warm background

What is a wallet drainer? How they empty crypto wallets

What is a wallet drainer? How they empty crypto wallets
AdminAdmin
發佈於 7 分鐘閱讀

A wallet drainer is a ready-made toolkit that steals crypto by tricking you into signing one transaction. In that signature lies the theft. Nothing gets hacked, no password is stolen, and your wallet does exactly what you told it to. According to Scam Sniffer, $83.85 million was drained from 106,106 wallets in 2025, down 83% from $494 million the year before.

Drainers ask for permission, not secrets

Where ordinary phishing asks for a secret, a drainer asks for permission.

From a fake login page comes a request for your password. From a fake wallet site, your seed phrase. Most people have been warned about both, and most refuse.

A drainer asks for none of that. Instead it shows you a normal-looking transaction: claim an airdrop, verify your wallet, mint an NFT, connect to a site. You press confirm because pressing confirm is how crypto works. That single signature hands an attacker's contract permission to move your tokens, and the sweep follows.

Hence why experienced users get drained. They know never to share a seed phrase. Nobody asked them to.

How a wallet drainer works

Four parts. Only the third involves you.

  1. A malicious page. A fake mint, a cloned exchange, a fraudulent airdrop claim, or a compromised legitimate site.
  2. A wallet connection. You connect, which by itself steals nothing.
  3. A signature request, presented as routine. You approve it.
  4. A spender contract that immediately transfers your tokens to addresses the attacker controls, often splitting them across several to complicate tracing.

Every drainer kit ends at the same place: the moment you press confirm. Every drainer kit also fails if you do not.

Drainer-as-a-service

These are everywhere because running one requires no technical skill at all.

On Telegram and dark web forums, drainer kits are sold and rented on a revenue-share basis. Operators build and maintain the software. Affiliates run the phishing campaigns and drive traffic. Between them the profits split, typically with the kit operator taking a percentage of everything stolen.

Among the named kits runs a lineage that reads like a business sector: Monkey, then Inferno, then Angel, Pink, and Medusa. Inferno Drainer alone was linked to more than $80 million in theft and over 16,000 malicious domains impersonating more than 100 crypto brands. It announced a shutdown in November 2023, resurfaced, then sold its code and infrastructure to Angel Drainer in October 2024.

When the legitimate site is the attack

Two incidents show the worst version, where doing everything right is not enough.

In one case, attackers phished a former Ledger employee whose publishing access was still active, then used it to push the Angel Drainer toolkit into a malicious build of Ledger Connect Kit. Across multiple applications, wallets were drained in under two hours, and the victims had visited real sites.

In its High-Tech Crime Trends 2026 report, Group-IB documented a trojanized Trust Wallet build that gave attackers access to wallet data and enabled transactions directly from user accounts. Trust Wallet confirmed 2,520 affected wallets and approximately $8.5 million stolen, traced to 17 attacker-controlled addresses.

Bookmarking the right URL protects against most drainers. Not these.

Drainer losses in 2025: down 83%

Metric20242025Change
Total drained$494 million$83.85 millionDown 83%
Wallets affectedMore than 332,000106,106Down 68%
Largest single loss$55.4 million$6.5 millionDown 88%

Because losses fell faster than victim counts, the average theft got smaller as well as rarer. Better wallet warnings, several major drainer operations exiting, quieter market conditions, and attackers shifting tactics all likely contributed. The data does not separate how much each factor mattered.

One caution when reading these figures. They cover observed activity on Ethereum-compatible chains, not a complete total across every blockchain.

How to avoid a wallet drainer

  • Read what you are signing. Modern wallets describe the action in plain language. If a site you expected to log into is requesting permission to spend tokens, stop.
  • Treat signature requests as spending approvals, because that is frequently what they are, even when labeled "verify" or "claim."
  • Reach sites through bookmarks or typed addresses. Never through a link in a message, email, or social media reply.
  • Use a separate wallet for new or untested sites, holding only what you can afford to lose.
  • Revoke old token approvals periodically with a revocation tool.
  • Be suspicious of urgency. Countdown timers and expiring claims exist to stop you reading.
  • Keep long-term holdings on a hardware wallet that never connects to unfamiliar sites.

What to do if you signed a drainer transaction

Speed decides the outcome. Minutes matter.

Using a revocation tool, revoke the approval immediately, then move any remaining assets to a fresh wallet the compromised one cannot reach. Where a seed phrase was exposed rather than a signature, move everything at once, because the attacker can generate every address that wallet ever had.

Report it to the platform involved and to law enforcement. Rare as recovery is, documentation still matters.

Security you can verify on mb.io

By turning your own signature against you, drainers exploit a risk that exists on-chain rather than inside a regulated exchange account.

mb.io is a regulated crypto spot exchange backed by MultiBank Group, a financial institution founded in 2005 that serves more than 2 million clients across 100+ countries.

  • Institutional-grade MPC custody powered by Fireblocks, with segregated client funds
  • 10/10 security score from Hacken, an independent blockchain security auditor
  • Regulated by VARA in the UAE and AUSTRAC in Australia
  • Withdrawal controls that let you verify a destination before funds move
  • Buy, sell, and swap in three steps, from sign-up to purchase
  • 24/7 multilingual client support

Open your account and start trading on mb.io.

Frequently asked questions

What is a wallet drainer?

A ready-made toolkit that steals crypto by getting you to sign a transaction granting an attacker's contract permission to move your tokens. In that signature lies the theft mechanism.

How much do wallet drainers steal?

According to Scam Sniffer, $83.85 million was taken across 106,106 wallets in 2025, down 83% from $494 million and more than 332,000 wallets in 2024.

How is a drainer different from ordinary phishing?

Where ordinary phishing asks for a secret such as a password or seed phrase, a drainer asks for a signature on what looks like a routine transaction. Hence why people who know never to share a seed phrase still get drained.

What is drainer-as-a-service?

Kits sold or rented on Telegram and dark web forums on a revenue-share basis. While operators maintain the software, affiliates run the phishing campaigns, and the two split whatever is stolen.

What was Inferno Drainer?

One of the largest drainer operations, linked to more than $80 million in theft and over 16,000 domains impersonating more than 100 crypto brands. After announcing a shutdown in November 2023, it later sold its code to Angel Drainer.

Can a drainer steal from a hardware wallet?

Yes, if you approve the malicious transaction on the device. Against malware, a hardware wallet protects the key. Against your own authorization of a transfer, it does nothing.

What should I do if I signed a malicious transaction?

Using a revocation tool, revoke the approval immediately, then move remaining assets to a new wallet. Where a seed phrase was exposed rather than a signature, move everything at once.

Why did drainer losses fall so sharply in 2025?

Better wallet warnings, several major operations exiting, quieter market conditions, and attackers shifting tactics all contributed. How much each factor mattered, the available data does not quantify.

RELATED POSTS

常見問題

常見問題

My Account
What is mb.io?mb.io is a secure, regulated crypto exchange designed to make cryptocurrency trading simple, fast, and stress-free. Whether you're buying your first Bitcoin or managing a diversified portfolio, mb.io gives you the tools you need without the complexity.Built on institutional-grade security and backed by MultiBank Group, mb.io offers spot trading with competitive fees, MPC-powered custody, and a clean interface that adapts to your experience level. Trade with confidence knowing your assets are protected by the same security standards trusted by major financial institutions.How long does account verification take?Most verifications are completed within a few minutes.Once you submit your documents, our system reviews them automatically. If everything looks good, you'll be verified and ready to trade almost immediately.In some cases, we may need to review your documents manually. This can add a bit of time, but it's usually still done the same day.Why is my account verification pending?If your verification is taking longer than expected, here are a few common reasons: Document quality issues: Blurry photos, missing corners, or glare can slow things down.Mismatched information: The details on your documents need to match what you entered during signup.High volume: During busy periods, manual reviews can take a bit longer. If your verification has been pending for more than an hour, contact our support team. They'll check what's happening and help you get verified quickly. They're available 24/7 via live chat or email.
Adding Funds
Withdrawing funds
Features
Regulations
Client Support
Account Security
Deposits & Withdrawals
查看更多

還需要其他幫助?