A wallet drainer is a ready-made toolkit that steals crypto by tricking you into signing one transaction. In that signature lies the theft. Nothing gets hacked, no password is stolen, and your wallet does exactly what you told it to. According to Scam Sniffer, $83.85 million was drained from 106,106 wallets in 2025, down 83% from $494 million the year before.
Drainers ask for permission, not secrets
Where ordinary phishing asks for a secret, a drainer asks for permission.
From a fake login page comes a request for your password. From a fake wallet site, your seed phrase. Most people have been warned about both, and most refuse.
A drainer asks for none of that. Instead it shows you a normal-looking transaction: claim an airdrop, verify your wallet, mint an NFT, connect to a site. You press confirm because pressing confirm is how crypto works. That single signature hands an attacker's contract permission to move your tokens, and the sweep follows.
Hence why experienced users get drained. They know never to share a seed phrase. Nobody asked them to.
How a wallet drainer works
Four parts. Only the third involves you.
- A malicious page. A fake mint, a cloned exchange, a fraudulent airdrop claim, or a compromised legitimate site.
- A wallet connection. You connect, which by itself steals nothing.
- A signature request, presented as routine. You approve it.
- A spender contract that immediately transfers your tokens to addresses the attacker controls, often splitting them across several to complicate tracing.
Every drainer kit ends at the same place: the moment you press confirm. Every drainer kit also fails if you do not.
Drainer-as-a-service
These are everywhere because running one requires no technical skill at all.
On Telegram and dark web forums, drainer kits are sold and rented on a revenue-share basis. Operators build and maintain the software. Affiliates run the phishing campaigns and drive traffic. Between them the profits split, typically with the kit operator taking a percentage of everything stolen.
Among the named kits runs a lineage that reads like a business sector: Monkey, then Inferno, then Angel, Pink, and Medusa. Inferno Drainer alone was linked to more than $80 million in theft and over 16,000 malicious domains impersonating more than 100 crypto brands. It announced a shutdown in November 2023, resurfaced, then sold its code and infrastructure to Angel Drainer in October 2024.
When the legitimate site is the attack
Two incidents show the worst version, where doing everything right is not enough.
In one case, attackers phished a former Ledger employee whose publishing access was still active, then used it to push the Angel Drainer toolkit into a malicious build of Ledger Connect Kit. Across multiple applications, wallets were drained in under two hours, and the victims had visited real sites.
In its High-Tech Crime Trends 2026 report, Group-IB documented a trojanized Trust Wallet build that gave attackers access to wallet data and enabled transactions directly from user accounts. Trust Wallet confirmed 2,520 affected wallets and approximately $8.5 million stolen, traced to 17 attacker-controlled addresses.
Bookmarking the right URL protects against most drainers. Not these.
Drainer losses in 2025: down 83%
| Metric | 2024 | 2025 | Change |
|---|---|---|---|
| Total drained | $494 million | $83.85 million | Down 83% |
| Wallets affected | More than 332,000 | 106,106 | Down 68% |
| Largest single loss | $55.4 million | $6.5 million | Down 88% |
Because losses fell faster than victim counts, the average theft got smaller as well as rarer. Better wallet warnings, several major drainer operations exiting, quieter market conditions, and attackers shifting tactics all likely contributed. The data does not separate how much each factor mattered.
One caution when reading these figures. They cover observed activity on Ethereum-compatible chains, not a complete total across every blockchain.
How to avoid a wallet drainer
- Read what you are signing. Modern wallets describe the action in plain language. If a site you expected to log into is requesting permission to spend tokens, stop.
- Treat signature requests as spending approvals, because that is frequently what they are, even when labeled "verify" or "claim."
- Reach sites through bookmarks or typed addresses. Never through a link in a message, email, or social media reply.
- Use a separate wallet for new or untested sites, holding only what you can afford to lose.
- Revoke old token approvals periodically with a revocation tool.
- Be suspicious of urgency. Countdown timers and expiring claims exist to stop you reading.
- Keep long-term holdings on a hardware wallet that never connects to unfamiliar sites.
What to do if you signed a drainer transaction
Speed decides the outcome. Minutes matter.
Using a revocation tool, revoke the approval immediately, then move any remaining assets to a fresh wallet the compromised one cannot reach. Where a seed phrase was exposed rather than a signature, move everything at once, because the attacker can generate every address that wallet ever had.
Report it to the platform involved and to law enforcement. Rare as recovery is, documentation still matters.
Security you can verify on mb.io
By turning your own signature against you, drainers exploit a risk that exists on-chain rather than inside a regulated exchange account.
mb.io is a regulated crypto spot exchange backed by MultiBank Group, a financial institution founded in 2005 that serves more than 2 million clients across 100+ countries.
- Institutional-grade MPC custody powered by Fireblocks, with segregated client funds
- 10/10 security score from Hacken, an independent blockchain security auditor
- Regulated by VARA in the UAE and AUSTRAC in Australia
- Withdrawal controls that let you verify a destination before funds move
- Buy, sell, and swap in three steps, from sign-up to purchase
- 24/7 multilingual client support
Open your account and start trading on mb.io.
Frequently asked questions
What is a wallet drainer?
A ready-made toolkit that steals crypto by getting you to sign a transaction granting an attacker's contract permission to move your tokens. In that signature lies the theft mechanism.
How much do wallet drainers steal?
According to Scam Sniffer, $83.85 million was taken across 106,106 wallets in 2025, down 83% from $494 million and more than 332,000 wallets in 2024.
How is a drainer different from ordinary phishing?
Where ordinary phishing asks for a secret such as a password or seed phrase, a drainer asks for a signature on what looks like a routine transaction. Hence why people who know never to share a seed phrase still get drained.
What is drainer-as-a-service?
Kits sold or rented on Telegram and dark web forums on a revenue-share basis. While operators maintain the software, affiliates run the phishing campaigns, and the two split whatever is stolen.
What was Inferno Drainer?
One of the largest drainer operations, linked to more than $80 million in theft and over 16,000 domains impersonating more than 100 crypto brands. After announcing a shutdown in November 2023, it later sold its code to Angel Drainer.
Can a drainer steal from a hardware wallet?
Yes, if you approve the malicious transaction on the device. Against malware, a hardware wallet protects the key. Against your own authorization of a transfer, it does nothing.
What should I do if I signed a malicious transaction?
Using a revocation tool, revoke the approval immediately, then move remaining assets to a new wallet. Where a seed phrase was exposed rather than a signature, move everything at once.
Why did drainer losses fall so sharply in 2025?
Better wallet warnings, several major operations exiting, quieter market conditions, and attackers shifting tactics all contributed. How much each factor mattered, the available data does not quantify.

