A wallet drainer is malicious code that gets you to sign a transaction granting an attacker the ability to move your assets. You don’t hand over your seed phrase. You approve something that looks routine, and the approval is the theft.
How they work
A fake website — a cloned exchange, a fake airdrop claim, a fraudulent mint — presents a transaction to sign. The transaction is an unlimited token approval, a permit signature, or a transfer disguised as something else. Once signed, the attacker’s contract can move your tokens whenever it chooses.
The signature is legitimate. Your wallet did exactly what you told it. That’s why there’s no recourse.
The signatures to never give
Unlimited approvals to contracts you don’t know. Permit or Permit2 signatures on sites you didn’t navigate to yourself. Any signature request that appears before you’ve done anything on the site. Any transaction whose description in your wallet doesn’t match what you expected.
Modern wallets show what a signature grants. Read it. If it says “allow this contract to spend all your USDC,” and you were trying to claim an NFT, close the tab.
Why permission scope matters
The damage from a drainer is bounded by what your signatures can do. A signature that grants trading permission but not withdrawal permission can lose money by trading badly. It can’t empty the wallet.
This is why trade-only agent wallets are the right model for connecting automation. Even a fully compromised agent key can’t drain the account — which is not true of an unlimited token approval.
If you’ve signed something you shouldn’t have
Revoke the approval immediately using your wallet’s approval manager or a revocation tool. Move remaining assets to a fresh wallet. Assume the compromised address is permanently untrusted.