Crypto glossary

Wallet Drainer

A wallet drainer is malicious code, usually hidden on a fake website, that tricks you into signing transactions or approvals that let attackers move your tokens and NFTs out of your wallet.

Auf Deutsch lesen

How a drainer works

Drainers rarely hack wallets directly. Instead they rely on you signing something. You land on a convincing copy of a real project, often through a fake airdrop, a compromised social media account, a sponsored search result or a direct message. You connect your wallet, and the site's script reads what you hold and prepares requests for your most valuable assets.

Those requests can be token approvals, NFT setApprovalForAll permissions, off-chain permit signatures, or plain transfers dressed up as a claim or mint. Once signed, the attacker's contract moves the assets within seconds. Some drainers are sold as kits to other scammers, who share a cut of the stolen funds with the developer.

An example

Say you see a post about a free token claim for holders of a project you use. The site looks right, you connect, and it asks for a signature that your wallet shows only as a long block of data. You sign it to claim. It was actually a permit giving a stranger unlimited access to your stablecoins, and they are gone moments later.

Warning signs

Urgency, such as claim within 30 minutes, links from replies or direct messages, and offers that require connecting a wallet to receive free money are classic signs. So are signature requests you cannot read, requests to approve tokens unrelated to what you are doing, and domains with small spelling differences from the real one.

Protecting yourself

Type known addresses yourself or use bookmarks. Read every request in full; if your wallet cannot decode it, do not sign. Use a separate wallet with little in it for new apps and mints, and keep savings in a wallet that never connects. A hardware wallet helps against malware on your computer, but it will still sign a malicious approval if you confirm it. If you signed something bad, revoke approvals immediately and move remaining assets to a new wallet.

Ask Coach about it

Coach is the AI on AtenaCrypto. It explains crypto with live market data, in plain words.

What should I do in the first minutes after signing a suspicious wallet request?Ask Coach →

Frequently asked questions

Can a drainer steal funds just because I visited a site?

Normally no. It needs you to connect and sign or approve something. Visiting alone, without signing, is generally not enough.

Does a hardware wallet stop drainers?

Only partly. It protects your keys from malware, but if you approve the drainer's request on the device, the transaction is valid.

Can drained funds be recovered?

Rarely. Blockchain transfers are final, and recovery usually depends on stolen funds landing at an exchange that freezes them.

Related terms

PhishingToken AllowanceRevokeBlind SigningSeed PhraseSocial Engineering

Learn it step by step

AC Learning explains these ideas in interactive lessons — the first eight sections are free.

Open AC Learning → Create a free account

All glossary terms · Educational reference only — not investment, legal, tax or financial advice.