- Date
- Views
- 2
- Time
- 10 分钟.
What Is A Crypto Drainer?

Key takeaways:
- A drainer steals assets through the user’s own actions. Scammers trick wallet owners into granting permissions, signing messages, or approving malicious transactions.
- Social engineering is the primary tool used by wallet drainers. Fake staking, DEX, airdrop, or Claim pages disguise malicious actions as regular Web3 operations.
- A fake can be difficult to spot by its interface. A phishing website can look almost identical to a legitimate service, making it critical to verify the domain and the source of the link.
- The best protection is to control what your wallet signs. Don’t connect your wallet to suspicious websites, approve unclear Approve or Permit requests or transactions, use separate wallets for primary holdings and experimental activities, and periodically revoke unnecessary permissions.
What Is a Wallet Drainer?
A drainer is a malicious tool or script designed to transfer cryptocurrency, tokens, and other digital assets out of a victim’s wallet without authorization.
How Does Crypto Drainer Work?
Drainers can employ various methods to interact with a crypto wallet. The key difference lies primarily in the action an attacker attempts to trick the user into authorizing:
- Approval-based — the victim is tricked into granting permission (approve) to manage their tokens. This permission can subsequently be exploited to transfer the tokens out of the wallet.
- Signature-based — this method revolves around obtaining the user’s signature, for example, for Permit-like authorization. On the surface, such a request may appear less dangerous than a full-fledged transaction, even though the signature can grant significant permissions.
- Transaction-based — the user approves a preconfigured transaction or smart contract call whose execution results in the wallet being drained.
Types Of Crypto Drainers Attacks
Wallet drain primarily rely on social engineering. Let’s examine the tactics most commonly employed by attackers.
Fake Staking Websites
Users are offered the opportunity to stake tokens at an attractive interest rate or participate in a new yield-generating program. Once the wallet is connected, the website prompts the user to perform an action that may grant access to their assets and initiate a transfer.
One way these websites are promoted is through YouTube videos. For example, an obscure channel with only a handful of subscribers and a dozen views may publish a video claiming that its creator has staked tokens at a 5,000% annual yield and is earning enormous returns.
A link to the “platform” is provided in the video description or a pinned comment. It directs users to a fake staking service designed to persuade them to connect their wallet and sign a transaction or grant permission to interact with their tokens. VirusTotal also flags the link as a threat.
Source: https://www.virustotal.com/
Fake DEXs and Exchanges
Attackers create near-identical copies of popular decentralized exchanges and promote them through paid search ads.
In May 2026, a fake version of Uniswap was distributed using this method: a sponsored link appeared at the top of Google search results and redirected users to a phishing website. Users would see a familiar interface, connect their wallets, and approve an operation that effectively gave the attackers control over their tokens. As a result, addresses associated with the drainer received at least $400,000 worth of assets.
Source: https://x.com/
Fake Airdrops and Claim Pages
Victims are told that they are eligible for free tokens, a reward, or compensation that must be collected by clicking a Claim button. To receive the “reward,” they are prompted to visit a website, connect their wallet, and authorize an action.
One example of this tactic involves the mass distribution of NFTs to random wallet addresses. The promised amount and website address are displayed directly on the NFT image, while the description repeats the link and urges recipients to claim the tokens. The scheme relies on wallet owners noticing an unfamiliar NFT, becoming intrigued by the “reward,” and voluntarily visiting the phishing website.
Source: https://tonscan.org/
How To Protect From Crypto Wallet Drainer?
It is impossible to eliminate the risk entirely, but most crypto draining attacks rely on users acting hastily or without sufficient caution. A few simple habits can significantly reduce the likelihood of losing your assets:
- Do not access Web3 services through random links. A Google ad, YouTube video, post on X or Telegram, or an NFT containing a website address does not prove that a resource is legitimate. For popular DEXs and DeFi protocols, it is best to identify the official domain through trusted sources once and save it as a bookmark.
- Do not interact with unexpected NFTs or tokens. If an NFT promising “5,000 TON,” an airdrop, or another reward suddenly appears in your wallet, do not follow the address displayed in it. Anyone can send such an NFT to an arbitrary public address.
- Pay close attention to what your wallet asks you to sign.Connect by itself typically only establishes a connection to a website. Approve, a Permit-like signature, or a transaction is an entirely different matter. If the interface promises one thing while your wallet requests unclear or excessive permissions, you should not authorize them.
- Verify the domain, not the website’s appearance. A phishing copy of Uniswap or another service can look virtually indistinguishable from the original. The logo, interface, and even a functional Connect Wallet button prove nothing — the website address is what matters.
- Use separate wallets. A crypto wallet containing your primary holdings should not be connected to every new mint, DEX, or DeFi protocol. For experimental activities, it is advisable to use a separate wallet containing only a limited amount of funds.
- Regularly review granted permissions. After using a dApp, active approvals may remain associated with your wallet. It is advisable to revoke permissions you no longer need using trusted tools designed for the relevant network.
What To Do If Your Wallet Has Been Drained?
If you notice assets disappearing from your wallet, the priority is not to waste time investigating the cause while funds still remain at the address.
- Create a new wallet with a new seed phrase and, if any assets remain in the old wallet, transfer them to the new address as quickly as possible. Do not restore the new wallet using the old seed phrase: if it has been compromised, the attacker will retain access to the addresses associated with it.
- Revoke suspicious permissions on the old wallet. If the crypto drain was caused by a malicious approve, a third-party contract may still have permission to manage certain tokens. Simply disconnecting the wallet from the website does not revoke this permission.
- Do not send funds for gas to a compromised wallet. If incoming assets are transferred to an unknown address almost immediately, this may indicate a sweeper bot — an automated script that monitors the balance of a compromised wallet and transfers newly received funds to an attacker-controlled address.
Conclusion
Drainers do not hack the blockchain — they exploit the wallet owner’s lack of vigilance. A fraudulent website can look virtually identical to a legitimate one, while a malicious transaction can be disguised as a routine swap, staking operation, or claim. Therefore, the best protection is to understand which website you are interacting with and exactly what you are authorizing in your wallet.
This material is provided for informational purposes only and does not constitute financial or investment advice.
To Share
Published by












