Wallet drainers: how they actually work
A drainer doesn't need your seed phrase. It needs one signature—on a transaction that looks like a claim, a mint, or a swap, and does something else entirely.
The short answer
A wallet drainer is a script or malicious program that empties a connected wallet after the victim signs a transaction they didn't fully understand. Modern drainer campaigns are distributed as ready-made "drainer-as-a-service" kits: an operator rents the kit, builds a phishing front end, and keeps a cut of everything stolen through it.
This is a different threat than a stolen seed phrase. Your wallet stays under your control the entire time. The damage comes from a permission or transfer you approved yourself, without realizing what it actually authorized.
The typical kill chain
- Bait. A fake airdrop, mint, or "claim your rewards" page, often cloning a real project's design and promoted through paid ads, a deepfaked video, or a compromised social account.
- Connect. The victim connects a wallet to what looks like a normal dApp interaction.
- Sign. The site requests a transaction that either sets a malicious token account delegate, transfers assets directly, or—more recently— contains a program-level conditional that can be flipped after signing so a transaction that looked harmless at signing time behaves differently once submitted.
- Extract. Assets move out immediately, frequently routed through a swap and a no-KYC exchange to complicate tracing.
Google's Threat Intelligence team documented one such operation, CLINKSINK, running as a drainer-as-a-service since December 2023 across at least 35 affiliate campaigns, with an estimated $900,000+ stolen in identified waves (Google Cloud Threat Intelligence). Security firm Blowfish separately identified drainers ("Aqua" and "Vanish") capable of flipping a program's conditional logic after a valid signature was already collected (CoinGlass).
What actually reduces the risk
- Use a burner wallet for anything unproven—see burner wallets.
- Simulate before signing where your wallet supports it. Wallets like Solflare surface transaction simulation and flag risky interactions before you approve.
- Check for delegates regularly and revoke anything you don't recognize—see revoking approvals.
- Never treat urgency as a reason to skip review. Every drainer campaign depends on you signing faster than you read.
Sources
Turn the lesson into evidence
Check what a wallet has actually signed.
Preflight reconstructs a wallet's transaction history—no connection or signature required.
Open wallet preflight