What Is a Crypto Wallet Drainer? How to Tell If Your Wallet Was Drained

By Alexandr Kerya · · 6 min read

TL;DR - A crypto wallet drainer is a phishing kit that tricks you into signing a transaction or approval that hands an attacker control of your tokens. It does not steal your seed phrase - it gets you to authorise the theft yourself. You can spot the damage in your transaction history, cut off an active drainer by revoking token approvals, and lower your exposure by screening any contract or address before you sign.

Most people meet a wallet drainer the same way: a "free mint", a surprise airdrop, or a support DM that leads to a slick site. They connect their wallet, click approve, and within seconds the balance is gone. Drainers are now one of the most industrialised threats in Web3 - Chainalysis has reported quarters where the value stolen by drainers exceeded the value stolen by ransomware. This guide explains what a drainer is, how to tell if your wallet touched one, and what to do next.

What is a crypto wallet drainer?

A crypto wallet drainer is malicious software - usually a website plus a smart contract - built to empty a connected wallet. Drainers are sold as off-the-shelf "drainer-as-a-service" kits, so the same code powers thousands of scam sites. As Chainalysis puts it, operators "masquerade as web3 projects, enticing victims into connecting their crypto wallets to the drainer and approving transaction proposals that grant the operator control of the funds inside the wallet."

The key thing to understand: a drainer rarely needs your private key or seed phrase. It needs your signature. Modern wallets ask you to approve token spending and sign messages all the time, and a drainer disguises a malicious approval as a routine one. You authorise it, and the contract does the rest.

How does a wallet drainer actually steal your crypto?

Almost every drain follows the same four-step arc, whatever the lure on the front end.

A four-step flow diagram showing how a wallet drainer works: a fake site or airdrop lure, the victim connecting and approving a malicious transaction, the drainer contract sweeping the tokens, and the stolen funds being laundered through mixers and bridges.
  1. The lure. A fake airdrop, mint, giveaway, or "wallet validation" page. Chainalysis notes operators promote these "in Discord communities and on compromised social media accounts" - one campaign used a hijacked SEC account on X to push a fake airdrop.
  2. The signature. You connect your wallet and the site asks you to approve. This is the trap. It might be an ERC-20 approve for an unlimited spend, a setApprovalForAll on your NFTs, or an off-chain Permit / Permit2 signature that grants spending rights without an on-chain transaction.
  3. The sweep. Once the approval exists, the drainer contract transfers your tokens out - often picking the highest-value assets first and batching them in one or several transactions.
  4. The laundering. Stolen funds are moved fast through swaps, bridges, and mixing services to break the trail. Chainalysis reports drainer operators' use of mixers has risen since 2021 as they try to obscure where the money went.

Because steps 2 and 3 can be separated by hours or days, an approval you signed last week can be the thing that drains you today. That is why a wallet can look "fine" right up until it is emptied.

How do you know if your wallet was drained - or touched a drainer?

The warning signs are usually visible on-chain. Look for outgoing transfers you did not initiate, a sudden disappearance of tokens or NFTs after interacting with a new site, or approval transactions to contracts you do not recognise.

To investigate manually, open your address on a block explorer such as Etherscan and read the transaction list for unexpected Transfer and Approval events. Then check what you have authorised with an approval-auditing tool like Revoke.cash, which lists every active token approval on your address. If you see an open, unlimited approval to a contract you never meant to trust, that is the door a drainer walks through.

A block explorer shows the raw events, but it will not tell you whether the address that received your funds - or a contract you are about to approve - is already tied to known theft. Screen any wallet or counterparty with Plastron and you get the full risk picture in seconds: sanctions exposure, mixer contact, and proximity to stolen-funds and scam clusters across Ethereum and six other chains, with no wallet connection required. Running that check before you sign is the difference between spotting a drainer and funding one.

What should you do if your wallet was drained?

A checklist panel of the response steps after a wallet drain: revoke active token approvals, move remaining assets to a fresh wallet, treat the seed phrase as compromised, document the transaction hashes, and report to the platform - with a note that funds are rarely recoverable.

Act in this order. Speed matters, because an open approval lets the attacker keep coming back.

  1. Revoke active approvals from the affected wallet so the drainer contract can no longer move your tokens.
  2. Move what is left to a brand-new wallet generated on a clean device - ideally a hardware wallet. Send native gas tokens last so you can still pay fees for the other transfers.
  3. Treat the seed phrase as burned. If malware (not just a bad signature) was involved, the whole wallet is compromised. Never reuse it.
  4. Document everything - the malicious site URL, the transaction hashes, the receiving address, and timestamps. You will need these for any report.
  5. Report it to the wallet provider, the exchange if funds landed on one, and the relevant authorities. Be realistic: on-chain theft is rarely reversible, and anyone who DMs you promising guaranteed "fund recovery" is almost always a second scam.

How do you avoid wallet drainers in the first place?

  • Read what you sign. Treat every approve, setApprovalForAll, and Permit request as a question: why does this site need spending rights over my assets?
  • Use a burner wallet for mints, airdrops, and any unfamiliar dApp. Keep long-term holdings in a separate hardware wallet that never touches risky sites.
  • Verify the source. Airdrop and giveaway links from Discord, X, or DMs are guilty until proven innocent - even when they appear to come from an official account, which can be compromised.
  • Revoke approvals you no longer use, regularly. An approval that sits open forever is a standing liability.
  • Screen before you interact. Checking whether a contract or counterparty is linked to known scams or stolen-funds clusters takes seconds and removes the guesswork from "is this site real?"

Frequently asked questions

Can a wallet drainer steal my crypto without my seed phrase?

Yes. That is the whole point of a drainer. It does not need your seed phrase - it needs you to sign a malicious approval or transaction that grants its contract permission to move your tokens. Once that permission exists, the drainer can sweep your assets without ever seeing your keys.

Does disconnecting my wallet stop a drainer?

No. Disconnecting only stops a site from seeing your address; it does nothing about approvals you have already signed. If you granted a malicious approval, the contract can still spend your tokens after you disconnect. You have to revoke the approval to close that door.

How can I tell if a token approval is dangerous?

Watch for unlimited spend amounts, setApprovalForAll on NFT collections, and approvals to contracts with no verifiable project behind them. Audit your active approvals on a tool like Revoke.cash, and screen the spender address for links to known theft before trusting it. A legitimate dApp will usually request a specific, limited amount rather than unlimited access.

Will my wallet be flagged just for interacting with a drainer?

Receiving or being drained by a malicious contract puts a flagged address into your transaction history, and screening tools and exchanges can see that link. Direct contact with a known scam or stolen-funds cluster carries the most weight; a distant, indirect link matters less but does not vanish. Knowing your exposure before you deposit to an exchange lets you explain it rather than be surprised by a freeze.

Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.

About Plastron

Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.

How Plastron works and who runs it →

Keep reading

Identifying High-Risk Smart Contract Interactions: A Guide to Avoiding Wallet FlaggingAddress Poisoning: The Lookalike Address in Your HistoryWhat to Do If You Received Crypto From a Hacked ProtocolFATF Says Criminals Are Building Stablecoins No One Can Freeze