What Is a Wallet Drainer?
A wallet drainer is malicious code that empties a crypto wallet after tricking its owner into signing the wrong thing. Not by stealing your seed phrase, usually. By getting your own wallet to authorize the theft, one plausible-looking signature at a time.
How It Actually Works
- You land on a bait site: a fake mint, a fake airdrop claim, a fake support portal, an ad bought above the real site's search result.
- The site requests a signature or a token approval dressed up as "verify wallet" or "claim."
- What you actually sign grants spending rights or executes transfers. Automated scripts then sweep tokens and NFTs in seconds, routing them through mixers and mules.
- Much of this runs on drainer-as-a-service kits: professional criminal software rented out for a revenue share. The person who phished you is a franchisee.
Risks and Common Mistakes
- Believing danger requires typing a seed phrase. Signatures and approvals drain wallets that never revealed a secret.
- Trusting links from DMs, replies, sponsored search results, and compromised project Discords, which are the standard delivery channels for phishing.
- Signing blind. If the wallet cannot tell you plainly what a signature does, decline. Wallets with human-readable simulation exist; my reviews cover Rabby in the wallet roundup queue.
- Holding everything in one hot wallet. Compartmentalize: a spending wallet that touches dapps, a vault that touches nothing. See Wallet Security.
When It Matters
Any wallet that interacts with websites is in drainer territory. Immediate response if hit: revoke remaining approvals via Revoke.cash, move what survives to a fresh wallet with a fresh seed, and report to Chainabuse and the FBI's IC3.
Related Terms
Glossary · Learn · Resource Library · Return to Official Home Page
Copyright © 2026 Crypto Guidance Inc.