Most people picture crypto theft as someone guessing a password. Wallet drainers work the other way round: they never see your recovery phrase, and they do not need to. They get you to approve a contract, and an approval is a standing permission. The theft can happen minutes later, or three weeks later, from a page you closed and forgot about.

How a wallet drainer actually works

Token standards on Ethereum and most EVM chains separate ownership from permission to spend. When an application needs to move your tokens, you grant it an allowance. That design is what makes decentralised exchanges possible, and it is what a drainer abuses.

  1. You land on a page that looks like a mint, an airdrop claim, a token migration or a support tool.
  2. It asks you to connect your wallet. Connecting alone is harmless: it reveals your address, nothing more.
  3. It then asks you to sign. The prompt is framed as "claim", "verify", "enable trading" or "sync".
  4. What you actually sign is an approval, often for an unlimited amount, or a setApprovalForAll for a whole NFT collection.
  5. The contract now has permission. It drains the tokens at a time of its choosing, sometimes automatically, sometimes long after you have left.
Token approval
A permission you grant a smart contract to spend a specific token from your wallet, up to a limit you set. Many interfaces default that limit to unlimited, and the permission does not expire on its own.

What TrustSniffer sees in its own data

TrustSniffer maintains a verdict page for every address it can state a fact about. As of today that includes 5,517 Ethereum addresses reported as scam wallets or drainer recipients, alongside 3,102 Ethereum and 6,667 TRON addresses frozen by a stablecoin issuer, and 1,099 addresses named on sanctions programmes.

Two patterns are worth naming, because both change what you should do about them.

Drainer proceeds move fast, and they move to stablecoins. An issuer freeze is the clearest evidence of that: Tether and Circle can freeze a balance on their own contracts, and they do it when funds are traced to theft. A frozen address is not an accusation we make, it is an on-chain fact anyone can verify, which is why we publish those lists rather than a private score.

A reported address keeps receiving. Addresses stay active long after they are first reported, which is exactly why checking one before you interact is worth the thirty seconds it takes.

How to tell a drainer page from a real one

The site hosting the drainer is usually the weakest link, because it has to be new. A contract can be reused; a domain that has been reported gets blocked. That asymmetry is what makes the website worth checking.

  • Registered days or weeks ago. A protocol that claims years of history on a domain registered last month is describing two different things.
  • The urgency is doing the work. A deadline, a countdown, a "limited allocation" that exists to stop you reading the prompt.
  • The signature request does not match the action. "Claim your airdrop" should not require setApprovalForAll on a collection you already own.
  • It arrived in a reply, a DM or a search ad. Almost no legitimate protocol launches through an unsolicited message.
  • No verifiable operator. No company, no jurisdiction, no way to contact anyone who is accountable.

What to do if you have already signed

  1. Move remaining assets to a wallet that has never touched the site. Do this first; revoking takes time you may not have.
  2. Revoke the approval from the compromised address. The permission survives until it is explicitly removed.
  3. Check where the funds went. Paste the receiving address into the wallet checker to see whether it is already known to us.
  4. Do not engage recovery services. An unsolicited offer to recover stolen crypto for an upfront fee is a second scam aimed at the same victim.
  5. Assume the seed phrase is safe unless you typed it somewhere. A drainer approval does not expose it.

Check before you sign

Two checks cover most of this. Run the domain through the website checker to see its age, hosting, identity signals and reputation. Run the receiving or contract address through the wallet checker to see whether it already carries a fact worth knowing. Both publish a permanent verdict page, and every assessment TrustSniffer has published is browsable in the risk directory with aggregate figures on the Risk Index.

Frequently asked questions

Does a wallet drainer steal my seed phrase?

No. It relies on a token approval you sign in your wallet. Your recovery phrase is not exposed unless you typed it into a website, which no legitimate application will ever ask you to do.

Why did the theft happen days after I signed?

An approval is a standing permission with no expiry. The contract can spend at any time after you grant it, and waiting makes the connection to the original site harder for the victim to see.

Can I get drained just by connecting my wallet?

No. Connecting reveals your address and nothing else. The risk begins at the signature prompt, which is why reading what you are signing matters more than whether you connected.

Does revoking an approval return my tokens?

No. Revoking stops future spending from that permission. It does not reverse transfers that already happened, which is why moving remaining assets comes first.

How does TrustSniffer know an address is a scam wallet?

Each listing states its own source and date on the address’s verdict page: a community scam report, a stablecoin issuer freeze recorded on-chain, or a sanctions listing. We publish the fact and its provenance rather than an opinion.

Related reading: what a rug pull looks like from the outside, and the freeze reports TrustSniffer publishes when an issuer acts on an address.