§ — Crypto scams · Wallet drainers

A wallet drainer does not steal your keys It gets your permission.

A wallet drainer is malicious code that obtains one signature — an approval, an off-chain permission, or a transaction whose real contents are hidden behind a friendly button — and uses it to move everything it can reach in a single sweep. The wallet was never broken into. It did what a signature told it to do, which is why the theft can look like nothing at all at the moment it happens. This page explains each permission that gets abused, what happens to the money in the minutes afterwards, and where the opening for recovery actually is.
Last updated: 1 August 2026Figures as of: 30 July 2026First response: within 2 business hours
Types of crypto theft4 pages
Type 01
Type 03
Wallet drainers
You are here
§ 01 — What it is

What a drainer is, and who is actually running it.

Most drainers are not written by the person who robbed you. They are rented kits: the author supplies the code and takes a share, and the operator supplies the bait — a fake airdrop claim page, a cloned mint site, a support account in a project's chat, a sponsored search result sitting above the real one. The same kit therefore appears behind campaigns that otherwise have nothing in common, and the wallet that receives your assets is often not the wallet that keeps them.

That structure matters for a case. It means the addresses involved are usually part of a larger pattern rather than a one-off, and it means the proceeds follow a laundering routine that has been used before — which is exactly what makes them traceable.

The uncomfortable part. Nothing was hacked. The signature was valid, the transaction was valid, and the blockchain did what it is supposed to do. That is also why nobody — not us, not a developer, not an exchange — can reverse it. What can be done happens afterwards, to the money, not to the transaction.

§ 02 — Permissions

The four permissions that empty a wallet.

Different chains and wallets word these differently, but the mechanisms come down to four. The middle two are the reason victims so often say they never sent anything.
What you approvedWhat it actually allowsVisible in your wallet history?
Token approval
an on-chain allowance
A named contract may move a token on your behalf, frequently for an unlimited amount and with no expiry. Granted once, usable indefinitelyYes — it is a transaction you paid gas for
Off-chain permission
a gasless signature
The same power to move tokens, granted by signing a message rather than sending a transaction. The attacker submits it later, at a moment of their choosingNo — nothing is recorded until it is used
Collection-wide approval
typical for NFTs
Permission over an entire collection at once, rather than a single item. One signature, everything of that kind in the walletYes, but the wording rarely conveys the scope
Blind signature
an opaque transaction
A request whose contents cannot be displayed in readable form. It may bundle several transfers into one call, so the wallet empties in a single confirmationYes — after the fact

This is also why a drain sometimes happens long after the interaction that caused it. An approval does not expire on its own, and an unused off-chain permission sits with the attacker until they decide it is worth spending gas on.

§ 03 — The bait

How people are brought to the signature.

The signature is the theft; everything before it is stagecraft. The recurring routes, in the cases we see:

Airdrop and claim pages.

A reward is waiting, and claiming it requires connecting and signing. The reward does not exist; the signature does.

Cloned and near-identical domains.

Reached through a paid search result, a link in a chat, or a spelling that differs by one character.

Compromised official channels.

A project's own account posts a mint link because the account itself was taken over. The source looked right, because it was.

Support that comes to you.

A person appears after you post a problem publicly, offers to fix it, and directs you to a wallet-connect page or a QR code.

Fake security tools.

Pages offering to check or revoke your approvals, which ask you to sign in order to do it.

The one rule that holds across all of them. If the flow ends in a signature you cannot read in plain language, stop there. A request that cannot be explained by the site asking for it is not a formality — it is the payload.

§ 04 — The money

What happens in the ten minutes after the drain.

The sweep.

Everything covered by the permission leaves at once, often including assets you had forgotten were in the wallet.

Seconds — usually a single transaction

Conversion.

Anything illiquid or easily blocked is swapped on decentralised exchanges into the assets that move most easily.

Minutes

Dispersal.

The proceeds are split across new addresses and bridged to other networks, which breaks the trail for anyone who is only watching one chain.

Minutes to hours — the window that decides your case

Consolidation.

Sooner or later the pieces are brought back together, because spending them separately is impractical.

This is the point tracing is aiming at

Cash-out.

The value has to become ordinary money, which means a service that screens deposits — and that is where it can still be stopped.

After this, there is nothing left to freeze

We investigate on Ethereum, Bitcoin, Tron, BSC, Polygon and Solana, where each of those steps is permanently visible and can be followed across the bridge that was meant to hide it. We do not work with Monero, because it cannot be traced, and we say so at the first call instead of billing the attempt.

§ 05 — Recovery

Can it be recovered? The honest version.

Drainer cases sit in the middle of the range — harder than a theft from an exchange account, considerably better than a rug pull. Two features work in a victim's favour and one against.

In your favour. The proceeds are ordinary transferable assets that have to be laundered before they are worth anything, and the routine used to launder them is often shared across campaigns run by the same kit. Both facts make the money followable. We flag stolen transactions to AML providers within four hours of intake, so the marker is waiting at the services the funds are heading towards; a freeze request to an exchange takes 2–4 days once filed, and the formal block that follows a police report adds 2–3 days.

Against you. Speed. A drain is executed and dispersed in minutes, while an investigation begins whenever the victim gets in touch. Cases that reach us the same day are a different proposition from cases that reach us a month later, and no amount of skill compensates for funds that were cashed out three weeks ago.

What recovery looks like when it works: the assets are traced through the swaps and bridges, flagged, and stopped where they touch a service with a compliance team and a customer behind the account. Return then follows the ordinary timetable — 6–9 months from an exchange, 6–36 months for complex or multi-jurisdictional cases. A freeze is measured in days; being repaid is not. Full timings are on our data page.

Documented case
$18K frozen of $200K

A cold-wallet theft we handled, documented on our cases page: $200,000 taken, $18,000 frozen on Solana in a cross-chain trace. We publish that case for the same reason we publish the difficult answers here — most of that money was already gone by the time the case reached us, and a page that only shows the recoveries would be telling you about our marketing rather than about your odds.

Our published figure is 68% success rate on accepted cases · measured over the past 24 months. The word accepted carries the weight: we decline cases where we see no realistic prospect of recovery, and drainer cases that arrive weeks late are frequently among them.

§ 06 — What to do now

What to do now, in this order.

Move what is left — before anything else.

Send remaining assets to a wallet created from a new recovery phrase, not to another account inside the same wallet. Approvals you have not found yet may still be live.

Highest-value assets first; you may not have time for all of them

Then revoke the approvals.

Use the token-approval screen of a block explorer for that chain, or your wallet's own approvals view. Revoking is a transaction that costs gas — which is why it comes second, not first.

Revoking stops further losses; it does not return anything

Sign nothing else.

Especially not for anyone who has appeared since the drain offering to help, and never for a page asking you to sign in order to secure the wallet.

The second attempt often arrives within hours of the first

Save the evidence.

The transaction hashes of the drain, your wallet address, the site or app that requested the signature, the exact wording of the request, and the chat where the link came from.

Hashes matter most — they are what we trace

Report it to the police.

The formal block at an exchange rests on a police report, and the court order that returns money rests on the file behind it.

Where and how, by country: our reporting guide

Get the addresses flagged.

Send us the hashes. Flagging happens within four hours of intake, the assessment call is free, and it may end with us telling you not to proceed.

[email protected] · +971 56 182 9077 · reply within 2 business hours
§ 07 — The second scam

The people who will contact you next.

Drained wallets are a public list. Anyone can see which address was emptied and roughly what it was worth, and that list is worked commercially — expect approaches offering recovery, sometimes within hours, sometimes in the same chat where the original link appeared.

The FBI's Internet Crime Complaint Center has issued repeated advisories about fictitious law firms contacting crypto scam victims and offering to recover funds for an up-front fee. Between February 2023 and February 2024 alone, victims re-targeted this way reported losses of more than $9.9 million. Both advisories are public: PSA240624 and PSA250813.

This applies to us too. We do not cold-message victims, we are not affiliated with any government agency, and no agency refers cases to us. If someone approaches you in our name, it is not us — report it to IC3. Before engaging anyone, including us, run the ten-point check on our verification page; our registry entries are published in full on credentials.

§ 08 — Our limits

What we do not do.

Reverse transactions.

Nobody can. What exists is a freeze after the funds reach a service with an operator, and a return after that.

Recover a wallet whose recovery phrase was exposed.

The phrase cannot be un-shared; the wallet is finished and the case becomes about the money, not the wallet.

Monero.

It cannot be traced, so we decline rather than bill the attempt.

Chinese OTC channels.

Outside what we can work effectively.

Cases where the source of the funds cannot be confirmed.

Non-negotiable.

Cases with no realistic prospect of recovery.

Declined on the first call.

Legal practice.

Forensics and the evidence base are ours; police reports, freeze filings and court applications are carried out by partner law firms in the relevant jurisdiction.

Guarantees.

Recovery is decided by courts, exchanges and token issuers.

Related: all six types of crypto theft and their recoverability · fake exchanges and platforms · how a recovery case runs end to end · what happens in the first four hours.

§ 09 — FAQ

Wallet drainers — the questions we are asked.

A wallet drainer is malicious code that persuades you to sign something — an approval, an off-chain permission, or a transaction whose real contents sit behind a friendly button — and then uses that signature to move everything it can reach out of your wallet. Your keys are not stolen and your recovery phrase is usually never seen: the wallet does exactly what a signature you gave told it to do. Most drainers today are rented kits, so the people who wrote the code and the people who built the site that got you to sign are frequently not the same.

§ 10 — Authorship

Who wrote this, and who checked it.

Taras Podhorodetskyi

Founder and CEO, StarCompliance · blockchain investigations since 2022 · speaker, WOW Summit 2024 · interviewed by ForkLog, 23 July 2024

Reviewed by: compliance reviewer — name and role published with the next update of this page.

Disclaimer. This page is informational and is not legal or security advice. It describes how these schemes generally operate; no assessment of any individual case can be made from a general description. Recovery decisions rest with courts, exchanges and token issuers, and no outcome is guaranteed. Company figures are stated as of 30 July 2026.
§ — Engage

Have a case?
Start an intake.

Response within two business hours. Confidential. Success-fee terms on recovery work.