Security · Drainers

Crypto Wallet Drainer Scams Explained

Wallet drainers can empty your crypto wallet in a single transaction — before you realise anything happened. Here is exactly how they work and how to protect yourself.

Ashir Khan
By Ashir Khan3 min read

Ashir Khan writes about cryptocurrency security, self-custody, macro market analysis, and regulatory policy at CryptoBeacon.

Last updated:

Wallet drainers can be triggered by a single signature. Once signed, draining is instantaneous and irreversible. The defence is reading before you sign.

What is a wallet drainer?

A wallet drainer is malicious smart contract code that, once authorised (by your signature), can transfer tokens or NFTs out of your wallet without any further interaction from you. The attacker deploys the drainer contract and then lures victims into signing a transaction that grants it access to their assets.

Unlike hacking a private key (which is computationally infeasible), drainers exploit the legitimate approval mechanisms built into token standards. They are legal transactions — from the blockchain's perspective — because you authorised them.

ERC-20 approval exploits

ERC-20 tokens have an approve(spender, amount) function. When you interact with DeFi protocols, you approve them to spend a certain amount of your tokens on your behalf. This is necessary and legitimate — it is how DEXes and lending protocols work.

The attack: a fake dApp asks you to approve an unlimited amount (type(uint256).max) to the attacker's contract rather than to a legitimate protocol. Once you sign, the attacker can drain that token from your wallet at any time.

setApprovalForAll: the nuclear NFT exploit

setApprovalForAll(operator, true) is an ERC-721 (NFT) function that gives an operator permission to transfer every NFT from a specific collection in your wallet. It is used legitimately by marketplaces like OpenSea so they can transfer NFTs when you sell them.

Attackers abuse it by prompting victims to call setApprovalForAll on their malicious contract — typically disguised as a minting transaction, a reward claim, or a marketplace listing. Once signed, the attacker can transfer all your NFTs from that collection instantly.

Permit signatures: zero on-chain trace

ERC-2612 adds a permit() function that allows approvals to be signed off-chain (no on-chain transaction, no gas, no entry in your history). Drainers increasingly use permit signatures — they look like a free signature request, but they grant the same spending authority as an on-chain approval. No transaction visible, no gas charge, and the approval is valid instantly when submitted by the attacker.

How to detect dangerous approval requests

  • Read the full transaction details in your wallet popup before confirming
  • If it shows an approval to a contract you don't recognise, reject it
  • Unlimited approvals (115792...2815) to unknown contracts are a definitive red flag
  • Use Pocket Universe, Fire, or WalletGuard browser extensions that simulate transactions before you sign
  • If a "free" action asks for an approval signature, it is suspicious

Revoke existing approvals

If you are concerned about past approvals, use Revoke.cash or Etherscan's token approval checker to see all active approvals on your address and revoke any you do not recognise or no longer need.