Wallet Drainer
A wallet drainer is malicious code, typically embedded in a scam website, that tricks visitors into signing transactions or approvals which transfer their crypto assets to an attacker. Drainers are sold as ready-made kits in criminal markets, with the kit developer taking a share of stolen funds, which has made this attack industrialized and widespread.
A typical scenario: a user sees a link to a supposed airdrop claim page, often spread through hacked social media accounts of real projects or through sponsored search ads. The site looks legitimate and asks them to connect their wallet and sign to claim. The signature is not a claim at all; it is a token approval, a batched transfer, or an off-chain order signature that authorizes the drainer contract to sweep tokens and NFTs. Sophisticated drainers inspect the wallet first and craft whatever combination of signatures extracts the most value, sometimes emptying a wallet in a single confirmation.
Defense comes down to signature hygiene: never sign anything on a site you reached from an ad, a direct message, or a hype announcement, and read what the wallet actually displays before approving. Modern wallets increasingly simulate transactions and warn about drainer patterns, which helps but is not foolproof. A common misconception is that merely connecting a wallet to a site can drain it; connection alone only reveals your address, and losses require you to sign something.