What is a wallet drainer and how does it steal crypto?
A wallet drainer is a scam tool that tricks you into signing away crypto from your wallet. US victims can report the theft to the FTC and the FBI's IC3.

On this page
- Drainers spread through phishing sites, fake mints, malicious ads and fake support messages.
- They use token approvals and signatures, not seed phrases, to move assets.
- Revoking stops future drains only before assets move.
A drainer often looks like a normal request from an app you connect to.
How do drainers reach victims?
Drainers spread through channels that look routine in crypto.
- Phishing websites that copy a real app's login page.
- Fake mint pages that ask you to approve a free token.
- Malicious ads and fake support messages.
How do wallet drainers work?
A drainer does not need your seed phrase. It waits for a signature from you, then moves assets with that permission.
Can you revoke a malicious approval?
You can revoke token approvals, and that stops future transfers from that approval. Revoking works only before assets move; after that, the transaction is final.
How is a drainer different from malware?
A drainer is not a seed-phrase stealer. It is not a clipboard hijacker that swaps a copied address. It is not an exchange account takeover. It targets a wallet you connect and approve.
What should US victims do?
If a drainer takes your crypto, you can limit further loss and keep records.
Frequently asked questions
A hardware wallet keeps keys offline, so a drainer cannot take your seed phrase. A malicious approval you sign can still move the assets it covers.
A drainer kit is ready-made code scammers use to build phishing pages. Drainer-as-a-service is when a provider runs that kit for a cut.
No. Revoking stops future transfers from that approval. Once assets move, the transaction is final and revoking does not bring them back.
A token approval usually stays active until you revoke it or the contract changes. It has no standard expiration.






