brand exits, improved wallet warnings, stronger platform response, market conditions, and tactical migration may all have contributed. The dataset does not quantify each factor separately.

What is the difference between a drainer and address poisoning?

A drainer abuses a malicious approval or signature. Address poisoning manipulates transaction history so the user sends funds to a look-alike address.

Are wallet-drainer losses included in broader crypto-theft totals?

They may overlap with broader personal-wallet or stolen-funds datasets, depending on the tracker's methodology. Wallet-drainer, personal-wallet, DeFi, and all-crypto figures should not be added together unless the underlying categories are proven to be mutually exclusive.

Protect Users Against Drainer-Style Attack Paths

A standard penetration test does not automatically evaluate wallet-drainer scenarios. When dApp testing, wallet-flow review, phishing simulation, social-engineering testing, brand-impersonation assessment, or adversary-emulation objectives are explicitly included in scope, an assessment can test whether the relevant technical and human controls withstand drainer-style attack paths.

Explore DeepStrike's penetration testing services to scope an engagement around these attack paths.

About the Author

Abdalla is an offensive security engineer at DeepStrike, where he runs penetration tests across web applications, cloud infrastructure, and internal networks. He breaks into systems so defenders can fix them first and writes about the attack paths he sees most often in real engagements.

background
Let's hack you before real hackers do

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today

Contact Us