Wallet drainer
Definition
A wallet drainer is malicious code that tricks you into signing transactions or approvals which transfer your assets to an attacker.
A wallet drainer is a kit of malicious code, usually embedded in a fake or compromised website, designed to empty a connected wallet. Rather than breaking cryptography, it manipulates the victim into authorising the theft: it presents a deceptive prompt so the user signs a harmful token approval, a permit signature, a setApprovalForAll, or a direct transfer. Once signed, the drainer’s contract or operator moves the assets out.
Why it matters
Drainers are behind many high-value self-custody losses. They are often promoted through fake airdrops, impersonated project sites, poisoned search ads, and hijacked social accounts, all funnelling victims to a page that says “connect wallet” and then requests a signature. Because the victim signs, the resulting transaction is valid and cannot be reversed, and a hardware wallet will not stop it if the user confirms.
Common misunderstanding
The biggest misconception is that merely connecting a wallet to a site drains it. Connecting alone only shares your address; the loss requires a signature or transaction you approve. The practical defences follow from this: read every signing request, be especially wary of unexpected approvals and permits, reject requests you did not initiate, and use a block explorer or approvals tool to review and revoke standing permissions. Keeping large holdings in cold storage separate from a browsing wallet limits what any single mistake can cost. Slowing down when a site asks you to sign something is the simplest and most effective defence of all.
Related terms
Frequently asked questions
Can just connecting my wallet to a site drain it?
Note: CamoCrypt is security & education only — no prices, no predictions, no investment advice. Verify every address and contract yourself; we cannot recover lost funds and neither can anyone who contacts you claiming they can.