Most people picture crypto theft as someone guessing a password. Wallet drainers work the other way round: they never see your recovery phrase, and they do not need to. They get you to approve a contract, and an approval is a standing permission. The theft can happen minutes later, or three weeks later, from a page you closed and forgot about.
How a wallet drainer actually works
Token standards on Ethereum and most EVM chains separate ownership from permission to spend. When an application needs to move your tokens, you grant it an allowance. That design is what makes decentralised exchanges possible, and it is what a drainer abuses.
- You land on a page that looks like a mint, an airdrop claim, a token migration or a support tool.
- It asks you to connect your wallet. Connecting alone is harmless: it reveals your address, nothing more.
- It then asks you to sign. The prompt is framed as "claim", "verify", "enable trading" or "sync".
- What you actually sign is an approval, often for an unlimited amount, or a
setApprovalForAllfor a whole NFT collection. - The contract now has permission. It drains the tokens at a time of its choosing, sometimes automatically, sometimes long after you have left.
- Token approval
- A permission you grant a smart contract to spend a specific token from your wallet, up to a limit you set. Many interfaces default that limit to unlimited, and the permission does not expire on its own.
What TrustSniffer sees in its own data
TrustSniffer maintains a verdict page for every address it can state a fact about. As of today that includes 5,517 Ethereum addresses reported as scam wallets or drainer recipients, alongside 3,102 Ethereum and 6,667 TRON addresses frozen by a stablecoin issuer, and 1,099 addresses named on sanctions programmes.
Two patterns are worth naming, because both change what you should do about them.
Drainer proceeds move fast, and they move to stablecoins. An issuer freeze is the clearest evidence of that: Tether and Circle can freeze a balance on their own contracts, and they do it when funds are traced to theft. A frozen address is not an accusation we make, it is an on-chain fact anyone can verify, which is why we publish those lists rather than a private score.
A reported address keeps receiving. Addresses stay active long after they are first reported, which is exactly why checking one before you interact is worth the thirty seconds it takes.
- Scam-reported wallets on Ethereum — the drainer recipients themselves
- Frozen USDT and USDC wallets on Ethereum — where proceeds often end up
- Frozen USDT wallets on TRON — the same pattern on the cheaper chain
- Sanctioned wallets on Ethereum — a separate, legal category
How to tell a drainer page from a real one
The site hosting the drainer is usually the weakest link, because it has to be new. A contract can be reused; a domain that has been reported gets blocked. That asymmetry is what makes the website worth checking.
- Registered days or weeks ago. A protocol that claims years of history on a domain registered last month is describing two different things.
- The urgency is doing the work. A deadline, a countdown, a "limited allocation" that exists to stop you reading the prompt.
- The signature request does not match the action. "Claim your airdrop" should not require
setApprovalForAllon a collection you already own. - It arrived in a reply, a DM or a search ad. Almost no legitimate protocol launches through an unsolicited message.
- No verifiable operator. No company, no jurisdiction, no way to contact anyone who is accountable.
What to do if you have already signed
- Move remaining assets to a wallet that has never touched the site. Do this first; revoking takes time you may not have.
- Revoke the approval from the compromised address. The permission survives until it is explicitly removed.
- Check where the funds went. Paste the receiving address into the wallet checker to see whether it is already known to us.
- Do not engage recovery services. An unsolicited offer to recover stolen crypto for an upfront fee is a second scam aimed at the same victim.
- Assume the seed phrase is safe unless you typed it somewhere. A drainer approval does not expose it.
Check before you sign
Two checks cover most of this. Run the domain through the website checker to see its age, hosting, identity signals and reputation. Run the receiving or contract address through the wallet checker to see whether it already carries a fact worth knowing. Both publish a permanent verdict page, and every assessment TrustSniffer has published is browsable in the risk directory with aggregate figures on the Risk Index.
Frequently asked questions
Does a wallet drainer steal my seed phrase?
Why did the theft happen days after I signed?
Can I get drained just by connecting my wallet?
Does revoking an approval return my tokens?
How does TrustSniffer know an address is a scam wallet?
Related reading: what a rug pull looks like from the outside, and the freeze reports TrustSniffer publishes when an issuer acts on an address.



