Open app

NexFlow › Wallet drainer scams

Wallet drainer scams — how one signature empties a wallet

A wallet drainer is not a virus and not a hack — it is a signature you were tricked into giving. Here is exactly how the kits work, who runs them, and where the defense actually lives.

Updated 2026-10-06 · ~9 min read · every claim sourced and dated

Wallet drainers are the highest-volume theft mechanism in crypto — the pattern behind most “my wallet got emptied overnight” stories. The industry treats them like malware, but the mechanics are simpler and more preventable than that framing suggests: a drainer is a permission you granted under false pretenses, and every step of that grant is visible if you know where to look.

Every claim below names its source and date.

What a drainer actually is

A drainer is a script — usually delivered through a fake or compromised website — that calls your wallet and asks it to sign something that gives the attacker control of your assets: a token approval, a Permit/Permit2 signature, a setApprovalForAll on your NFTs, or a crafted transaction. The critical mechanic: drainers do not steal your seed phrase and do not need to. They exploit the fact that a signed approval IS the authority — once you sign, the attacker's contract can pull the approved assets whenever it wants, no further contact needed.

That is why the “I never gave anyone my seed phrase” defense is beside the point — the wallet did exactly what the signature authorized. The theft happened at the signature, not at a later hack.

The attack flow, step by step

The pattern is so standardized that drainer incidents read like copies of each other:

1. The lure. A fake airdrop claim, a “mint is live” announcement, a fake token-verification page, or a compromised-but-real-looking site — often promoted through hacked X/Discord accounts of real projects, bought ads, or reply-guy links under legitimate posts.

2. The connect. The site asks you to connect your wallet — an ordinary-looking step that itself is harmless (connecting reveals your address, nothing more).

3. The signature. The site requests a signature presented as something benign — “verify ownership”, “claim your airdrop”, “confirm eligibility” — while the actual payload is an approval, a Permit2 grant, or a setApprovalForAll covering your entire NFT collection.

4. The drain. The attacker's contract pulls every approved asset — sometimes immediately, sometimes hours later to break the mental link between the site visit and the loss.

It is an industry, not a hacker

The scale fact that reframes the threat: most drainers are not custom-built per attack. They are products — drainer kits sold as a service (the famous ones — Inferno Drainer, MS Drainer, Pink Drainer, Angel Drainer — were documented by security researchers as subscription businesses with revenue-share pricing, support channels, and customer-facing dashboards). An affiliate buys access, points the kit at a lure, and the kit operators take a cut of everything drained.

That industrialization is why the same signature patterns keep working: the kits are continuously updated to render signature requests that wallets struggle to display honestly, and to cycle through fresh contract addresses faster than blocklists update.

The honest asterisk: wallets show you the sign — badly

The uncomfortable truth in the defense file is that most drain victims were shown the dangerous request — inside a wallet UI that rendered it as an unreadable hex blob, an ambiguous “signature request”, or a wall of method names. The defense burden is genuinely unfair right now: wallets are improving (transaction simulation, human-readable approval warnings) but the gap between “what the signature does” and “what the user sees” is where the whole industry of theft lives.

What actually protects you

The defenses that hold, in order of value:

Read what the signature grants, not what the site says. An approval to an unverified contract, a Permit/Permit2 for your entire balance, or a setApprovalForAll — any of these on a site you don’t fully trust is the attack, full stop. Nothing else on the page matters.

Never connect to an airdrop/mint link from replies or DMs. Nearly every drainer lure arrives through social channels; legitimate claims come through official announcements you navigate to yourself.

Revoke approvals you didn’t intend. Approval-revocation tools let you see and kill open grants — run it on any wallet that ever touched an airdrop link.

Keep value off the browsing wallet. A drainer can only take what’s in the connected wallet — a separate hot wallet for interactions is the structural fix that makes every other defense a backup.

What to do if you signed

If you realize you signed a malicious approval before assets moved: revoke the approval immediately — the grant only works while it exists. If assets already moved, the honest answer is that signature-authorized transfers are final; report the contract and domain to the chain’s abuse lists and to the wallet’s security team, because kits get blocklisted and the report is how the next victim’s wallet warns them. Recovery services that promise to get drained funds back are the secondary scam that follows the first — treat any “we can recover it” pitch as the next attack.

Why wallets can't just block it

The obvious question — why doesn't the wallet refuse a setApprovalForAll to a random contract? — has the uncomfortable answer that the wallet can't tell intent. A legitimate NFT marketplace listing and a drainer request are the same signature type; a Permit2 grant to Uniswap and to a scam page are byte-for-byte the same kind of authorization. Wallets can't distinguish "user listing an NFT on a real marketplace" from "user granting the same right to a drainer" without reputation data the wallet doesn't reliably have for fresh contracts — and drainer kits rotate contract addresses specifically to stay ahead of whatever reputation the wallet does track.

This is why the defense space is arms-race-shaped rather than solved: transaction simulation shows the post-state ("after this signature, contract X can move your tokens") and human-readable decoding translates hex into "setApprovalForAll: true for all 23 of your NFTs" — both genuinely help, and kits respond by designing requests that render ambiguously even under simulation. The wallet layer improves steadily; the kits evolve alongside it.

The kit model, and why it matters to your defense

Understanding the supply side changes the math of your exposure. When Inferno Drainer reportedly retired in late 2023 and Pink Drainer followed in 2024, the thefts didn't slow — affiliate volume flowed to whichever kit was live, and new kits spun up with the same playbook. What this means practically: the threat isn't one team's infrastructure that law enforcement or blocklists can kill. The signature patterns, lure templates, and fake-site generation are commoditized — a takedown displaces volume rather than removing it.

It also explains the volume. Chainalysis and wallet-security researchers have attributed hundreds of millions of dollars in cumulative theft to drainer kits since 2021 — not through exotic exploits but through the same three signature types requested at industrial scale, against lures generated faster than blocklists cycle. The economics guarantee persistence: an affiliate needs one victim in thousands to profit; the kit takes a percentage of every drain, so it keeps shipping improvements for free.

Your defense therefore can't rely on the kits being blocked — it has to be signature hygiene: nothing gets an approval, a Permit, or a setApprovalForAll unless you navigated to the site yourself and intended exactly that grant.

The verdict, precisely

A wallet drainer is a signature you gave under false pretenses — preventable at the signature step, unrecoverable after the transfer. The defense is not antivirus or paranoia about every site; it is the habit of reading what a signature actually grants before you give it, and keeping serious value out of the wallet that browses.

Frequently asked

What is a wallet drainer?

A script on a fake or compromised site that tricks you into signing a token approval, Permit signature, or setApprovalForAll — giving the attacker's contract authority to pull your assets. It steals permissions, not your seed phrase.

Can a drainer steal my seed phrase?

No — it doesn't need to. A signed approval IS the authority; once you sign it, the attacker moves approved assets whenever they want. That's why victims who 'never shared their phrase' still got drained.

How do I know if a signature is a drainer?

Any token approval to an unverified contract, a Permit/Permit2 covering your balance, or a setApprovalForAll from a site you don't fully trust IS the attack — regardless of what the page calls the signature.

What should I do if I signed a malicious approval?

Revoke it immediately — an approval only works while it exists. If assets already moved, the transfer is final; report the contract and domain to abuse lists and treat any 'recovery service' pitch as the follow-up scam.

How do wallet drainers find victims?

Through lures — fake airdrop claims, 'mint is live' links, verification pages — pushed through hacked project accounts, reply-guy links, bought ads, and DMs. The lure comes to you; legitimate claims don't.

Are drainers run by individual hackers?

Mostly not — they're sold as kits-as-a-service (Inferno, Pink, Angel and others are documented subscription products with revenue-share pricing), which is why the same attack patterns keep working at industrial scale.

NexFlow is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a NexFlow product