Sources checked

How we checked this

We reviewed the linked sources and keep this page updated when the record changes. Use the source list below to verify the details.

Source links attached Safety context included Corrections open

Key points

A wallet drainer is a scam tool or script designed to move crypto assets after a user signs a malicious transaction, connects to a fake site, or grants an unsafe token approval. The risk is common in phishing campaigns because the victim may not reveal a seed phrase at all; the loss can come from a signature that gives an attacker permission to spend tokens or NFTs.

This guide focuses on the practical search intent behind the term: how to spot the risk, how approvals differ from direct transfers, and what checks to run if you think you signed something unsafe. It is not a guarantee that funds can be recovered, and it is not legal or financial advice.

What a wallet drainer does

A drainer usually sits behind a phishing page that imitates an airdrop, mint, token claim, exchange login, support portal, or portfolio tool. The page asks the user to connect a wallet and approve a prompt. The prompt may look routine, especially if the user is rushing or using a mobile wallet with limited transaction details.

The harmful action can vary:

Risk patternWhat the user may seeWhy it matters
Token approvalA request to approve spending for a tokenThe attacker may later move approved tokens without a new confirmation
NFT approvalA permission request for a collection or marketplace-like actionA broad approval can expose multiple assets
Malicious transferA transaction that directly sends funds or assetsLoss can happen immediately after confirmation
Permit signatureAn off-chain signature requestSome signatures can authorize later movement without a normal on-chain approval screen

Not every wallet connection is dangerous. Viewing a balance or connecting to a legitimate application can be normal. The danger appears when a site asks for spending permission, a broad operator approval, a confusing signature, or a transaction that does not match the action you expected.

Common warning signs before you sign

The strongest protection is to slow down before approving anything. Many campaigns rely on urgency: a limited airdrop window, a fake token migration deadline, a supposed account freeze, or a direct message from someone claiming to be support.

Red flags include:

  • A claim page promoted mainly through replies, DMs, Telegram groups, or sponsored-looking posts rather than an official project domain.
  • A wallet prompt asking for broad approval when you only expected to view information.
  • A domain that differs by one character from the real project name.
  • A “support agent” asking you to connect your wallet to a recovery or validation portal.
  • Pressure to act before checking the project’s official website, status page, or verified social channels.
  • A transaction simulation that shows unexpected asset movement, if your wallet or security tool provides simulations.

MetaMask’s safety guidance, Revoke.cash educational resources, Etherscan’s approval checker, and security research from groups such as Scam Sniffer are useful starting points for learning how phishing and approval risks appear in practice.

Why token approvals can remain risky

Approvals are easy to misunderstand because they do not always move funds immediately. On Ethereum and many EVM-compatible networks, a user can grant a contract permission to spend a token up to a set amount. If the spender is malicious, compromised, or not the contract the user believed it was, the permission can become a path to theft.

Some approvals are limited and necessary for normal DeFi use. Others are broad, outdated, or connected to sites the user no longer recognizes. The risk is higher when approvals are unlimited, old, or granted after visiting a suspicious link.

A useful habit is to review approvals periodically, especially after using new decentralized apps, mint pages, bridges, or token claim sites. Tools such as the Etherscan token approval checker and Revoke.cash can help users inspect and revoke permissions on supported networks. Use the official URLs directly, not links sent by strangers.

What to do after a suspicious wallet action

If you think you interacted with a malicious site, focus on preserving remaining assets and evidence. Do not send more funds to “unlock,” “validate,” or “recover” anything. Recovery-fee demands are a separate scam pattern.

Practical steps:

Disconnect the wallet from the suspicious site inside your wallet settings if the option is available.
2. Review token and NFT approvals using a reputable checker for the relevant network.
3. Revoke approvals that you do not recognize or no longer need, understanding that revocation itself requires a network transaction and gas fee.
4. Move remaining assets to a fresh wallet if you believe the current wallet may remain exposed through approvals or unsafe habits.
5. Save evidence: transaction hashes, wallet addresses, domains, screenshots, chat handles, emails, and timestamps.
6. Report the phishing page to the wallet provider, browser safe-browsing tools, project team, exchange support if an exchange account is involved, and relevant law-enforcement or consumer-protection channels.

If your seed phrase or private key was entered anywhere, treat the wallet as compromised. Revoking approvals is not enough in that case. A seed phrase gives full control, and the safer path is to move remaining assets to a new wallet generated on a clean device.

What not to share after a loss

Scammers often target victims again. A person who posts about a theft may receive messages from “recovery experts,” fake investigators, or impersonated support staff. Be careful with what you disclose publicly.

Do not share:

InformationWhy it should stay private
Seed phrase or private keyAnyone with it can control the wallet
Full exchange login detailsIt can expose accounts beyond the wallet
Remote-access codesAttackers can take over devices or sessions
Unpublished evidence filesThey may contain identity data or security clues

A transaction hash and public wallet address can be useful for reporting and analysis, but they should still be shared carefully. If the case involves a large loss, identity theft, extortion, or exchange accounts, consider formal reporting channels and qualified professional advice.

Source limits and next checks

Public blockchain data can show movements, approvals, contracts, and wallet addresses, but it does not automatically prove who controls an address or whether a website operator is the same person as an on-chain wallet. Avoid unsupported accusations based only on screenshots or social posts.

Next checks that are usually worth doing:

  • Type the project’s official domain manually or use a bookmarked link.
  • Compare any claim page with the project’s official documentation and announcements.
  • Inspect approvals on the specific chain where you interacted.
  • Save transaction hashes before changing devices or clearing browser data.
  • Treat guaranteed recovery offers, upfront recovery fees, and seed phrase requests as high-risk signals.

Update log

  1. 21 Jul 2026Published with source tracking and reader-safety context.
  2. CorrectionsIf a source changes or a claim needs clarification, this page can be updated from the editorial desk.