August 2, 2026
Updated: August 2, 2026
Losses, victims, major operations, and methodology for wallet-drainer phishing in 2024 and 2025.
Abdalla Mohamed

Data note: The headline figures primarily reflect Scam Sniffer's observed EVM wallet-drainer and signature-phishing dataset. They are not a complete total for every blockchain or every form of personal-wallet theft.
Wallet-drainer phishing losses rose to $494 million across more than 332,000 affected wallets in 2024, then fell to approximately $83.85 million across 106,106 affected wallets in 2025. The decline is substantial but category-specific: it does not mean broader personal-wallet compromise disappeared.
This 2026 reference uses the latest completed annual wallet-drainer dataset, which currently covers activity through December 2025.
| Metric | Figure |
|---|---|
| 2024 losses | $494M |
| 2024 affected wallets | 332K+ |
| 2025 losses | $83.85M |
| Loss decline | -83% |
| 2025 affected wallets | 106,106 |
| Wallet decline | -68% |
| Largest 2024 incident | $55.4M |
| Largest 2025 incident | $6.5M |
Coverage note: The main annual figures reflect Scam Sniffer's observed EVM wallet-drainer dataset and should not be interpreted as a complete total for every blockchain.
| Year | Losses | Affected wallets | Reporting note |
|---|---|---|---|
| 2023 | ~$300M | ~320,000 | Original annual headline |
| 2023 | ~$295M | ~324,000 | Later comparison baseline |
| 2024 | $494M | 332,000+ | Peak annual loss in cited series |
| 2025 | $83.85M | 106,106 | Losses down 83%; wallets down 68% |
Scam Sniffer's reports archive preserves an original 2023 headline near $300 million and 320,000 users, while later comparisons used a baseline near $295 million and 324,000. Both versions are retained to make revisions visible.
Annual Drainer Losses, 2023 to 2025:

Figure 1. Observed wallet-drainer phishing losses by year.
Losses rose much faster than the number of affected wallets between 2023 and 2024. This indicates that the 2024 peak was driven not only by broader campaign reach, but also by several unusually costly incidents.
Affected Wallets by Year:

Figure 2. Affected wallets by year.
The 2025 contraction affected both dimensions of the threat. Fewer wallets were affected, but the decline in financial losses was even steeper, which points to lower average severity as well as reduced reach.
The reduction was also visible at the top end of the distribution: the largest recorded drainer loss fell sharply from 2024 to 2025.
Largest Single Incident, 2024 vs 2025:

Figure 3. Largest recorded drainer incident in 2024 and 2025.
Using the published totals, the implied loss per affected wallet was approximately $1,488 in 2024 and $790 in 2025, a decline of about 47%. Financial losses therefore fell faster than the number of affected wallets, indicating a material reduction in average incident severity as well as campaign reach.
Calculation note: the 2024 wallet count is reported as more than 332,000, so the 2024 per-wallet figure should be treated as an approximate upper-bound estimate rather than an exact average.

Figure 4. DeepStrike calculation of implied loss per affected wallet.
A wallet drainer is a phishing tool that tricks a user into authorizing a malicious transaction or signature. A classic drainer usually does not need an exchange login, wallet password, or seed phrase; it abuses approvals such as approve, set Approval For All, Permit, or Permit2. Seed-phrase harvesting and credential theft may occur in the same phishing ecosystem but are distinct from signature-based draining.
Wallet-drainer campaigns depend on distribution as much as malicious code. Attackers place convincing links where users already expect project announcements, support messages, token claims, and wallet prompts.
These channels broaden the article's relevance beyond crypto security to phishing, malvertising, brand protection, community moderation, and social engineering risk.
| Drainer | Reported impact | Status | Primary evidence |
|---|---|---|---|
| Inferno Drainer | >$80M | Shutdown announced; infrastructure persisted and brand resurfaced | Group-IB: 16,000+ domains, 100+ brands, standard 20% operator share |
| Pink Drainer | >$85M; 21,000+ victims | Retired May 2024 | SlowMist 2024 Mid-year report reproduces the retirement announcement |
Group-IB's Inferno Drainer investigation supports the infrastructure and service-model figures. For Pink Drainer, the SlowMist 2024 Mid-year Blockchain Security and AML Report provides a stronger research source and reproduces the retirement announcement, reporting more than $85 million stolen from over 21,000 victims.

Figure 5. Reported impact and selected operational indicators for Inferno and Pink Drainer.
Drainer-as-a-Service lowered the technical barrier for affiliates by providing prebuilt scripts, phishing templates, hosting, dashboards, and operational support. Building and maintaining the core infrastructure still required technical expertise from the service operators.
The observed decline is consistent with major brand exits, stronger wallet warnings, faster takedowns, changing market conditions, and possible migration to tactics outside the drainer classification. The dataset does not isolate the exact causal contribution of each factor.
The difference between the loss decline and the wallet-count decline is important: it shows that 2025 brought fewer victims and materially smaller losses per affected wallet.

Figure 6. Financial losses fell faster than the number of affected wallets.
The defensible conclusion is correlation, not a precise causal allocation.
Address poisoning manipulates transaction history so a victim copies a look-alike address. It does not rely on a malicious approval or wallet signature and therefore should not be included in wallet-drainer loss totals.
| Category | Typical methods | Correct interpretation |
|---|---|---|
| Wallet-drainer phishing | Malicious approvals, Permit signatures, cloned dApps | Narrow EVM phishing category |
| Broader personal-wallet compromise | Drainers, malware, key/seed theft, impersonation, address poisoning | Wider category; not equivalent to drainers |
| DeFi protocol exploit | Protocol logic, oracles, reentrancy, access control | Smart-contract and protocol risk |
| Centralized-service compromise | Exchange, custody, cloud, signing, internal access | Organizational infrastructure risk |
For the wider view of how these categories add up across the ecosystem, see our crypto hacking incident statistics.

Figure 7. Scope map showing where wallet-drainer phishing sits within the wider threat landscape.
| Dataset | Measures | Does not necessarily include | Best use |
|---|---|---|---|
| Scam Sniffer | Observed EVM wallet-drainer and signature-phishing losses | Every blockchain, all malware, all seed theft, exchange hacks | Drainer loss and victim trends |
| Chainalysis personal-wallet analysis | Broader theft from individual wallets | Drainer-only breakdown | Personal-wallet risk across techniques |
| Immunefi DeFi data | Exploit-driven DeFi protocol losses | Most retail phishing and centralized-exchange theft | Protocol security trends |
| Chainalysis stolen-funds data | Broad theft across services and individuals | Wider illicit activity not classed as theft | Ecosystem-wide stolen value |
| Group-IB research | Drainer infrastructure and service model | Complete annual market totals | Operation-level analysis |
Broader illicit-flow context for these datasets is covered in our crypto crime report.
The accompanying CSV records annual losses, affected wallets, largest incidents, source, scope, figure status, verification date, and notes. It is designed for journalists and researchers who need the figures in a reusable format.
| Period | Losses | Wallets | Largest incident | Status |
|---|---|---|---|---|
| 2023 original | $300M | 320K | - | Original headline |
| 2023 revised | $295M | 324K | - | Later baseline |
| 2024 | $494M | 332K+ | $55.4M | Source-reported |
| 2025 | $83.85M | 106,106 | $6.5M | Source-reported |
Scam Sniffer reported approximately $494 million across more than 332,000 affected wallets in 2024 and about $83.85 million across 106,106 affected wallets in 2025.
No. Wallet-drainer phishing is one subset of personal-wallet compromise, which can also include malware, private-key theft, seed theft, SIM swapping, impersonation, and address poisoning.
The largest cited loss was approximately $55.4 million in 2024; the largest recorded 2025 incident was approximately $6.5 million.
Major brand exits, improved wallet warnings, stronger platform response, market conditions, and tactical migration may all have contributed. The dataset does not quantify each factor separately.
A drainer abuses a malicious approval or signature. Address poisoning manipulates transaction history so the user sends funds to a look-alike address.
They may overlap with broader personal-wallet or stolen-funds datasets, depending on the tracker's methodology. Wallet-drainer, personal-wallet, DeFi, and all-crypto figures should not be added together unless the underlying categories are proven to be mutually exclusive.
A standard penetration test does not automatically evaluate wallet-drainer scenarios. When dApp testing, wallet-flow review, phishing simulation, social-engineering testing, brand-impersonation assessment, or adversary-emulation objectives are explicitly included in scope, an assessment can test whether the relevant technical and human controls withstand drainer-style attack paths.
Explore DeepStrike's penetration testing services to scope an engagement around these attack paths.
Abdalla is an offensive security engineer at DeepStrike, where he runs penetration tests across web applications, cloud infrastructure, and internal networks. He breaks into systems so defenders can fix them first and writes about the attack paths he sees most often in real engagements.

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us