Inside Inferno Drainer

A DeFi protocol’s social media account got hijacked. Fake airdrop, cloned site, one phishing link, one malicious signature, wallets drained.
The malware was Inferno Drainer. And for two days, I couldn’t tell you who pulled the trigger.
Let me show you why, in plain terms.
When a victim approves the malicious transaction, their crypto doesn’t go straight to the thief. It flows through a chain of automated contracts. A throwaway “forwarder” contract (created on the spot, used once, never again) passes the native crypto into one shared contract that acts as the collection point for the loot. From there the operator can pull out their 80%. The remaining 20% goes to the people who built the malware. Other tokens get auto-split the same way, 80/20, in the same instant (with or without throwaway “forwarders” depending on the case).

Clean. Industrial. And shared.
That last word is the whole problem.
Inferno Drainer is malware-as-a-service. Hundreds of independent criminals rent the exact same kit and push everything through the exact same contracts. That’s not a flaw. That’s the product. The shared infrastructure IS the anonymity.
You’re not one thief in a room. You’re one thief in a stadium, and every move you make looks identical to everyone else’s.
So I started where the money pools: that single shared collection contract (Smart Contract A). I pulled every address that ever took funds out of it.
Thousands came back.
Thousands of wallets, all looking identical. One of them ran the attack I was hunting. The rest were strangers, robbing other people, the same timeframe, with the same tool. No names. No labels. Nothing that said “this is the one.”
This is the moment the malware is designed for.
The point where a couple of obvious searches (E.g. time window query) come back with nothing, and most people write “untraceable” in the report and close the file.
I didn’t have a single thing that separated my attacker from the crowd.
So I stopped looking at the crowd. And I asked a different question.
Who did this attacker actually target?
Not random people. They cloned ONE specific protocol. So their victims weren’t random either, they were people who held that protocol’s tokens and the respective collateral. And if you’re the operator who handled all those drained wallets, your own address has to carry the residue: those same tokens showing up in your history far more than any unrelated criminal’s would.
That was the crack in the wall.
So I ran one query.
Take that pile of thousands, and keep only the addresses that ever touched the 34 token contracts belonging to that protocol’s ecosystem. I built it on Dune and turned the result into a heat map (think of it as a brightness score, where the more an address connects to those tokens, the hotter it glows).
Thousands collapsed to 32.
And inside those 32, one address didn’t just touch a token or two. It lit up across the entire board. Every ecosystem asset, all of it, on a single wallet, with the exact timing of the attack: funds arriving the moment the fake sites went live, activity stopping the moment the campaign ended.
Not a coincidence. A confession written in timestamps.
That became the Threat Actor’s Address. From that one anchor, everything unspooled: every victim’s wallet identified, and the money traced forward through bridges and laundering tricks designed to shake investigators off, all the way to deposit accounts inside exchanges that know exactly who opened them.
The attacker hid inside shared infrastructure, thinking the crowd was cover.
The crowd was the dataset.
Next: Wallet Balances
Also published on LinkedIn.