Wallet drainer: how one signature can empty your wallet
A drainer often doesn't hack the seed phrase but obtains permission to withdraw tokens through a user's signature.
At first, nothing looks critical. A drainer often doesn't hack the seed phrase but obtains permission to withdraw tokens through a user's signature. The problem becomes obvious only after the signature, transfer, or attempted withdrawal.
The main thing to know right away: The key is not to panic and not to try to "fix" the situation with random transfers. First, stop the repeated risk, save the original data, and only then figure out what happened.
How the scheme works
A drainer often works through token approvals rather than stealing the seed phrase. The user connects their wallet to a phishing site and signs an approve, permit, or other operation, after which the contract or specified spender gains the ability to withdraw assets within the granted permissions.
In this situation, it's important to separate two things: the attack mechanism itself and what has already happened to the assets. A drainer often doesn't hack the seed phrase but obtains permission to withdraw tokens through a user's signature. After an incident, the technical review begins not with guesses but with a specific operation and its continuation on the blockchain.
What to do if it has already happened
Check your approvals history and revoke those you don't recognize. If there are signs of seed or device compromise, a revoke alone is not enough — it's better to move assets to a new wallet from a clean device.
- Stop repeating the action that led to the incident: don't sign new requests and don't send additional payments.
- Save the tx hash, full addresses, network, asset, amount, and time of the operation.
- Record the correspondence, domain, profile, app, or signature screen — everything that explains the context of the operation.
- If there's a risk of wallet compromise, move remaining assets to a new safe wallet without using the exposed seed phrase.
- If the amount is significant, it makes sense to trace the further route of funds and identify service points along the way.
What to save for the review
For this specific topic, it's especially useful to save: the spender/contract address and the transaction or signature that granted the permission.
For an initial review, prepare the data in one message or file — this reduces the risk of losing an important detail:
- tx hash / txid
- full sender and recipient addresses
- network, asset, amount, and time
- screenshots and correspondence
- domain, profile, or app if they are related to the incident
What you should not do
- Do not share your seed phrase and private keys with "helpers" or a "recovery service".
- Do not pay an unknown intermediary a "tax", "insurance", or "unlock fee".
- Do not delete correspondence and transaction history before everything is saved.
Important: the transaction and address are verifiable on-chain facts. The owner's identity, motive, and legal status should not be automatically inferred from a single graph.
When it makes sense to involve a specialist
If the amount is significant, the route has already branched, or exchanges, swap services, bridges, and other services have appeared on it, a manual review helps separate available actions from useless ones. To start, public data is usually enough — private keys are not needed.
Frequently asked questions
If the seed phrase was not entered, why could tokens disappear?
Because permission to withdraw tokens can be granted by a signature. The keys remain with the owner, but the approved contract gets the right to move certain assets.
Can a confirmed transaction be canceled?
As a rule, no. Further actions depend on the route of the funds and whether services have appeared on it that can restrict the movement of assets.
Can you immediately identify a scammer by address?
No. The blockchain shows addresses and operations. Identity requires additional data: KYC from a service, public sources, case materials, or other confirmations.
In short
A drainer often doesn't hack the seed phrase but obtains permission to withdraw tokens through a user's signature. If this has already happened, first stop the repeated risk and save the original data. Then you can analyze the route and real points for further actions.
Need to understand what happened and where the funds went?
Provide the tx hash, network, and a brief description of the situation. Seed phrase and private keys are not needed for an initial assessment.
Submit data for assessment