| Key Takeaways |
|
|
|
|
What Is a Crypto Wallet Drainer?
Crypto drainers are phishing tools in the Web3 space that impersonate legitimate crypto businesses to trick users into authorizing fraudulent transactions. Typically, this happens when users click malicious links embedded in phishing scams that look like legitimate advertisements. After a victim approves the transaction, operators can withdraw the funds from the wallet.
Phishing scammers deliver these drainers through several methods, including:
- Malicious ads and fake airdrops or giveaways
- Phishing on Discord, Telegram, and X (formerly Twitter), including spam comments and mentions
- Email phishing and supply chain attacks
- Redirection through DNS attacks and SIM swaps
The disruption is only rising—
Crypto drainers went from their first large-scale campaign in August 2022 to an organized criminal market by early 2025. Over that span, wallet-draining scaled from isolated scams into an industrial Drainer-as-a-Service (DaaS) operation, a model where affiliates rent ready-made draining kits from operators for a share of the stolen funds.
Crypto drainers now run across tens of thousands of phishing sites.
- The first well-known drainer, Monkey Drainer, ran from August 2022 to February 2023 and stole roughly $13 million, an early sign of how lucrative the tactic could be.
- A 2025 study presented at the ACM Internet Measurement Conference found that Drainer-as-a-Service phishing drained about $135 million from 76,582 victim wallets on Ethereum between March 2023 and April 2025, at times exceeding 100 victims a day.
- The wider crypto-fraud picture grew alongside it. The FBI’s Internet Crime Complaint Center reported $5.6 billion in crypto-related fraud losses for 2023, up 45% from the prior year.
- The DaaS model fueled the scale, with the same study identifying 56 operators supplying more than 6,000 affiliates to run the attacks.
The Impact of Crypto Drainers
Crypto drainers cause direct, often irreversible financial loss, and the damage extends beyond the individuals who lose funds. Victims rarely recover stolen assets, and most losses go unreported, so recorded totals understate the real harm.
The impact falls on two groups: everyday crypto users and the organizations pulled into the attack chain.
Financial impact on individual users
For individual users, the loss is immediate and hard to reverse. Once a victim signs a malicious approval, the drainer moves the assets, and an on-chain transfer cannot be undone.
Most victims lose modest amounts on their own, yet those sums aggregate across tens of thousands of wallets. Many victims never report the theft because each individual loss is small, which keeps recorded totals below the true cost.
| Metric | Figure |
| Total stolen from victims | ~$135 million |
| Kept by affiliates | $111.9 million |
| Taken by operators | $23.1 million |
| Total victim accounts affected | 76,582 |
| Percentage of victim accounts with losses below $1,000 | 83.5% |
| Accounts phished more than once | 8,856 |
Impact on organizations and impersonated brands
Crypto drainers hurt organizations in two ways: financially and reputationally. The financial hit is direct when attackers compromise the infrastructure an organization’s users depend on.
In December 2025, a malicious version of the Trust Wallet Chrome extension reached the Chrome Web Store outside the vendor’s standard release process. Group-IB’s High-Tech Crime Trends 2026 report found that the trojanized build gave attackers access to wallet data and enabled unauthorized transactions directly from user accounts. Trust Wallet confirmed 2,520 affected wallets and approximately $8.5 million in stolen assets, traced to 17 attacker-controlled addresses.
The pattern was established two years earlier, when attackers phished a former Ledger employee whose publishing access remained active and used it to push the Angel Drainer toolkit into malicious builds of Ledger Connect Kit, draining wallets across multiple dApps in under two hours.
Organizations also suffer reputational damage from impersonation and hijacked accounts. Drainers spoof legitimate crypto brands to make phishing pages look trustworthy. Group-IB’s investigation into Inferno Drainer found more than 16,000 domains impersonating over 100 crypto brands, each trading on a real company’s reputation.
How Do Crypto Wallet Drainers Work?
Crypto drainers work in two stages. A phishing stage lures the victim to a fake site, and a draining stage empties the wallet once the victim approves a malicious transaction.
Phishing or impersonation phase
Attackers build a fraudulent site that impersonates a legitimate wallet, exchange, or Web3 project, often with a valid SSL certificate and familiar branding. They promote it through phishing ads, fake airdrops, and compromised social accounts to draw victims in.
The aim is to get the victim to connect their wallet and approve a request, believing the site is legitimate. Some sites go further and ask for the seed phrase directly, which hands over the entire wallet.
Wallet drainer phase
Once the victim approves the request, the drainer takes over. The transaction they signed grants the drainer’s contract permission to move their tokens or to transfer the assets outright.
The drainer scans the wallet for valuable tokens and NFTs and sends them to attacker-controlled addresses, often automatically and within seconds. If the victim entered a seed phrase instead, the attacker can regenerate every address in the wallet and drain them all.
Attackers frequently move the proceeds through fresh wallets to make the funds harder to trace.
Types of Crypto Wallet Drainers
Crypto drainers take several forms, from ready-made phishing kits to malicious apps and browser extensions. Each reaches victims through a different vehicle, but the goal is the same: a signed transaction that grants the attacker wallet access.
The main types often overlap in a single campaign.
Wallet drainer phishing kits
Wallet drainer phishing kits are prepackaged toolkits that let an attacker stand up a convincing fake site and drain any wallet that connects to it. They ship ready to deploy, so an affiliate with little technical skill can launch a campaign quickly.
The 2025 ACM study identified 32,819 phishing sites built with these kits, most of which were tied to the Drainer-as-a-Service families that rent them out.
Malicious decentralized applications (dApps)
Malicious decentralized applications, or dApps, are blockchain apps built to look legitimate but designed to drain any wallet that connects to it. A dApp typically asks to connect to a user’s wallet to function, and a fake one abuses that prompt to request malicious approval instead.
Legitimate dApps can turn dangerous too if their code is compromised, as happened when the Angel Drainer toolkit was slipped into Ledger’s Connect Kit library.
Fake browser extensions
Fake browser extensions pose as crypto tools, offering portfolio tracking or added security while quietly stealing wallet credentials in the background.
A user installs the extension for a legitimate-sounding feature and later notices unauthorized transactions. Extensions run with broad access to browser activity, so they can capture private keys or alter transactions as the user signs them.
Social engineering campaigns
Social engineering campaigns rely on manipulation rather than a technical flaw, pressuring victims to connect a wallet or approve a transaction themselves. Fake airdrops and giveaways are the most common hook, promising free tokens in return for a wallet connection.
Others impersonate support staff or project teams and use urgency, warning of a security problem the victim must fix by signing right away.
Smart contract drainers
Smart contract drainers hide malicious behavior inside the contract a victim interacts with. A smart contract is self-executing code on the blockchain, and its approval function can grant another account permission to move a user’s tokens.
Drainers abuse that function, so a single approval a victim signs can let the attacker transfer tokens at will. The FBI advises users to check token allowances periodically and revoke any they do not recognize.
Real-World Examples of Crypto Drainer Attacks
Two Group-IB investigations show how crypto drainers work in practice and how they have evolved. Inferno Drainer built a large scam-as-a-service platform around fake crypto brands, and the subsequent Declaration trap campaign shows the same tooling shifting to impersonate government tax authorities.
Inferno Drainer
Inferno Drainer was one of the largest crypto drainers to run as a scam-as-a-service platform, and Group-IB’s High-Tech Crime Investigation unit helped expose it. Before it announced a shutdown, the operation stole an estimated $80 million from victims across the Web3 ecosystem.
- Operational period. Inferno ran as a scam-as-a-service operation from November 2022 to November 2023.
- Scale. Group-IB identified more than 16,000 unique domains linked to Inferno that impersonate at least 100 crypto brands.
- Method. The drainer ran scripts that spoofed popular Web3 protocols, tricking users into signing fraudulent transactions.
- Revenue split. Inferno’s operators took 20% of stolen assets, and the affiliates who ran the campaigns kept the remaining 80%.
- Aftermath. Inferno announced its shutdown in November 2023, but its code lived on. Group-IB found its user panel active until January 2024, and an updated Inferno wallet-connect script later resurfaced in the 2025 Declaration trap campaigns.
Crypto drainers posing as European tax authorities
In June 2025, Group-IB documented a campaign it called the Declaration trap, in which drainers moved off crypto-brand lures and instead impersonated government tax authorities.
The operators posed as the Dutch tax authority (Belastingdienst) and the national government portal (MijnOverheid), emailing victims about an urgent crypto tax declaration and sending them to spoofed government sites that harvested personal data, IBAN details, and wallet information. The campaign started in the Netherlands and expanded to other countries.
The sites drained wallets in two ways. Some asked victims to enter their seed phrase, which went straight to an attacker-controlled Telegram bot. Others used an updated wallet-connect script tied to Inferno Drainer to trick users of smart-contract wallets such as Safe, Argent, and Ambire into signing malicious transactions through a QR code. That reused script shows a drainer can outlive its own shutdown, with its code resurfacing in new campaigns more than a year later.
How to Respond to a Crypto Drainer Attack
A crypto drainer keeps access to your wallet until you cut it off, so responding quickly limits the damage. The priority is to stop further transfers, move what remains, investigate the scope, and report the theft.
1. Revoke malicious token approvals
Revoke any token approvals you do not recognize. A drainer usually relies on an approval you signed that lets its contract move your tokens, and that permission stays active until you cancel it. Use a token-approval checker, such as the tool built into block explorers like Etherscan, to review what each address can spend, then revoke the suspicious ones.
Revoking works when the drainer depends on an approval. If you entered your seed phrase or private key on a fake site, the wallet itself is compromised, and no revocation will secure it, so move to the next step right away.
2. Transfer remaining assets to a secure wallet
Move any remaining assets to a wallet the attacker cannot reach. Create a new wallet on a device you trust, ideally a hardware wallet, and transfer your funds and valuable NFTs there.
Do this from a clean device if you suspect malware on the original one. Never reuse the seed phrase from the compromised wallet.
3. Identify compromised wallets and transactions
Map exactly what the attacker touched. Open a block explorer such as Etherscan and review your transaction history to find the malicious approval, the drainer’s address, and every asset that moved. Note the transaction hashes, dates, and receiving addresses. This record shows which wallets are compromised and gives investigators something to trace.
4. Report the incident
Report the theft to the authorities, even if recovery seems unlikely. In the US, file a complaint with the FBI’s Internet Crime Complaint Center (IC3) at ic3.gov and the Federal Trade Commission (FTC) at reportfraud.ftc.gov, and include the transaction hashes and addresses you gathered.
Recovery is sometimes possible, since stolen tokens can occasionally be frozen by the issuer, as Tether did after the Ledger compromise.
5. Strengthen wallet security
Harden your setup before using crypto again. Store long-term holdings in a hardware wallet and keep only what you need in a hot wallet for daily use.
Verify every site and wallet connection request before approving, and review your token approvals on a regular schedule. Treat unsolicited airdrops, giveaways, and urgent security warnings as likely scams.
How to Protect Against Crypto Wallet Drainers?
You can avoid most crypto drainers by controlling what you connect to and what you approve. Drainers rely on a victim visiting a fake site and signing a malicious transaction, so verifying sites and limiting wallet permissions close their main entry point.
Verify a site before connecting
- Check the domain’s registration date with a lookup like whois.com, since newly created sites are a common red flag.
- Cross-check the token on a major aggregator like CoinMarketCap and confirm the project through its official website and social channels, not a link in a message or ad.
- Treat airdrops, giveaways, and “free token” offers as likely bait, since they are the most common drainer lure.
Control what you sign and approve
- Never share your seed phrase or private keys, because no legitimate service needs them
- Grant only the permissions a task requires, and reject broad token-spending approvals
- Preview what a transaction will do before you sign, then review and revoke old token approvals regularly
Stop Drainer Infrastructure Before It Reaches Users and Endpoints
Drainer operations have evolved to increasingly mimic trusted brands, and this tactic is expanding beyond just crypto companies. These phishing lures have changed. Rather than simply promising airdrops, they can take the form of compliance deadline notifications, capitalizing on users’ fears of regulatory issues.
Some campaigns blend phishing tactics with malware, creating a dual threat in which malicious software remains active on the host device. Unfortunately, user caution alone isn’t sufficient to combat this growing threat. To address these risks, impersonated organizations must dismantle the infrastructure being exploited, and security teams need to intercept these threats before they reach end-user devices.
- Digital Risk Protection detects brand impersonation, phishing domains, and fake apps in real time, then removes them through a three-stage takedown process.
- Threat Intelligence monitors the dark web and fraudster forums to surface Drainer-as-a-Service operators and phishing kits before they target your brand.
- Fraud Protection identifies fake accounts and blocks the account takeovers attackers use to broadcast drainer links from trusted profiles.
Talk to Group-IB experts to map the infrastructure of crypto drainers impersonating your brand and prioritize takedown actions.
