You were on a website offering an airdrop, an NFT mint, or a security check. Your wallet requested verification, you clicked the link, and everything seemed fine. Shortly after, tokens, NFTs, or both went missing.

That was a wallet drain. And the puzzling thing is: nothing was hacked. There was no security breach, no intrusion, and no blockchain error. From the network's perspective, it was a perfectly legitimate transaction. You did indeed sign it, you just didn't understand what rights you were granting.

This is precisely what makes the case so elusive and yet less hopeless than it feels. Unlike with a stolen key, the perpetrator's access is usually limited, and some of it can be disabled.

What a wallet drainer is and what it isn't

A wallet drainer isn't software on your phone or in your wallet. There's nothing to uninstall. It's powered by an infrastructure: a convincingly constructed fake website, a connection to your wallet, logic that evaluates your holdings in the background, pre-prepared signature requests, one or more smart contracts, and collection addresses for the stolen funds.

The crucial point: With traditional methods, the perpetrator doesn't gain general control over your wallet, but only the specific permissions you've granted. Your seed phrase remains unknown. This limits both the potential damage and the chances of successful defense.

This fundamentally distinguishes the drainer from the Sweeper Bot, In this case, the perpetrator knows your key and therefore has permanent access to everything. You can revoke access you have granted, but you cannot revoke a key that has been compromised.

How a wallet drainer attack typically unfolds

The bait. They end up on a deceptive website via fake airdrops, NFT mints, token claims, staking, or bridge offers. Often, compromised social media accounts, paid search ads, or links from direct messages lead there. Increasingly, these are imitations of well-known providers using almost identical domain names.

The connection. You connect your wallet. This alone does not yet authorize access, but from this moment on, the other party knows your address.

The rating. Your inventory is being read and sorted in the background. The query displayed to you depends on which value yields the highest return and can be processed most quickly. Therefore, the same page generates different queries for different users.

The signature. They confirm: a release, a message, an authorization, or directly a transaction.

The execution. The right is exercised, often for multiple values in a single transaction.

The redirect. The loot is sent to collection points, divided, exchanged, moved via Bridges, and paid out somewhere.

Crucially, the drain is the end of the chain, not its beginning. The decisive moment lies before it.

What you actually confirmed

A release for tokens

On Ethereum and similar networks, you can authorize an address or program to transfer tokens on your behalf. This is perfectly normal and essential for decentralized exchanges.

It becomes abusive when this permission is granted to a contract of the perpetrator. They can then access the released amount at any time without you having to do anything further.

Two things exacerbate the problem. First, many applications request unlimited permissions for cost reasons, far exceeding the scope of the specific request. Second, a granted permission remains in effect until it is revoked or used up. Disconnecting the wallet from the website only ends the browser session; it doesn't change the permission itself.

One release for your entire NFT collection

With NFTs, the possibilities go even further. Beyond individual items, a single confirmation can be used to appoint a manager for the entire collection. If the perpetrator controls this manager, they can transfer all NFTs in that collection without further authorization. For valuable collections, this can result in significant damage in a single transaction.

A signature without a visible transaction

This is the most insidious variant. Newer methods shift the authorization from the transaction to the signature. You sign a structured message that authorizes authorization or a direct transfer. It is then redeemed later by someone else.

For you, this looks doubly harmless: there are no fees, and the wallet often only displays technical data without any understandable explanation. However, the absence of a cost warning does not mean that nothing happens.

Added to this is the time lag. Hours or even days can pass between your signature and the transaction being executed. This is precisely why many affected individuals misjudge the timing of the incident and look for the error in the wrong place. And this is particularly problematic for investigations: The signature itself leaves no trace on the blockchain. Only its redemption is visible. The fact that you signed at all must be proven from browser history, wallet logs, or your communications.

One authorization for your entire account

Since an Ethereum update in May 2025, regular wallets can delegate execution rights to a smart contract. This is intended for convenience features, such as allowing someone else to cover your fees or bundling multiple transactions.

This creates a new dimension for drainers. Instead of a single token release, you are presented with authorization to sign, often disguised as a security or convenience upgrade to your wallet. What is possible afterward is determined solely by the code you have granted this authorization to, even extending to the withdrawal of your regular coins. This variant thus circumvents the very limitations that otherwise characterize drainers.

At Solana: a silent change of ownership

Solana works differently and in one respect goes further. There, the authorization to access a single token account can be transferred to another address. After that, you can no longer access that specific token, even though your key remains valid for everything else.

The insidious thing about it is that no money changes hands during this process. It looks like nothing at all. Many surfaces therefore make the change less noticeable than a visible drain.

Also specific to Solana are transactions that remain valid indefinitely through a special process, instead of expiring after a short time. They can therefore be submitted considerably later. Here too, the moment of signature and the moment of execution are significantly separated.

Why your wallet isn't completely empty anyway

In a permission-based attack, not everything is necessarily taken. Only what the permission covers is affected: a specific token type, a specific NFT collection, a specific contract.

On Ethereum and similar networks, your regular coin, ETH or BNB, is not covered by a token or NFT release. Its transfer requires a separate transaction signed with your key. This is a strong indicator that helps you: If ETH remains unaccounted for while individual tokens are missing, it suggests that your key has not been compromised.

However, the reverse is not true. ETH can also flow out of a drainer if you have directly confirmed a transfer transaction or one of the account permissions described above. Therefore, "My ETH is gone too" does not prove key theft; it merely shifts the question to which specific permission led to the outflow.

Why a hardware wallet doesn't automatically protect

This is the most common misconception in this context. A hardware wallet protects your key because it never leaves the device. However, it doesn't protect you from accidentally confirming something incorrectly. A malicious share will be signed just as correctly as a legitimate one.

What matters is not where your key is located, but what you authorize.

Underlying this is a fundamental problem that makes most of these attacks possible in the first place: You confirm something whose content and consequences are not fully or clearly displayed. Sometimes only raw data appears, sometimes the function being called is not explained in plain text, and sometimes warning messages are clicked away out of habit.

Even preview and testing functions, designed to show you what a transaction will do, don't offer complete protection. A gap remains between testing and execution, which is deliberately exploited: Some contracts recognize that they are only being tested and then behave harmlessly. Others can be rewritten afterward. And in some cases, the malicious code doesn't even exist at the time of testing.

What to do immediately after a wallet drainer attack

Don't sign anything anymore. Neither on the website in question nor on alleged testing or rescue services.

Find out what happened before you take action. The key question is: Was only a permission misused, or was your key also compromised? Everything depends on this. In the first case, a revocation is sufficient; in the second, you must migrate everything to a new wallet.

Review and revoke permissions. Reset existing token and NFT approvals, and additionally revoke any granted account authorization. Revocation incurs network fees and only takes effect prospectively.

Do not follow the sequence schematically. Whether you move the remaining values first or revoke them first depends on the specific case. A transfer itself requires confirmation; an active release remains usable until revoked.

Secure evidence before deleting browser data or resetting the device.

Do not accept any rescue offers. More on that below.

And one important limitation: Revoking the permission only protects against future use of the shared data. Data already used will not be recovered. And it's completely useless if your key is known, your device is infected, or an account authorization is still active.

You should secure this evidence.

  • the address in question
  • all transaction hashes with time and amount
  • The accessed website with its full address, via screenshot
  • Browser history and, if available, your wallet activity log
  • all communication through which you accessed the page
  • which wallet software and which browser extensions are in use

Your browser history is not a minor detail here, but often the most important piece of evidence because it proves the time of your signature. And if you suspect your device is infected: don't clean it hastily, but also don't continue using it for your wallet, banking, or email. You can read about which evidence ultimately counts below. Evidence in cases of crypto fraud.

Then file a criminal complaint. We'll show you how to do this below. Report crypto fraud.

Beware the second wave: Recovery scam after the drainer

Such an incident is regularly followed by a second fraud attempt. Alleged recovery services, fake support accounts, and manipulated "recovery dashboards" are specifically designed to exploit situations where you are willing to take another risk.

A typical scenario begins with a malicious share and only then escalates: The victim contacts a fake support team and also hands over the seed phrase. A limited drainer attack then becomes a complete compromise, which is irreparable. We'll show you how to recognize such providers in [link to article]. How to recognize recovery scams after crypto fraud.

Remember this: No reputable service provider ever needs your seed phrase or private key. We also never contact victims proactively.

What blockchain analysis can and cannot do

An analysis cannot recover anything, and we want to make that very clear. What it can do is reconstruct the path: from your wallet via the drainer contract to the collection addresses, then through exchanges, bridges or mixers, to a payout point.

That's precisely where the problem lies. If the funds reach a regulated exchange with identity verification, there's a real entity to which authorities can submit requests for information and security. In the case of stablecoins, a block by the issuer is also a possibility; see [link/reference]. Freeze USDT and USDC.

From a forensic perspective, the situation is better than it might seem: approvals, permissions, contract calls, and redirects are permanently documented and can be analyzed chronologically. Where the signing process itself remains invisible, device and communication traces take its place. We describe the full possibilities below. Recover cryptocurrencies and asset recovery.

One more thing that surprises many: Anyone who forwards payments or makes their account available after the incident can themselves become a target of the authorities. We describe what happens then below. Account blocked due to suspected money laundering.

Avoid wallet drainers: how to protect yourself in the future

  • Separate wallets according to their purpose. The wallet you use for long-term storage should never be the same one you use to try out new applications.
  • Limit releases and regularly revoke permissions that are no longer needed. Avoid unlimited permissions.
  • Read signature requests. Don't confirm what you don't understand. Especially when it comes to permissions and structured signatures without any apparent reason.
  • Check the origin of the page. Do not accept links from direct messages, comments, or advertisements. Always type the address yourself.
  • Hardware wallet for larger holdings, and actually read the content on the device display.

We have further prevention tips in our Guide to recognizing and avoiding crypto fraud compiled.

Conclusion: The blockchain itself is not under attack, but rather your verification.

Wallet drainers don't attack the blockchain itself, but rather the moment you authorize something. They work because a signature is technically binding, but its meaning is often not apparent to you. And the trend is heading in the wrong direction: from signatures without any indication of fees to far-reaching account permissions and silent ownership changes at Solana, the harmful effects are becoming increasingly invisible, delayed, and widespread.

Ultimately, only one question matters to you: Was only one permission misused, or is your entire wallet compromised? This will determine whether a simple revocation is sufficient or whether everything needs to be transferred to a new wallet.

If you are unsure how your case should be classified, use our Free initial assessment for crypto fraud or Contact us directly.

FAQs about the Wallet Drainer

Is my wallet completely compromised after a drainer attack?

Not necessarily. If the incident only affects a release or signature, your key remains unaffected. However, this should be verified, not assumed, especially if ETH or SOL have also been compromised.

Is it possible to remove a wallet drainer?

There is nothing to remove from your wallet. You can revoke permissions and reset account authorizations. The perpetrator's infrastructure remains unaffected.

Is it enough to disconnect from the website?

No. This only ends the session in the browser. Granted permissions and access rights remain unchanged.

Why did my money disappear days after the suspicious click?

Because some signatures and pre-approved transactions can be redeemed later. The suspicious activity then occurs well before the outflow.

Does a hardware wallet protect against wallet drain?

It protects against key theft, yes; it protects against incorrect confirmation, no. What you authorize will be correctly signed, regardless of the device.

Is it sufficient to revoke the permissions?

Only if exclusively shared folders are affected. If the key is known, malware is active, or account authorization still exists, the address should be treated as lost.

How can I distinguish a drainer from a sweeper bot?

The extent of the problem and whether your key is affected. If ETH remains untouched and only individual tokens are missing, this suggests a drainer. If every new deposit disappears immediately, this indicates a Sweeper Bot there.

Are my NFTs affected?

If you have granted a manager access to an entire collection, all NFTs in that collection can be transferred without further approval. Therefore, review your NFT permissions first.

Will Crypto Investigation recover the stolen funds?

No. We reconstruct the flow of funds and compile a report that authorities and lawyers can use for further work. Exchanges, publishers, authorities, and courts decide on any necessary safeguards.

What is the most important first step?

Do not sign anything, secure the evidence unchanged, have the mechanism in place clarified, and only then decide on revocation or moving to a new wallet.

Note: This article is for general information purposes only and does not replace legal advice in individual cases. Crypto Investigation is a forensic service provider and not a law firm.