What Is a Wallet Drainer?

Wallet drainers steal your crypto the moment you sign a malicious transaction — no password needed. Learn how approve, setApprovalForAll, and Permit2 work and what to do after.

A wallet drainer is a malicious script embedded in a fake or compromised Web3 site that steals your crypto the moment you approve a transaction — no password required.

In the first half of 2025 alone, wallet drainers stole $1.93 billion from crypto holders across chains, according to PhishDestroy. Six months of losses. Not a cumulative figure built over years — a professionalized attack industry that rents out drainer software on a commission model, running at scale. The victims range from newcomers connecting their first MetaMask wallet to experienced DeFi users and NFT collectors who knew the risks but clicked too fast.

This guide covers the full picture: what each malicious transaction type actually authorizes, how an attack moves from fake link to empty wallet, where drainer sites show up, what to do in the minutes after a suspicious signature, and how to run your wallet so you are harder to drain.

Key takeaways

  • A wallet drainer steals funds by tricking you into signing a transaction that authorizes the attacker to move your assets — not by hacking your private key.
  • Three transaction types do most of the damage: approve(), setApprovalForAll, and off-chain Permit2 signatures. The third type is especially dangerous because it costs no gas and looks harmless.
  • If you suspect you signed something malicious, the first move is to transfer surviving assets to a new wallet — before you revoke anything — because revoke transactions can be front-run.

What a Wallet Drainer Actually Does

Most people who get drained assume their private key was stolen or their password was guessed. Neither is true. A wallet drainer never touches your key.

What it does is more efficient: it tricks you into signing a transaction that hands the attacker permission to move your assets. Once that permission exists on-chain, the attacker’s wallet calls the transfer function and your tokens leave in seconds — before you realize anything happened. Your private key stays intact. Your seed phrase is untouched. The attacker simply used the permission you gave them.

Blockchain transactions are irreversible. There is no bank to call, no chargeback, no dispute window. The assets are gone.

The drainer script does one clever thing before it shows you the sign prompt: it scans your wallet. It identifies which tokens and NFTs you hold, estimates their USD value, and queues the most valuable assets first. If you hold stablecoins, high-cap tokens, and an NFT collection, it drains the stablecoins and blue-chip NFTs before touching the smaller positions. All of this happens in the background before the pop-up even appears.

The assets targeted are typically ERC-20 tokens (including stablecoins like USDT and USDC), ERC-721 NFTs, ERC-1155 multi-token assets, and increasingly native tokens when the drainer kit can estimate gas reserves. If you hold assets across multiple chains but connected on one chain, the drain may focus on that chain only — which is why post-attack revocation must cover every chain where the wallet is active, not just Ethereum.

If approvals are new to you, the crypto wallets hub explains how wallet permissions work from the ground up.

The Three Ways a Wallet Drainer Gets Permission

The attack always starts the same way: a transaction request appears in your wallet, you click “Confirm,” and the permission exists on-chain. But there are three distinct transaction types that drainers exploit, and they work very differently. Here is what each one actually authorizes:

Permission Type What It Authorizes
approve(spender, uint256.max) Grants the attacker’s address unlimited rights to transfer a specific ERC-20 token from your wallet, forever, until revoked.
setApprovalForAll(operator, true) Grants the attacker’s address full control over every NFT in an entire collection in your wallet. One signature covers all of them.
Off-chain Permit / Permit2 signature Signs a gasless typed-data message that encodes spending permissions for one or multiple tokens at once. The attacker then submits it on-chain via a relay.

The first type — approve() — is the most common. Legitimate DEXes like Uniswap use approve() so their smart contracts can pull tokens from your wallet when you trade. Drainers disguise malicious approve requests as “Claim tokens,” “Access reward,” or “Authorize swap.” The disguise usually specifies uint256.max as the amount, meaning unlimited — but your wallet UI may just show “Unlimited” in small text, or nothing at all.

The second type — setApprovalForAll — is what NFT drainers rely on. It appears as “Mint,” “Verify ownership,” or “Access gallery.” Because it covers every NFT in a collection rather than one token, a single signature can be worth hundreds of thousands of dollars. The Bored Ape Yacht Club hack was partly enabled by this mechanism.

The third type — Permit2 (and its predecessor EIP-2612) — is the most dangerous because it exploits a specific blind spot. A Permit2 signature costs no gas. Your wallet shows no transaction fee, which makes it feel like a harmless message-signing step, not a financial authorization. But the typed-data payload encodes spending permissions — sometimes for multiple tokens at once. The moment the attacker’s relay receives the signed message, they call transferFrom() from a separate wallet, and the transfer executes. The user never sees a second prompt.

How a Wallet Drainer Attack Unfolds (The Kill Chain)

Every wallet drainer follows roughly the same six stages. Once you see the full sequence, the attack’s logic — and where it can be interrupted — becomes obvious.

The attack starts with the lure. The attacker gets a fake or compromised site in front of the target through a hacked Discord server posting an urgent minting announcement, a verified X/Twitter account taken over by phishers, a Google Ads campaign targeting the exact name of a real project, or a direct Telegram message with a “limited airdrop” link.

The user arrives at a visually identical clone of the real site and connects their wallet. The site looks right. The URL is slightly off — but users rarely check.

In the background, the drainer script scans the wallet’s token and NFT balances via public RPC calls. It ranks assets by value and queues the highest-value holdings for the permission request it is about to send.

Then a wallet prompt appears. The framing is usually urgent and mundane: “Mint,” “Claim airdrop,” “Verify,” or “Access exclusive content.” The user clicks Confirm. That is the point of no return.

Permission granted. The attacker’s contract calls transferFrom() from a separate wallet, moving assets within seconds. The drain happens before most users have closed the browser tab.

The final stage is laundering. Stolen funds move through mixing services, cross-chain bridges, or privacy protocols to obscure the on-chain trail. By the time a victim notices and reports, the trail is already cold.

One important detail about Stage 1: many drains are not executed by the person who built the software. The DaaS (drainer as a service) model means the attacker who phished you may have rented a ready-to-deploy kit for a flat fee or a 15–20% commission on proceeds. The lure can be highly polished because the affiliate who deployed it paid for a professional-grade tool. The attacker’s technical skill and the kit’s sophistication are now completely separate things.

Where Wallet Drainers Show Up (And How to Spot Them)

Wallet drainer-hosting sites do not advertise themselves. They arrive through channels users already trust — which is exactly what makes them effective.

The five main distribution channels are:

  • Compromised official Discord servers of real projects, where moderators have been phished and the announcement channel posts a fake mint link.
  • X/Twitter accounts taken over using stolen session tokens, often with a verified checkmark intact from the legitimate owner.
  • Google Ads and sponsored search results targeting project names exactly — scammers buy “MetaMask download,” “Uniswap app,” or a new project’s official name to place fake sites above organic results.
  • Fake airdrop and minting sites deployed in the days immediately after a real project announcement, when FOMO is highest and scrutiny is lowest.
  • Fake mobile apps on Google Play and the App Store — Check Point Research documented a fake WalletConnect app that accumulated 10,000 downloads and stole approximately $70,000 before detection.

Before connecting your wallet anywhere, watch for these red flags:

  • The URL nearly matches the real domain but with a transposed character, an extra letter, or a different TLD (e.g., .app instead of .io).
  • Urgency framing: “Mint closes in 6 minutes,” “Limited to 500 wallets,” “Window closes at midnight.”
  • Any request for your seed phrase or private key — no legitimate site ever needs these.
  • A “Connect” or “Sign” prompt with no clear explanation of what you are authorizing.
  • A sponsored search result appearing above the project’s organic listing.

Even experienced users get caught. The Nest Wallet founder lost $125,000. The BAYC hack was preceded by weeks of coordinated social engineering. Getting drained is not a sign of being a beginner — it is a sign that the attacker’s kit was better than the user’s habit.

The same scam infrastructure that delivers drainer links shows up in fake project launches too. The hard rug pull guide covers how fraudulent projects build credibility before the exit — the same playbook drainer affiliates use. And the guide on dust in crypto explains how small unsolicited token deposits fingerprint active wallets before an attacker chooses who to target.

What to Do If You Think You Signed a Wallet Drainer

The hard truth first: if funds have already left your wallet, they almost certainly cannot be recovered. Blockchain transactions are irreversible, there is no authority to reverse them, and the laundering step (Stage 6 above) happens fast. The recovery conversation is about stopping further loss, not undoing what happened.

Here is the sequence, in order:

  1. Do not sign anything else. A second wave of fake prompts targets panicked users immediately after a drain. Fake “recovery services” and “wallet restoration tools” are common second-stage scams. Do not interact with anything.
  1. Move surviving assets first. Generate a fresh wallet address — on a device that has not interacted with the suspicious site if possible — and transfer everything that has not already been drained. Do this before revoking approvals. Revoke transactions cost gas and can theoretically be front-run by a watching bot. Get your remaining assets out first.
  1. Revoke all approvals on the compromised wallet. Use Revoke.cash (supports 100+ chains) or the Etherscan Token Approval Checker. Go through every chain where the compromised wallet has ever been active — not just Ethereum. An approval granted on Polygon or Arbitrum is just as dangerous.
  1. Document everything. Screenshot the malicious transaction hash, the site URL, any messages or DMs that led you there, and the wallet addresses that received your funds. You will need all of this for reporting — and in rare cases it has supported coordinated on-chain recovery efforts.
  1. Report it. US users should file with the FBI Internet Crime Complaint Center (IC3). File a report with the platform — Discord, X/Twitter — through which the lure arrived. The project whose name was impersonated may also be able to issue warnings to their community.

Revoking approvals on the compromised wallet stops future draining from those permissions. It does not reverse what already happened. Keep the compromised wallet isolated — do not fund it again, and do not use it to interact with dApps until you fully understand what approvals remain.

How to Keep Your Wallet Safe from Drainers

Prevention is simpler than recovery. Five habits cover most of the realistic risk.

The most effective structural defense is keeping your wallets separate. Use a dedicated burner wallet for interacting with new or unfamiliar sites. Keep large holdings in a cold wallet or a wallet that has never connected to a dApp. If the burner gets drained, the damage is bounded.

Transaction simulation tools have become genuinely useful. Blockaid, Wallet Guard, and Pocket Universe show you the predicted balance change before you confirm a transaction. These tools catch most known drainer payloads by comparing the requested permission against a database of malicious contract addresses and known attack patterns. MetaMask has integrated Blockaid’s detection natively. Use simulation tools as a second opinion on anything unusual.

Monthly approval hygiene reduces your standing exposure. Use Revoke.cash once a month to check and revoke permissions you no longer need. This is not a response to a drain — it is a routine that limits the blast radius if a contract you previously trusted is later exploited.

URL verification before connecting is non-negotiable. Navigate directly to the official site by typing the URL or using a verified bookmark. Do not click links from Discord, Telegram, or social media without cross-referencing the exact URL character by character.

One misconception causes more losses than almost any other: assuming a hardware wallet makes you immune to drainers. It does not. A Ledger or Trezor protects your private key from remote extraction — but it still signs whatever the compromised front-end asks it to sign. If a site asks you to sign a malicious Permit2 message and you confirm it on your hardware device, the drain happens exactly the same way. A 2026 social engineering campaign specifically targeted Trezor users, tricking them into revealing seed phrases via fake Trezor support sites. Hardware wallets reduce one risk vector while leaving transaction-approval attacks fully intact.

Here is a quick reference of what each protection layer actually stops:

Protection What It Stops
Wallet segregation Limits losses to the burner wallet’s holdings if a drain occurs
Transaction simulation tools Catches known malicious contract addresses and approval patterns before confirmation
Monthly approval revocation Reduces standing exposure from permissions granted to contracts you no longer use
URL verification Prevents landing on cloned sites that host the drainer script
Hardware wallet Prevents private key extraction — does not prevent approval-based drainer attacks

Stolen funds rarely disappear cleanly. The guide on AML in crypto covers how chain analytics firms and regulators trace and freeze stolen funds — and why that laundering step in Stage 6 is a serious crime in most jurisdictions.

The Wallet Drainer Business (Who Actually Runs These Attacks)

Most wallet drains are not the work of a lone coder building a custom tool. The DaaS (drainer as a service) industry is structured like a franchise, and it is why the attack volume is so high.

A drainer developer builds the kit — the malicious JavaScript, the smart contract interaction logic, the wallet recon script — and then licenses it to affiliates. The affiliate does not need to understand how the code works. They rent the kit for a flat fee ($500 to $10,000 depending on the kit) or agree to a 15–20% commission split on stolen proceeds. The affiliate then handles the phishing: building the fake site, compromising a Discord server, running the Google Ads campaign, or buying a verified social account.

The Inferno Drainer, one of the most documented kits, ran more than 16,000 malicious domains before its operators announced a shutdown. It remained active after the announcement. Angel Drainer, Venom Drainer, MS Drainer, Ghost, Medusa, Nova, Vega, and Monkey are all named kits that have appeared in security reporting — when you see these names in a security alert, they refer to the software toolkit, not a specific hacking group.

Lucifer DaaS is the most recent significant example. Between January 2025 and early 2026, Lucifer was advertised across approximately 700 documented underground forum posts, offering “Zero Config” deployment so affiliates with almost no technical skill could deploy functional drainer infrastructure. After Telegram banned the distribution bots in August 2025, operators migrated to IPFS hosting to maintain availability.

The $1.93B stolen in H1 2025 represents a 540% increase over the H1 2023 baseline. That growth is not primarily because drainers are more sophisticated — it is because the DaaS model lowered the barrier to entry so far that nearly anyone can run a drain campaign.

The DaaS affiliate structure is built on the same logic as other coordinated crypto fraud: developers take a cut, affiliates do the dirty work, and retail holders are the revenue source. The guide on exit liquidity covers how ordinary investors end up on the losing side of these organized schemes.

FAQ

What is a wallet drainer in crypto?

A wallet drainer is a malicious script embedded in a fake or compromised Web3 site that tricks users into signing a transaction that authorizes the attacker to move their crypto assets. The attack does not require your password or seed phrase — it only needs you to confirm a disguised approval in your wallet. Once the permission is on-chain, the attacker’s wallet executes the transfer in seconds and the funds leave irreversibly.

How does a wallet drainer get access to your funds?

Wallet drainers use one of three permission mechanisms. The first is approve(), which grants the attacker unlimited rights to transfer a specific ERC-20 token. The second is setApprovalForAll, which hands over control of an entire NFT collection with one signature. The third is a Permit2 or EIP-2612 off-chain signature — a gasless typed-data message that encodes spending permissions for one or more tokens. Because a Permit2 signature shows no transaction fee, it often feels harmless when it appears in the wallet prompt.

Can you recover crypto stolen by a wallet drainer?

Almost never. Blockchain transactions are irreversible by design, and there is no central authority that can reverse a completed transfer. Revoking the approval on your compromised wallet stops the attacker from draining anything else using that permission — but it does not undo what already happened. The most realistic post-drain goal is to limit further loss by moving surviving assets to a new wallet immediately and revoking all remaining approvals on the compromised address.

What is a wallet drainer as a service?

Drainer as a service (DaaS) is a model where a developer builds and maintains a wallet drainer kit and rents it to affiliates who run the phishing campaigns. Affiliates typically pay a flat fee of $500–$10,000 or agree to a 15–20% commission on stolen proceeds. The developer handles the technical tool. The affiliate handles the lure — fake sites, compromised Discord servers, paid ads. This separation of roles means an attacker with no coding ability can run a technically sophisticated drainer attack by renting an existing kit.

How do I check my wallet for wallet drainer approvals?

Go to Revoke.cash and connect your wallet. The tool shows every active approval across more than 100 chains, what contract holds the permission, and the amount authorized. You can revoke individual approvals directly from the interface. The Etherscan Token Approval Checker covers the same function for Ethereum mainnet specifically. Both tools are free. Run the check on every chain where your wallet has ever been active — a malicious approval on Arbitrum or Base is just as exploitable as one on Ethereum mainnet.