Crypto-wallet drainer
A crypto wallet works by signing transactions that move crypto assets. Draining a wallet is the process in which the user, believing they are doing something legitimate, signs a transaction or an approval that hands the attacker control of those assets.
Term
description · examples · notesA crypto wallet works by signing transactions that move crypto assets. Draining a wallet is the process in which the user, believing they are doing something legitimate, signs a transaction or an approval that hands the attacker control of those assets.
Description
The bait can be a token airdrop, a fake page of a well-known project, a message on social media, an advert, an NFT offer or a "connect wallet" button. The signature being asked for often looks like a routine step, while behind it lies a broad approval — the right to spend every token, for instance.
Here a password is usually not stolen and no encryption is broken. The victim signs an action they do not understand. Once the transaction executes on the chain there is generally no way back. There is no bank, no chargeback, no service that undoes a click.
Examples
- A user receives a message about a free token airdrop, connects their wallet to a fake site, and signs an approval the drainer uses to pull the funds out.
- A fake page of a popular project asks for a signature that looks like a login but actually permits tokens to be spent.
- A pinned link to a supposed promotion appears in a crypto group; several members lose funds before the rest work out what happened.
Notes
- With wallet drainers the most dangerous thing is signing something that is not fully understood, and approving without care.
- If you do not understand what you are signing, you do not sign. The rule sounds blunt, but in crypto there is often no second line of defense.
Mentioned in the news
- 22. APR 2026. Lažne wallet aplikacije u kineskom App Store-u kradu seed phrase →
- 4. APR 2026. Napadači opljačkali Drift za 285 miliona dolara za manje od 10 sekundi →
- 28. MAR 2026. GlassWorm koristi Solana dead drop za RAT i krađu browser i kripto podataka →
- 14. MAR 2026. Kompromitovan AppsFlyer Web SDK korišćen za krađu kriptovaluta →
Techniques
carried out with 3Techniques used to carry it out. Select one to open its page.
Defenses
countered by 3How it is defended against. Select one to open its page.