๐Ÿ›ก๏ธ We will never ask you to pay to recover your funds. Anyone who promises to get your crypto back for a fee is scamming you.
๏ผ‹ Scam First Aid Get my action plan
Scam guide

Wallet drainer & approval scams: how they work and what to do

A wallet drainer tricks you into signing one malicious transaction or approval โ€” and that single signature lets a scammer empty your wallet of tokens and NFTs.

If this happened to you, it is not your fault. Malicious signature requests are designed to look routine. Here's how they work โ€” and what to do now.

What is a wallet drainer?

It's malicious code on a fake site (a phony airdrop, dApp, mint, or "wallet checker") that asks you to connect your wallet and sign a transaction or token approval. That approval grants spending access, and the drainer uses it to sweep your assets. A related trick, address poisoning, sends you a tiny transaction from a look-alike address hoping you'll copy it from your history.

How the scam unfolds

  1. 1.The lure. A "claim your airdrop," "connect to continue," or "validate your wallet" site โ€” often from an ad, DM, or hacked account.
  2. 2.The connect. You connect your wallet, and the site asks you to sign or approve something.
  3. 3.The approval. The signature grants token-spending access (e.g. an unlimited approve or permit) โ€” not an obvious "send."
  4. 4.The drain. The scammer moves your tokens and NFTs out, sometimes minutes or days later.

Warning signs

If your wallet was drained โ€” do this first

  • โ€ขRevoke all token approvals at revoke.cash right away.
  • โ€ขMove any remaining assets to a brand-new wallet (new seed phrase, generated offline). Assume the old wallet is compromised.
  • โ€ขNever copy an address from your transaction history โ€” always verify the full address from a trusted source.
  • โ€ขRecord the drainer address and your transaction hashes for reporting.
Build my full action plan โ†’

How to report it

โš ๏ธ Beware the second scam

"Recovery experts" may contact you promising to get your money back for a fee. Most are scammers targeting victims again. Never pay anyone who guarantees recovery or asks for an upfront fee. Read the red flags โ†’

You're not alone

Drainer signatures are deliberately disguised to look like normal wallet prompts. Being caught by one isn't carelessness. Reach out to someone you trust and consider a moderated victim community for support.

Get your personalized next steps

Answer 4 quick questions and get a tailored checklist, the right reporting links, and a ready-to-use evidence summary. Nothing is saved.

Start the action plan

โ† Back to all scam guides