How wallet drainers work, step by step
Drainer kits industrialised crypto theft: a template site, a signature request, and a wallet emptied in one confirmation. Understanding the sequence is what lets you break it.
Reviewed by Lauren Bennett, Senior Bitcoin Analyst · Last reviewed August 24, 2026

On this page
A wallet drainer is off-the-shelf software that empties a wallet the moment its owner approves a single request. The attacker does not break cryptography and does not need your seed phrase. They need you, on a page that looks legitimate, clicking confirm — which is why the defence is procedural rather than technical.
Where does the traffic come from?
The theft starts long before the wallet prompt. Operators buy search ads on brand terms, register domains a character away from the real one, compromise an official social account, or post an airdrop announcement into channels where people are already primed to claim something. The common thread is urgency: a snapshot ending, an allocation expiring, a support agent who needs you to validate your wallet. The wider catalogue of these approaches is in our guide to avoiding crypto scams.
The page you land on is usually a faithful copy of a real interface, sometimes served from a genuine-looking subdomain. Nothing on screen is designed to alarm you — the whole point is that it reads as ordinary.
What does the malicious request look like?
Once your wallet is connected, the kit inspects the balances and chooses the cheapest request that gets the most value. There are three shapes it typically takes.
- A token approval that names the attacker's contract as spender, usually with an unlimited allowance.
- An off-chain signature — a structured message granting spending rights, which needs no gas and produces no transaction in your history.
- A direct transfer or a call to a contract function that transfers, dressed as a claim, a mint or a verification step.
- For an NFT, a marketplace order that sells your item to the attacker for nothing.
How do you read a wallet prompt properly?
Modern wallets simulate the outcome of a request and show it in plain language. That simulation is the single most useful safety feature available to an ordinary user, and it is worth choosing a wallet that does it well.
- Ask what the prompt says you are giving up. If it says a balance will decrease and you expected a claim, stop.
- Check the spender or recipient address against the protocol's official documentation, not against the page you are on.
- Treat 'unlimited' in an approval as a decision, not a default.
- Be suspicious of any signature you did not initiate — especially one that appears immediately on connecting.
- Slow down on anything with a countdown. Manufactured urgency is the oldest tool in the kit.
What happens after a successful drain?
The sweep is automated and ordered by value, often within seconds. Funds move through a chain of fresh addresses, then to a mixer or a cross-chain bridge, and the operator's cut is split with the affiliate who supplied the traffic. Because settlement is final, there is no recall mechanism. Reporting to the platform and to law enforcement is still worth doing — it feeds investigations and sanctions work — but it should not be mistaken for a recovery path.
What actually reduces the damage?
Assume that one day you will click the wrong thing while tired. Design for that. Clearing old permissions matters here too — see our guide to token approvals and how to revoke them.
- Keep savings in a wallet that never connects to any application.
- Use a burner wallet for mints, claims and anything unfamiliar.
- Sign with a hardware wallet, and read the request on the device screen rather than the browser.
- Review and revoke stale approvals periodically so an old permission cannot be used later.
- Reach applications through your own bookmarks — never through an advert, a direct message or a search result.
- If you suspect a compromise, move remaining assets to a new wallet first and investigate afterwards.
What are the recurring red flags?
Drainer campaigns vary in presentation and repeat in structure. The following signals appear again and again, and any one of them is enough to justify closing the tab.
- A deadline. Snapshots ending, allocations expiring, a window closing in minutes.
- An unsolicited arrival: a direct message, a reply to your post, a comment under an official announcement.
- A request to 'verify', 'validate', 'sync' or 'migrate' a wallet — none of these are real operations.
- A signature prompt that appears before you have chosen to do anything.
- A domain that is nearly right, or a link shortened so you cannot see where it goes.
- Support that contacts you first. Real support desks do not initiate contact and never need your wallet.
The uncomfortable part is that experienced users are not immune. Campaigns increasingly target people who are used to signing frequently, because habit is the vulnerability — which is why structural defences like burner wallets and cold storage matter more than confidence.
- 1. What to know about cryptocurrency and scams — US Federal Trade Commission
- 2. Internet Crime Complaint Center — FBI IC3
- 3. EIP-712: typed structured data signing — Ethereum Improvement Proposals
Frequently asked
Can a wallet be drained just by connecting to a website?
No. Connecting shares your address and lets the site read public data. Assets move only after you approve a transaction or sign a message, which is why the confirmation step is where attention belongs.
Why do drainers ask for a signature instead of a transaction?
Signatures cost no gas, leave nothing in your transaction history, and many users treat them as harmless. A signed message can still authorise a transfer of tokens.
Can drained funds be recovered?
Practically never. On-chain transfers are final, and funds are moved and mixed within minutes. Report it to the platform and to law enforcement, but treat recovery as unlikely.
Does a hardware wallet protect me from drainers?
Partly. It protects the private key from malware and shows you the request on a trusted screen, but if you approve a malicious request on the device, it executes. The device removes key theft, not consent.
What should I do first if I think I signed something malicious?
Move any remaining assets to a fresh wallet immediately, before investigating. Then revoke approvals from the compromised address and stop using it.

Kayla Peterson is a DeFi Research Analyst at Crypto Almanac Daily, where she specializes in decentralized finance, lending protocols, decentralized exchanges (DEXs), liquidity markets, yield strategies, and tokenomics. Her work focuses on analyzing the mechanics behind DeFi ecosystems, helping readers understand how lending platforms, automated market makers, liquidity incentives, and governance models influence the broader digital asset economy. Kayla regularly covers major protocols, emerging trends in on-chain finance, and the evolution of decentralized financial infrastructure through data-driven research and in-depth market analysis. Before joining Crypto Almanac Daily, she researched blockchain-based financial systems and digital asset markets, building expertise in protocol design, token economics, and decentralized capital markets. Her reporting combines technical accuracy with clear explanations, making complex DeFi concepts accessible to both experienced investors and newcomers to the industry. At Crypto Almanac Daily, Kayla contributes daily market coverage, protocol analyses, educational guides, and long-form research articles. Her goal is to provide readers with reliable, objective insights into the rapidly changing world of decentralized finance while highlighting the opportunities and risks shaping the next generation of financial innovation.
This guide is educational and general in nature. It is not financial, investment, legal or tax advice, and it does not account for your circumstances. Crypto assets are volatile and you can lose the money you put in. See our editorial policy and methodology.


