Beginner · 9 min read

Wallet Drainers: How the Signature That Empties You Works

Nothing is hacked. You approve a transaction whose real meaning is hidden behind a wallet prompt that says almost nothing.

Selin AydinSelin AydinSecurity Editor · Crypto security, custody, exploits and smart-contract risk
Wallet Drainers: How the Signature That Empties You Works
The short answer

A wallet drainer is a kit that tricks a user into signing a message or transaction granting the attacker control of their tokens. The common vectors are ERC-20 approvals and Permit signatures, setApprovalForAll for NFTs, Seaport orders that sell assets for nothing, and delegate or ownership transfers. Because the signature is valid, no protocol is exploited and no funds are recoverable. The defence is reading what you sign and keeping high-value assets on a wallet that never touches unknown sites.

Drainer kits are sold as a service. The operator supplies the contract and the front end, an affiliate supplies the traffic — a fake airdrop, a compromised project account, a sponsored search result — and the split is usually 20/80. The victim's part is a single signature, and afterwards there is nothing to report to a protocol, because nothing was broken.

Vector one: the token approval

ERC-20 tokens cannot be moved by a contract unless you approve it. Approve a spender for an unlimited amount and that contract can transfer that token out of your wallet at any point in the future, with no further interaction from you.

Legitimate applications need this. So does a drainer. The prompt looks identical, and many wallets still display it as an opaque contract interaction with no amount and no counterparty name.

The dangerous property is persistence. An approval you granted two years ago to a project that has since been abandoned or compromised is still live, which is why reviewing and revoking approvals is a maintenance task rather than a one-off.

Vector two: Permit and Permit2 signatures

This is the one that catches experienced users. A Permit is an off-chain signed message that grants an approval without a transaction — no gas, no on-chain trace at the time of signing, and in most wallets a prompt that says "signature request" and shows a block of structured data.

Because it costs nothing and does not look like a transaction, people sign it casually. The attacker then submits the signature themselves and takes the tokens. Permit2, which many aggregators use legitimately, has the same shape and the same exposure.

The rule is uncomfortable but simple: a signature request that includes a spender address, a token address and an amount or deadline is an approval, whatever the wallet calls it. If you did not intend to grant one, reject it.

Vector three: setApprovalForAll

The NFT equivalent, and much worse, because it is all-or-nothing: one signature authorises a contract to transfer every token in that collection from your wallet. Marketplaces need it to list assets. Drainers ask for it while pretending to be a mint, a claim, or a collection migration.

Vector four: Seaport and order signatures

Marketplace protocols let you sign an order that sells an asset at a stated price. A drainer presents a signature request that is, in fact, an order selling your assets for zero or near-zero consideration to an address it controls. No approval is needed beyond the marketplace approval you already granted when you first listed something.

This is why a wallet that decodes signature payloads into plain language matters more than any other feature. The better wallets now show "you are selling X for 0 ETH" instead of a hash — and that single line stops the attack.

Vector five: account-level control

Two variants worth knowing. Contract wallets and smart accounts can have their owner changed; a drainer may ask you to sign an ownership transfer disguised as a security upgrade. And on chains supporting delegation, a signature can point your account's execution at attacker-controlled code, which converts a normal wallet into one that forwards everything.

How the traffic reaches you

The signature is the easy part for the attacker; getting you to the page is the work. The recurring channels are paid search ads above the real result for a wallet or bridge, compromised project accounts on social platforms posting a claim link, Discord announcement channels after a moderator account is taken over, and airdrop notifications that arrive as tokens or NFTs sent directly to your wallet with a website written in the metadata.

That last one is worth stating plainly: assets you did not buy appearing in your wallet are advertising, and interacting with them is the entire point.

The defence, in order of effectiveness

**Separate wallets by function.** A wallet holding long-term assets should never connect to a site. Do exploratory minting and claiming from a wallet holding what you can afford to lose. This single structural change defeats every vector above, because the drainer can only take what the connecting wallet holds.

**Use a hardware wallet with a screen that decodes.** Signing on a device that displays the actual contract call and amount removes the gap between what the browser claims and what you authorise. Our hardware wallet ratings weight clear-signing quality heavily for exactly this reason.

**Read the prompt for three things:** which contract, which token, what amount. If any of the three is unclear or unlimited and you did not expect it, cancel. Cancelling costs nothing.

**Navigate by bookmark, never by search or by link.** Almost every drainer campaign depends on the first click being wrong.

If you have already signed

Speed matters, and the first move is not to revoke — it is to move. Transfer remaining assets to a fresh wallet, because a live approval only endangers what stays in the compromised account. Revoke afterwards, and treat the wallet as burned if a delegation or ownership change was involved rather than a token approval. The first-hour playbook covers the sequence in detail.

FAQ

How do wallet drainers actually steal funds?
They get the user to sign a valid approval, permit, marketplace order or ownership change. The transfer that follows is legitimate on-chain activity, which is why nothing can be reversed and no protocol was exploited.
Is signing a message safe if it costs no gas?
No. Off-chain signatures like Permit and Permit2 grant token approvals without a transaction, and marketplace order signatures can sell your assets for nothing. Gasless does not mean harmless.
What is setApprovalForAll?
An NFT approval that authorises a contract to transfer every token you own in a collection. It is required by marketplaces and abused constantly by fake mints and migration pages.
What should I do immediately after signing a drainer prompt?
Move remaining assets to a new wallet first — revoking takes a transaction that may be outrun. Then revoke the approvals, and abandon the wallet entirely if account ownership or delegation was changed.