Skip to main content
AVOID.NET
Lucifer Drainerreviewed 2026-09-09 · 19 claims checked

Fact-check findings

What an automated fact-checker found when it re-read Lucifer Drainer against the sources the page cites. Only the most recent review is shown.

Read this first

These findings are produced by an automated reviewer, and its results vary between runs: the same page, checked three times on the same day, came back with 15%, 20% and 34% of its claims disputed, mostly because each run extracted a different number of claims. Treat what follows as leads, not rulings.

“Disputed” means the reviewer could not reconcile the claim with the evidence it cited. It does not mean the claim is false. “Unverifiable” means no reachable source settled it either way.

Nothing here changes the page on its own. A proposed correction is applied only after a human moderator approves it; until then the page reads as it did when reviewed.

disputed

1 claim

The reviewer could not reconcile the claim with the evidence it cited. This is a lead, not a ruling that the claim is false.

  1. #7[disputed][awaiting moderator]in section: Ecosystem Context and Predecessor Drainers
    Inferno Drainer, which claimed responsibility for $250 million in total thefts, announced a shutdown in November 2023
    reviewerInferno Drainer claimed responsibility for $250 million in total thefts when it announced a shutdown in November 2023.This sentence conflates two different claims: the ~$80 million figure widely reported at the time of the November 2023 shutdown (which the page's own timeline entry, sourced to the same CryptoNews article, correctly states) and a later $250 million lifetime total the operators themselves claimed by May 2024, per Check Point's 2025 resurgence research. As written, the sentence misattributes the $250M figure to the November 2023 announcement, contradicting the page's own timeline entry for the identical event.
    Proposed correction (not yet applied)
    Inferno Drainer, which claimed responsibility for over $80 million in total thefts, announced a shutdown in November 2023

unverifiable

1 claim

No source the reviewer could reach confirms or contradicts the claim.

  1. #17[unverifiable][awaiting moderator]in section: Operator Anonymity and Attribution
    No public attribution of the Lucifer Drainer operators' real-world identities has been reported as of June 2026.
    reviewerNo public attribution of Lucifer Drainer operators' identities as of June 2026; no law enforcement actions, indictments, or arrests publicly associated with this operation.This is a negative/absence claim (no attribution, no law enforcement action) as of a date one month after the cited May 2026 article's publication. A negative claim of this kind cannot be affirmatively confirmed by search; no contradicting reports of an arrest or unmasking were found, but that does not rule one out. Marked unverifiable rather than confirmed.

partially supported

1 claim

The cited evidence supports part of the claim but not all of it.

  1. #18[partially supported][awaiting moderator]in section: User Risk and Protection Guidance
    Lucifer-affiliated phishing sites distribute wallets through phishing links, fake websites, compromised social media accounts, malicious advertisements, spam, and direct messages.
    reviewerSentinelOne research discusses drainer distribution via phishing links, fake websites, compromised social media, malicious ads, spam, and DMs; general Permit2/EIP-712 risk framing for user protection guidance.The distribution-channel list is well supported for drainer phishing generally, but SentinelOne's piece does not discuss Lucifer Drainer specifically, so attributing these exact channels to 'Lucifer-affiliated phishing sites' by name slightly overstates what the cited source itself documents (it documents the DaaS ecosystem, not Lucifer).

confirmed

16 claims

The cited evidence supports the claim as written.

  1. #1[confirmed][no action needed]in section: Overview and Classification
    Researchers at Flare analyzed approximately 700 posts collected from underground forums, chats, and channels associated with Lucifer DaaS between January 2025 and early 2026, documenting its internal operations and finding characteristics consistent with professionalized software-as-a-service businesses: product versioning, release notes, bug-fix cycles, customer support, referral systems, and affiliate onboarding.
    reviewerFlare researchers analyzed approximately 700 posts from underground forums/chats/channels about Lucifer DaaS, collected January 2025 through early 2026, documenting SaaS-like professionalization (versioning, release notes, bug-fix cycles, customer support, referral systems, affiliate onboarding).Confirmed via a syndicated mirror of the cited Bleeping Computer piece, since the original returned 403 to direct fetch.
  2. #2[confirmed][no action needed]in section: Overview and Classification
    The platform occupies a dominant position in the current drainer ecosystem, recruiting from communities where predecessor brands including Inferno, Angel, Venom, Nova, Ghost, Medusa, Vega, and Monkey Drainer were previously active.
    reviewerLucifer recruits from communities where predecessor brands Inferno, Angel, Venom, Nova, Ghost, Medusa, Vega, and Monkey Drainer were previously active.Matches source closely.
  3. #3[confirmed][no action needed]in section: Business Model and Affiliate Structure
    The operators explicitly state that the software is not for sale and cannot be leased; the only participation mode is affiliate revenue sharing. Operators retain 20% of each successful drain while affiliates receive 80%.
    reviewerOperators state the software is not for sale/cannot be leased; only participation mode is affiliate revenue sharing, with operators retaining 20% and affiliates 80%.Confirmed.
  4. #4[confirmed][no action needed]in section: Business Model and Affiliate Structure
    BlockSec's joint research with Zhejiang University and MBZUAI analyzed $135 million in on-chain drainer activity from March 2023 to April 2025 and found a 20/80 operator-affiliate split was the dominant model across 1,910 profit-sharing contracts and 87,077 profit-sharing transactions involving 56 operator accounts and 6,087 affiliate accounts.
    reviewerBlockSec's joint research with Zhejiang University and MBZUAI analyzed $135 million in on-chain drainer activity from March 2023 to April 2025, found a 20/80 operator-affiliate split as dominant across 1,910 profit-sharing contracts and 87,077 profit-sharing transactions involving 56 operator accounts and 6,087 affiliate accounts.All figures verified against the cited primary source.
  5. #5[confirmed][no action needed]in section: Technical Capabilities
    Version 6.6.6, announced in March 2025, advertised the following features: ERC-20 token support, Permit2 abuse, off-chain signature exploitation, Telegram notifications for affiliates, wallet-security bypass mechanisms, and multichain deployment.
    reviewerVersion 6.6.6, announced March 2025, advertised ERC-20 support, Permit2 abuse, off-chain signature exploitation, Telegram notifications, wallet-security bypass, multichain deployment, 'Zero Config' deployment, and website-cloning.Confirmed via mirror of the primary source.
  6. #6[confirmed][no action needed]in section: Operational Resilience and Infrastructure
    In August 2025, Telegram banned the operation's bots. Rather than folding, the operators issued instructions to their affiliate channel directing users to create replacement bots and grant them admin privileges. In November 2025, a documentation domain hosted on Google Firebase was suspended following exposure in security research. The operators responded by migrating all documentation to IPFS (InterPlanetary File System), explicitly framing decentralization as a countermeasure against future takedowns.
    reviewerTelegram banned Lucifer's bots in August 2025; operators told affiliates to create replacement bots with admin privileges. Firebase-hosted documentation domain was suspended in November 2025; operators migrated documentation to IPFS.Confirmed via mirror of the primary source.
  7. #8[confirmed][no action needed]in the timeline
    Inferno Drainer announces shutdown after claiming over $80 million in total theft; later found to have continued operations covertly.
    reviewerInferno Drainer announces shutdown after claiming over $80 million in total theft (November 2023).This timeline entry is accurate and is the correct figure; it is the sections[4] Ecosystem Context sentence that contradicts it by using $250 million for the same event. Grouped under the same defect since both describe the November 2023 Inferno shutdown total.
  8. #9[confirmed][no action needed]in section: Ecosystem Context and Predecessor Drainers
    was later confirmed by Check Point Research to have resurfaced and stolen at least $9 million from 30,000+ wallets in a subsequent six-month period
    reviewerCheck Point Research confirmed Inferno Drainer resurfaced and stole at least $9 million from 30,000+ wallets over a subsequent six-month period.Matches source precisely.
  9. #10[confirmed][no action needed]in section: Ecosystem Context and Predecessor Drainers
    In October 2024, Inferno announced it was handing its platform to Angel Drainer.
    reviewerIn October 2024, Inferno announced it was handing its platform to Angel Drainer.Confirmed via corroborating independent coverage since the CryptoRank source itself blocked direct fetch.
  10. #11[confirmed][no action needed]in section: Ecosystem Context and Predecessor Drainers
    Angel Drainer was itself shut down in July 2024 after researchers at Match Systems alleged they had de-anonymized its developers — but it resurfaced as AngelX within weeks, deploying over 300 malicious dApps in four days.
    reviewerAngel Drainer was shut down in July 2024 after Match Systems alleged it had de-anonymized its developers, then resurfaced as AngelX within weeks, deploying 300+ malicious dApps in four days.Core facts confirmed; 'within weeks' for a ~6-week gap is loose but defensible phrasing, not flagged as a separate defect.
  11. #12[confirmed][no action needed]in section: Ecosystem Context and Predecessor Drainers
    Pink Drainer ceased operations in May 2024 after stealing approximately $85 million from over 21,000 victims.
    reviewerPink Drainer ceased operations in May 2024 after stealing approximately $85 million from over 21,000 victims.Confirmed, and date_original in timeline aligns with independently found publish date.
  12. #13[confirmed][no action needed]in section: Ecosystem Context and Predecessor Drainers
    Scam Sniffer reported that aggregate crypto phishing losses declined from $494 million in 2024 to approximately $83.85 million in 2025
    reviewerScam Sniffer reported aggregate crypto phishing losses declined from $494 million in 2024 to approximately $83.85 million in 2025.Confirmed via corroborating coverage of the same Scam Sniffer report; recommend the judge treat the direct-fetch 404 as inconclusive given multiple independent citations of a live-indexed URL.
  13. #14[confirmed][no action needed]in section: Broader DaaS Industry Impact
    The three platforms that dominated this period — Angel Drainer ($53.1 million), Inferno Drainer ($59 million), and Pink Drainer ($14.7 million) — have all since reduced operations or exited.
    reviewerBlockSec's study found $135M attributed to the DaaS ecosystem on Ethereum with 76,582 victims; Angel Drainer ($53.1M), Inferno Drainer ($59M), Pink Drainer ($14.7M) dominated; only 10.8% of DaaS-related addresses had been previously flagged by trackers like Etherscan.All figures verified against the primary research source.
  14. #15[confirmed][no action needed]in section: Broader DaaS Industry Impact
    The broader 2024 phishing-drainer wave resulted in $494 million in losses across 332,000 wallet addresses.
    reviewerThe broader 2024 phishing-drainer wave resulted in $494 million in losses across 332,000 wallet addresses.Confirmed.
  15. #16[confirmed][no action needed]in section: Broader DaaS Industry Impact
    While 2025 showed an 83% decline in aggregate losses to approximately $83.85 million, the drainer ecosystem continued to operate with new entrants, adapted techniques (including EIP-7702 account abstraction exploits after the Ethereum Pectra upgrade), and persistent affiliate networks.
    reviewer2025 showed an 83% decline in aggregate losses to approximately $83.85 million, with the drainer ecosystem adapting via EIP-7702 account abstraction exploits after the Ethereum Pectra upgrade.Confirmed via independent corroboration of the Scam Sniffer 2025 report.
  16. #19[confirmed][no action needed]in section: User Risk and Protection Guidance
    Once a victim signs a malicious EIP-712 Permit2 message, the attacker can drain approved tokens in a single subsequent on-chain transaction with no further user interaction required.
    reviewerOnce a victim signs a malicious EIP-712 Permit2 message, the attacker can drain approved tokens in a single subsequent on-chain transaction with no further user interaction required.Mechanism is also consistent with general EIP-2612/Permit2 technical documentation; treated as confirmed on the strength of corroborating search results despite the direct-fetch failure.
How this fits together. The reviewer reads the published page and its cited sources and records one finding per claim. A human moderator decides whether each proposed correction is applied; those decisions, and the score changes they cause, appear in the audit log. Earlier review runs are not shown here; only the latest reflects the page as it stands.