Wallet Drainers: How the Signature That Empties You Works
Nothing is hacked. You approve a transaction whose real meaning is hidden behind a wallet prompt that says almost nothing.
Nothing is hacked. You approve a transaction whose real meaning is hidden behind a wallet prompt that says almost nothing.
A wallet drainer is a kit that tricks a user into signing a message or transaction granting the attacker control of their tokens. The common vectors are ERC-20 approvals and Permit signatures, setApprovalForAll for NFTs, Seaport orders that sell assets for nothing, and delegate or ownership transfers. Because the signature is valid, no protocol is exploited and no funds are recoverable. The defence is reading what you sign and keeping high-value assets on a wallet that never touches unknown sites.
Drainer kits are sold as a service. The operator supplies the contract and the front end, an affiliate supplies the traffic — a fake airdrop, a compromised project account, a sponsored search result — and the split is usually 20/80. The victim's part is a single signature, and afterwards there is nothing to report to a protocol, because nothing was broken.
ERC-20 tokens cannot be moved by a contract unless you approve it. Approve a spender for an unlimited amount and that contract can transfer that token out of your wallet at any point in the future, with no further interaction from you.
Legitimate applications need this. So does a drainer. The prompt looks identical, and many wallets still display it as an opaque contract interaction with no amount and no counterparty name.
The dangerous property is persistence. An approval you granted two years ago to a project that has since been abandoned or compromised is still live, which is why reviewing and revoking approvals is a maintenance task rather than a one-off.
This is the one that catches experienced users. A Permit is an off-chain signed message that grants an approval without a transaction — no gas, no on-chain trace at the time of signing, and in most wallets a prompt that says "signature request" and shows a block of structured data.
Because it costs nothing and does not look like a transaction, people sign it casually. The attacker then submits the signature themselves and takes the tokens. Permit2, which many aggregators use legitimately, has the same shape and the same exposure.
The rule is uncomfortable but simple: a signature request that includes a spender address, a token address and an amount or deadline is an approval, whatever the wallet calls it. If you did not intend to grant one, reject it.
The NFT equivalent, and much worse, because it is all-or-nothing: one signature authorises a contract to transfer every token in that collection from your wallet. Marketplaces need it to list assets. Drainers ask for it while pretending to be a mint, a claim, or a collection migration.
Marketplace protocols let you sign an order that sells an asset at a stated price. A drainer presents a signature request that is, in fact, an order selling your assets for zero or near-zero consideration to an address it controls. No approval is needed beyond the marketplace approval you already granted when you first listed something.
This is why a wallet that decodes signature payloads into plain language matters more than any other feature. The better wallets now show "you are selling X for 0 ETH" instead of a hash — and that single line stops the attack.
Two variants worth knowing. Contract wallets and smart accounts can have their owner changed; a drainer may ask you to sign an ownership transfer disguised as a security upgrade. And on chains supporting delegation, a signature can point your account's execution at attacker-controlled code, which converts a normal wallet into one that forwards everything.
The signature is the easy part for the attacker; getting you to the page is the work. The recurring channels are paid search ads above the real result for a wallet or bridge, compromised project accounts on social platforms posting a claim link, Discord announcement channels after a moderator account is taken over, and airdrop notifications that arrive as tokens or NFTs sent directly to your wallet with a website written in the metadata.
That last one is worth stating plainly: assets you did not buy appearing in your wallet are advertising, and interacting with them is the entire point.
**Separate wallets by function.** A wallet holding long-term assets should never connect to a site. Do exploratory minting and claiming from a wallet holding what you can afford to lose. This single structural change defeats every vector above, because the drainer can only take what the connecting wallet holds.
**Use a hardware wallet with a screen that decodes.** Signing on a device that displays the actual contract call and amount removes the gap between what the browser claims and what you authorise. Our hardware wallet ratings weight clear-signing quality heavily for exactly this reason.
**Read the prompt for three things:** which contract, which token, what amount. If any of the three is unclear or unlimited and you did not expect it, cancel. Cancelling costs nothing.
**Navigate by bookmark, never by search or by link.** Almost every drainer campaign depends on the first click being wrong.
Speed matters, and the first move is not to revoke — it is to move. Transfer remaining assets to a fresh wallet, because a live approval only endangers what stays in the compromised account. Revoke afterwards, and treat the wallet as burned if a delegation or ownership change was involved rather than a token approval. The first-hour playbook covers the sequence in detail.
The order of operations decides how much you keep. Most people revoke first, which is the step that loses them the rest.
TVL is the industry's default size metric and one of its least standardised. The definition changes with the incentive of whoever is publishing it.

Most wallet losses are not stolen keys. They are approvals granted months ago to a contract that later turned hostile — and revoking them takes about a minute.