Independent platform · No upfront fees · We are not a recovery firm

Home › Knowledge Hub › Wallet drainers

Wallet drainers and token approval scams

By Yair Revach · Co-founder, Chain Pursuit · 8 min · Last updated 1 October 2026

A wallet drainer empties a wallet using permission you granted yourself, usually without realising. Rather than stealing a password, the attacker persuades you to sign a transaction or approve a smart contract that lets them move your assets later. Because the approval is legitimate at the protocol level, nothing blocks it, and the theft can happen hours or weeks after you signed.

If it just happened

Stop and do these three things before reading further.

  1. Move any remaining assets to a new wallet: one created fresh, with a seed phrase the attacker has never had a chance to see.
  2. Revoke the approvals on the compromised wallet, using a reputable revocation tool. Instructions below.
  3. Assume the wallet is permanently compromised if there is any chance your seed phrase was exposed. Revoking approvals does not help if the attacker has the phrase itself.

The order matters. Attackers often run automated scripts that sweep a wallet the moment anything arrives in it.

What an approval is

Most tokens work through a permission system. Before a decentralised application can move a token on your behalf (to swap it, stake it, or list it), you grant that application permission to do so. This is normal and necessary, and it is why the mechanism exists.

The problem is the scope. Many approvals default to unlimited: permission to move any amount of that token, indefinitely, with no further confirmation from you.

Grant that to a legitimate exchange contract and nothing happens. Grant it to an attacker's contract and they can drain that token whenever they choose, without you signing anything again.

Why the drain happens later
You sign an approval DAY 1 Contract gains unlimited permission waits Wallet drained without another signature HOURS OR WEEKS LATER Nothing happens when you sign, which is why people conclude it was harmless. Revoking the approval stops future transfers. It does not return what has gone.
The approval and the theft are separate events. Most people only connect them afterwards.

This is why the theft often happens later. People connect a wallet, sign something, see nothing bad occur, and conclude it was fine. The permission sits dormant until the attacker decides to use it.

Why the prompt looks harmless

The signature request that grants this permission is technical and unhelpful. Depending on the wallet, you may see a hexadecimal string, a contract address, and a function name, or a message asking you to "verify ownership" or "confirm you are human."

Some drainers use signature types that do not appear as transactions at all, so there is no gas fee and no obvious blockchain activity to alert you.

The honest position is that most people cannot read these prompts, and wallet interfaces have historically been poor at explaining them. Not understanding what you signed is not carelessness, the interface failed you.

How you get there

The signature is the mechanism; the lure gets you to it.

The seed phrase version

The other route is simpler and more final: convince you to type your recovery phrase into a website.

No legitimate wallet provider ever needs your seed phrase. Not for support, not for verification, not for migration, not for recovery, not to fix a bug. There is no exception to this and there never has been.

Anyone requesting it, including someone claiming to be from your wallet's support team, an investigator, or a government agency, is trying to steal from you.

Checking and revoking your approvals

Worth doing periodically even if nothing has gone wrong.

Our guide to revoking token approvals covers this in full.

  1. Use a reputable revocation tool. Revoke.cash and Etherscan's own Token Approval Checker are the widely-used ones. Navigate there directly: type the address rather than following a link, because fake revocation sites exist and are themselves drainers.
  2. Connect your wallet. Reviewing approvals is read-only.
  3. Look for approvals you do not recognise, and any marked unlimited.
  4. Revoke them. Each revocation is a transaction and costs gas.
  5. Repeat per network. Approvals are chain-specific, revoking on Ethereum does nothing on BNB Chain, Polygon or Arbitrum.

Revoking does not recover anything already taken. It stops future transfers.

Reducing the risk afterwards

Is recovery realistic?

Usually less so than for scams involving payments, and it is worth being direct about why.

With a fake investment platform you sent funds from an exchange, which gives investigators a starting point. With a drained wallet, funds moved directly from your address to the attacker's, often within seconds, and are frequently routed through a mixer or bridge before you notice.

It is more realistic if the theft was very recent and the funds went to an identifiable exchange rather than straight through a mixer. Our guide on what is recoverable sets out the factors, and how tracing works explains what an analyst can and cannot do.

Report it regardless. Drainer operations run at scale against thousands of wallets, and aggregated reports are how the infrastructure behind them gets identified.

What to preserve

Then follow the first 48 hours guide and file with the reporting channel in your country that can lead to an investigation.

Expect a recovery approach

Drainer victims are heavily targeted afterwards, often by people offering to "reverse the transaction" or "recover from the smart contract." Neither is possible.

Read how to spot a recovery scam before replying to anyone.

Frequently asked questions

How can my wallet be drained if I never sent anything?

Because you granted permission rather than making a transfer. Signing an approval lets a contract move tokens on your behalf, and many approvals are unlimited by default. The attacker uses that permission later, which is why the theft often happens well after you signed.

I signed something days ago and nothing happened. Am I safe?

Not necessarily. Approvals persist until revoked, and attackers often wait, sometimes to accumulate victims, sometimes until a wallet holds more. Check your approvals rather than assuming the delay means it was harmless.

Does a hardware wallet prevent this?

It protects your seed phrase, which is significant, but it does not prevent you approving a malicious contract. If you sign a drainer approval from a hardware wallet, the drainer still works. The protection is against phrase theft, not bad signatures.

Someone sent unknown tokens to my wallet. What should I do?

Nothing. Do not interact with them, do not try to sell them, do not visit any site named in the token. These are bait, the interaction is the attack. Hide the token in your wallet interface and ignore it.

Can I get my funds back by revoking the approval?

No. Revoking stops future transfers using that permission. It does not reverse what has already moved. Revoke anyway, immediately, to prevent further loss.

Do I need to revoke on every blockchain?

Yes. Approvals are specific to each network. If you have used the same wallet address across Ethereum, BNB Chain, Polygon, Arbitrum or others, check each one separately.

Wallet drained? Check what is realistic

Nine questions and an honest assessment of your specific case.

Evaluate my case free

Keep reading