Crypto Wallet Drainer Scams: How They Work and How to Protect Yourself
Disclosure: if you buy through some links on this page we may earn a commission at no extra cost to you. We never let that change what we recommend. Never share your seed phrase with anyone, including us.
A wallet drainer doesn't need your seed phrase. It needs one click: a single "Connect", "Approve" or "Sign" on a convincing fake website, and your tokens and NFTs can be gone within seconds. This guide explains how drainer scams actually work, the exact kinds of signatures they abuse, the warning signs, and what to do if it happens to you.
What is a wallet drainer?
A wallet drainer is a malicious script, usually hidden on a phishing website, that tricks you into giving it permission to move your crypto. Unlike classic phishing, which tries to steal your password or recovery phrase, a drainer works through your own wallet: it asks your wallet to sign something, and if you approve, the attacker gets the right to transfer your assets.
Most drainers are sold as a service. Criminal groups build the drainer kit, the smart contracts and the cash-out system, then rent it to "affiliates" who run the phishing campaigns and share the stolen funds. The best-known family, Inferno Drainer, publicly announced it was shutting down in November 2023. In May 2025, Check Point Research reported that it had never really stopped: its smart contracts from 2023 were still in use, and in the previous six months more than 30,000 wallets had been victimized, with at least $9 million in losses.
How big is the drainer problem?
The Web3 anti-scam company Scam Sniffer tracks signature-based drainer phishing on Ethereum and other EVM networks. Its 2025 report counted $83.85 million stolen from 106,106 victims, down sharply from $494 million and about 332,000 victims in 2024. The decline is good news, but the report also found that losses rose and fell with the market: the third quarter of 2025, during a strong rally, was the worst period with $31.04 million stolen. The largest single theft of the year, $6.5 million in September, came from one malicious Permit signature.
In other words, drainers follow the money. When prices rise and people rush to claim airdrops and try new apps, attackers are waiting.
How a drainer attack works, step by step
- The lure. You see a message about a free airdrop, a token claim, an NFT mint, a "security issue" with your wallet, or an urgent migration. It arrives via a hacked social media account, a Discord or Telegram server, an email, or even a paid search ad that ranks above the real site.
- The fake site. The link leads to a near-perfect copy of a real app, often on a look-alike domain (an extra letter, a different ending, or a long subdomain).
- Connect wallet. The site asks you to connect. Connecting alone usually only shares your address, but it lets the drainer scan your balances and pick the most valuable assets.
- The malicious request. The site asks you to sign or approve something, disguised as "verify", "claim", "log in" or "enable". This is the step that matters.
- The sweep. Once you approve, the attacker's contract transfers your tokens or NFTs, often immediately and automatically, then moves them through other addresses to cash out.
The 5 kinds of signatures drainers abuse
Knowing what you are being asked to sign is your best defence. These are the main patterns:
| Request | What it really does | Red flag |
|---|---|---|
Token approval (approve, increaseAllowance) | Gives a contract permission to spend your tokens, often an unlimited amount. | An approval for a token you aren't trading, or "unlimited" on a site you don't know. |
NFT approval for all (setApprovalForAll) | Lets a contract move every NFT in a collection you own. | Requested by a mint or "claim" page that has no reason to move your existing NFTs. |
| Permit / Permit2 signature | An off-chain signed message that becomes a real token approval when the scammer submits it. No gas, no transaction. | A "sign message" prompt full of fields like spender, value and deadline, presented as a log-in. |
| EIP-7702 delegation or batch | Since Ethereum's Pectra upgrade, an account can delegate its behaviour to a smart contract. A malicious delegation or batch can move many assets in one approval. | Any request to "upgrade" or "enable" smart account features that comes from a website, email or link. |
| Plain transfers and blind signing | A transaction that simply sends your coins, or a request your wallet can't decode. | A "claim" that sends value out of your wallet, or a hardware wallet showing data you can't read. |
Why Permit signatures are so dangerous: as Revoke.cash explains, many wallets show a clear warning for on-chain approvals, but a Permit is just a signed message, so "it may look like you're simply signing into a website, but you're actually granting an approval." Scam Sniffer found that Permit and Permit2 signatures accounted for 38% of losses in 2025's million-dollar cases.
Why EIP-7702 matters: after the Pectra upgrade, attackers began abusing delegations. Scam Sniffer recorded two large EIP-7702 cases in August 2025 worth $2.54 million. MetaMask has stated it will only prompt users to switch to a smart account inside the wallet itself; a website or email asking you to "upgrade" your account is a scam.
Common lures and red flags
- Free money with a deadline. "Claim your airdrop in the next 2 hours." Urgency is the drainer's favourite tool.
- Hacked official accounts. A real project's X account or Discord announcement links to a fake site. The account being genuine doesn't make the link genuine.
- Sponsored search results. Ads for wallet apps and popular DeFi sites can point to clones.
- "Wallet support" and "security alert" messages. Real wallet makers don't DM you, and they never need you to sign anything to "secure" your account.
- Fake revoke or "anti-drainer" tools promoted to people who just lost funds.
- A signature request on a page that only claimed to need a log-in. Logging in should never involve spender addresses, token amounts or deadlines.
How to protect yourself from wallet drainers
- Split your wallets. Keep long-term holdings in a hardware wallet that never connects to new apps. Use a separate "hot" wallet with small balances for mints, airdrops and experiments. A drained burner wallet is an annoyance, not a disaster.
- Use bookmarks for every app you use. Never reach a crypto app from a DM, a reply, an email or a search ad.
- Read every prompt before you approve. Look at the spender, the amount and the asset. If the wallet shows a security warning or a simulation that sends assets out, stop. On a hardware wallet, read the device screen. If it can't show you what you're signing, don't sign.
- Prefer limited approvals. When an app asks for an unlimited allowance, set a specific amount if your wallet allows it.
- Review and revoke old approvals. Every few months, check your approvals with a reputable tool such as Revoke.cash or your block explorer's token approval checker, and revoke anything you no longer use.
- Treat account "upgrades" with suspicion. Only switch to smart account features from inside your wallet app, never from a website.
- Keep your seed phrase offline, always. No legitimate site needs it. See our seed phrase storage guide and test your backup with our guide on how to test your seed phrase backup.
- Buy hardware wallets only from the manufacturer or an authorised reseller. In October 2026, Ledger investigated wallet drains tied to devices sold by a reseller in Southeast Asia (see our daily crypto news for Oct 10, 2026). A device that arrives with a pre-printed recovery phrase is compromised.
What to do if you were drained
Speed matters, because drainers often keep watching a victim's address for new deposits.
- Stop interacting with the site and disconnect your wallet from it.
- Work out what you signed. Check your wallet's activity and a block explorer for approvals, Permit usage or delegations around the time of the theft.
- Revoke malicious approvals using a reputable revoke tool you open yourself. If you were hit by an EIP-7702 delegation, switch the account back to a standard account in your wallet's settings; MetaMask documents how to do this, and it costs a small fee on each network.
- Move what's left to a fresh, clean wallet. If there's any chance your seed phrase was exposed, create a new wallet with a new recovery phrase on a hardware wallet and move everything to it.
- Don't send new funds to the compromised address, even to pay gas for revoking, without a plan. Attackers often run "sweeper" bots that take incoming ETH instantly.
- Report it. In the US, file a report with the FBI's Internet Crime Complaint Center at ic3.gov; elsewhere, report it to your national police cybercrime unit. Also tell the exchange where the funds went, if you can identify it.
- Ignore recovery offers. The FBI has warned about fictitious law firms and "recovery companies" that target crypto scam victims and charge upfront fees. They are a second scam.
Drainers rely on speed, urgency and confusing pop-ups. Slow down, read what you sign, keep your serious savings in a wallet that never touches new websites, and most of these attacks simply fail.
Frequently asked questions
- Can a wallet drainer steal my crypto just because I visited a website?
- Visiting a page alone normally cannot move your funds. A drainer needs you to connect your wallet and then approve something: a transaction, a token approval, a Permit-style signature or an account delegation. The danger is in what you sign, which is why you should reject anything you don't fully understand.
- Does a hardware wallet protect me from drainers?
- Partly. A hardware wallet keeps your seed phrase offline, so malware cannot copy it. But if you confirm a malicious approval or signature on the device, the hardware wallet will sign it. Read what the device screen says before you confirm, and reject anything you can't verify.
- If I was drained, do I need a new seed phrase?
- It depends on how. If you signed a malicious approval or signature, your seed phrase is not exposed: revoke the approvals and, ideally, move remaining funds to a fresh address. If you typed your seed phrase anywhere, or you can't tell what happened, assume the phrase is compromised and move everything to a new wallet with a new phrase immediately.
- Can I cancel a Permit signature?
- Sometimes. A Permit signature only becomes an on-chain approval when the scammer submits it, and tools like Revoke.cash can try to invalidate a pending signature. In practice scammers usually use it within minutes. Once it is used it becomes a normal approval that you can revoke.
- Is revoking approvals safe?
- Yes, if you use a reputable tool such as Revoke.cash or a block explorer's approval checker, reached by typing the address yourself. Revoking only sets permissions to zero and costs a small network fee. Be wary of anyone who sends you a 'revoke' link: fake revoke sites are a known drainer trick.
- Can someone recover my stolen crypto for a fee?
- Almost always no. The FBI has repeatedly warned about fake recovery companies and fictitious law firms that target scam victims and demand upfront fees. Report the theft to the authorities and ignore anyone who contacts you offering recovery.
Sources
- Scam Sniffer, "2025: Crypto Phishing Losses Fall 83% to $84 Million": drops.scamsniffer.io
- Check Point Research, "Inferno Drainer Reloaded" (May 7, 2025): research.checkpoint.com
- Revoke.cash, "What Are EIP2612 Permit Signatures?": revoke.cash
- ERC-2612: Permit Extension for EIP-20 Signed Approvals: eips.ethereum.org
- MetaMask Help Center, "How to switch to or revert from a smart account": support.metamask.io
- DeFiHackLabs / SunSec, "Top 7702 Delegator Revealed as Phishing Scam" (quotes MetaMask's in-wallet-only smart account warning): defihacklabs.substack.com
- FBI / IC3 PSA on fictitious law firms targeting crypto scam victims (Aug 13, 2025): ic3.gov