BTC:
ETH:
SOL:
BNB:
XRP:
Wallet safety

Wallet drainers: how they actually work

A drainer doesn't need your seed phrase. It needs one signature—on a transaction that looks like a claim, a mint, or a swap, and does something else entirely.

7 min readReviewed July 13, 2026Wallet safety

The short answer

A wallet drainer is a script or malicious program that empties a connected wallet after the victim signs a transaction they didn't fully understand. Modern drainer campaigns are distributed as ready-made "drainer-as-a-service" kits: an operator rents the kit, builds a phishing front end, and keeps a cut of everything stolen through it.

This is a different threat than a stolen seed phrase. Your wallet stays under your control the entire time. The damage comes from a permission or transfer you approved yourself, without realizing what it actually authorized.

The typical kill chain

  1. Bait. A fake airdrop, mint, or "claim your rewards" page, often cloning a real project's design and promoted through paid ads, a deepfaked video, or a compromised social account.
  2. Connect. The victim connects a wallet to what looks like a normal dApp interaction.
  3. Sign. The site requests a transaction that either sets a malicious token account delegate, transfers assets directly, or—more recently— contains a program-level conditional that can be flipped after signing so a transaction that looked harmless at signing time behaves differently once submitted.
  4. Extract. Assets move out immediately, frequently routed through a swap and a no-KYC exchange to complicate tracing.

Google's Threat Intelligence team documented one such operation, CLINKSINK, running as a drainer-as-a-service since December 2023 across at least 35 affiliate campaigns, with an estimated $900,000+ stolen in identified waves (Google Cloud Threat Intelligence). Security firm Blowfish separately identified drainers ("Aqua" and "Vanish") capable of flipping a program's conditional logic after a valid signature was already collected (CoinGlass).

What actually reduces the risk

  • Use a burner wallet for anything unproven—see burner wallets.
  • Simulate before signing where your wallet supports it. Wallets like Solflare surface transaction simulation and flag risky interactions before you approve.
  • Check for delegates regularly and revoke anything you don't recognize—see revoking approvals.
  • Never treat urgency as a reason to skip review. Every drainer campaign depends on you signing faster than you read.

Sources

Turn the lesson into evidence

Check what a wallet has actually signed.

Preflight reconstructs a wallet's transaction history—no connection or signature required.

Open wallet preflight