CRYPTALUME
All articles

What is a crypto wallet drainer and how does it steal tokens?

How malicious signatures, token approvals, and Permit requests enable wallet theft—and what to check immediately after an attack.

August 17, 2026 · 8 min read

A drainer does not hack the blockchain

A wallet drainer is a malicious flow that persuades a wallet owner to authorize a dangerous signature or permission. It may hide behind a token claim, account check, game connection, or a cloned project website.

Transfers and approvals are different

A transfer moves an asset immediately. An approval lets a contract spend a token later. Permit signatures can create that authority without a separate approval transaction, so the theft may happen after the victim has left the phishing site.

What to do after a suspicious signature

Revoke dangerous permissions through a trusted tool for the relevant network when possible. Never enter a seed phrase into a revocation website. Preserve addresses and transactions, move remaining assets to a fresh wallet, and inspect the route of funds already transferred.

When Incident Scan helps

Use a scan when an unknown outgoing transaction appears, tokens move after a site connection, or you need to understand where they went. No wallet connection is required—only a public address or transaction hash.