Wallet drainers: how one signature empties a wallet, and what to do in the first hour

6 min read · Updated 10 February 2026

Most drained wallets were never hacked. A signature granted spending permission — here is how to read it and how to respond.

It is usually permission, not a hack

In the large majority of drained-wallet cases we review, no private key was stolen. The victim approved a transaction on a spoofed mint page, airdrop claim or "wallet validation" site, and that approval granted a contract permission to move their tokens — sometimes an unlimited allowance, sometimes an off-chain permit signature that costs no gas and produces no visible transaction.

This matters for the investigation, because an approval leaves a precise, timestamped record of the exact moment and the exact contract that took control.

The first hour

If a wallet is being drained right now, in this order:

  • Move any remaining assets to a brand-new wallet created on a clean device. Do not reuse the compromised seed phrase.
  • Revoke outstanding approvals on every chain the wallet has touched — a drainer often holds allowances that have not been used yet.
  • Record the transaction hashes of the outgoing transfers and the approval transaction that preceded them.
  • Note the exact site, link or message that led to the signature, and preserve it before it is taken down.
  • If any part of the balance reached a centralised exchange, report it to that exchange immediately with the hashes — speed is the only thing that keeps a freeze possible.

What the trace produces

From the approval transaction we can identify the drainer contract, cluster it with the other wallets it has emptied, and follow the proceeds through the sweep wallets and any mixer or bridge used afterwards. Drainer kits are operated as a service with a revenue split between the kit developer and the affiliate who ran the phishing site, and that split is visible on-chain — it often separates the person who targeted you from the wider infrastructure.

Reducing exposure afterwards

Treat approvals as a standing risk, not a one-off event. Keep long-term holdings in a wallet that never signs on unfamiliar sites, use a separate wallet for minting and testing, review allowances periodically, and read what a signature actually authorises rather than the label on the button.