Home › Knowledge Hub › Wallet drainers
Wallet drainers and token approval scams
A wallet drainer empties a wallet using permission you granted yourself, usually without realising. Rather than stealing a password, the attacker persuades you to sign a transaction or approve a smart contract that lets them move your assets later. Because the approval is legitimate at the protocol level, nothing blocks it, and the theft can happen hours or weeks after you signed.
If it just happened
Stop and do these three things before reading further.
- Move any remaining assets to a new wallet: one created fresh, with a seed phrase the attacker has never had a chance to see.
- Revoke the approvals on the compromised wallet, using a reputable revocation tool. Instructions below.
- Assume the wallet is permanently compromised if there is any chance your seed phrase was exposed. Revoking approvals does not help if the attacker has the phrase itself.
The order matters. Attackers often run automated scripts that sweep a wallet the moment anything arrives in it.
What an approval is
Most tokens work through a permission system. Before a decentralised application can move a token on your behalf (to swap it, stake it, or list it), you grant that application permission to do so. This is normal and necessary, and it is why the mechanism exists.
The problem is the scope. Many approvals default to unlimited: permission to move any amount of that token, indefinitely, with no further confirmation from you.
Grant that to a legitimate exchange contract and nothing happens. Grant it to an attacker's contract and they can drain that token whenever they choose, without you signing anything again.
This is why the theft often happens later. People connect a wallet, sign something, see nothing bad occur, and conclude it was fine. The permission sits dormant until the attacker decides to use it.
Why the prompt looks harmless
The signature request that grants this permission is technical and unhelpful. Depending on the wallet, you may see a hexadecimal string, a contract address, and a function name, or a message asking you to "verify ownership" or "confirm you are human."
Some drainers use signature types that do not appear as transactions at all, so there is no gas fee and no obvious blockchain activity to alert you.
The honest position is that most people cannot read these prompts, and wallet interfaces have historically been poor at explaining them. Not understanding what you signed is not carelessness, the interface failed you.
How you get there
The signature is the mechanism; the lure gets you to it.
- Fake airdrops. A claim page for tokens you are told you qualify for.
- Unsolicited tokens appearing in your wallet. These are bait. The token name often contains a URL. Interacting with it is the trap.
- Counterfeit DeFi sites. A near-identical clone of a real protocol, on a domain differing by one character.
- Fake NFT mints or offers, often time-limited to prevent scrutiny.
- Urgent security alerts: "your wallet is at risk, migrate now."
- Search and social advertising placed above the real site's result.
- Fake support agents who respond to a public post asking for help.
The seed phrase version
The other route is simpler and more final: convince you to type your recovery phrase into a website.
No legitimate wallet provider ever needs your seed phrase. Not for support, not for verification, not for migration, not for recovery, not to fix a bug. There is no exception to this and there never has been.
Anyone requesting it, including someone claiming to be from your wallet's support team, an investigator, or a government agency, is trying to steal from you.
Checking and revoking your approvals
Worth doing periodically even if nothing has gone wrong.
Our guide to revoking token approvals covers this in full.
- Use a reputable revocation tool. Revoke.cash and Etherscan's own Token Approval Checker are the widely-used ones. Navigate there directly: type the address rather than following a link, because fake revocation sites exist and are themselves drainers.
- Connect your wallet. Reviewing approvals is read-only.
- Look for approvals you do not recognise, and any marked unlimited.
- Revoke them. Each revocation is a transaction and costs gas.
- Repeat per network. Approvals are chain-specific, revoking on Ethereum does nothing on BNB Chain, Polygon or Arbitrum.
Revoking does not recover anything already taken. It stops future transfers.
Reducing the risk afterwards
- Use a separate wallet for anything experimental. Keep the bulk of your holdings in a wallet that never connects to a website.
- A hardware wallet for long-term holdings. It does not make you immune, you can still approve a malicious contract from one, but it protects the seed phrase itself.
- Verify URLs by typing them, not by clicking. Bookmark the sites you use.
- Reject prompts you do not understand. There is no cost to declining and reading up first.
- Review approvals every few months, particularly after using anything new.
Is recovery realistic?
Usually less so than for scams involving payments, and it is worth being direct about why.
With a fake investment platform you sent funds from an exchange, which gives investigators a starting point. With a drained wallet, funds moved directly from your address to the attacker's, often within seconds, and are frequently routed through a mixer or bridge before you notice.
It is more realistic if the theft was very recent and the funds went to an identifiable exchange rather than straight through a mixer. Our guide on what is recoverable sets out the factors, and how tracing works explains what an analyst can and cannot do.
Report it regardless. Drainer operations run at scale against thousands of wallets, and aggregated reports are how the infrastructure behind them gets identified.
What to preserve
- Your wallet address and the transaction hash of the draining transaction
- The attacker's address: visible in that transaction
- The approval transaction, if you can find it, and its date
- The site you connected to, including the exact URL
- The message or advert that led you there
- Screenshots of the signature prompt if you have them
Then follow the first 48 hours guide and file with the reporting channel in your country that can lead to an investigation.
Expect a recovery approach
Drainer victims are heavily targeted afterwards, often by people offering to "reverse the transaction" or "recover from the smart contract." Neither is possible.
Read how to spot a recovery scam before replying to anyone.
Frequently asked questions
How can my wallet be drained if I never sent anything?
Because you granted permission rather than making a transfer. Signing an approval lets a contract move tokens on your behalf, and many approvals are unlimited by default. The attacker uses that permission later, which is why the theft often happens well after you signed.
I signed something days ago and nothing happened. Am I safe?
Not necessarily. Approvals persist until revoked, and attackers often wait, sometimes to accumulate victims, sometimes until a wallet holds more. Check your approvals rather than assuming the delay means it was harmless.
Does a hardware wallet prevent this?
It protects your seed phrase, which is significant, but it does not prevent you approving a malicious contract. If you sign a drainer approval from a hardware wallet, the drainer still works. The protection is against phrase theft, not bad signatures.
Someone sent unknown tokens to my wallet. What should I do?
Nothing. Do not interact with them, do not try to sell them, do not visit any site named in the token. These are bait, the interaction is the attack. Hide the token in your wallet interface and ignore it.
Can I get my funds back by revoking the approval?
No. Revoking stops future transfers using that permission. It does not reverse what has already moved. Revoke anyway, immediately, to prevent further loss.
Do I need to revoke on every blockchain?
Yes. Approvals are specific to each network. If you have used the same wallet address across Ethereum, BNB Chain, Polygon, Arbitrum or others, check each one separately.
Wallet drained? Check what is realistic
Nine questions and an honest assessment of your specific case.
Evaluate my case free