Wednesday, October 7, 2026
Learn / Scams and safety

Crypto phishing and wallet drainers

Crypto phishing tricks people into giving up a seed phrase or approving a harmful transaction. A wallet drainer is the code that then empties the wallet.

Scams and safety Illustration: Cryptoweek

Crypto phishing is fraud by imitation. A scammer poses as a trusted exchange, wallet or app to get one of two things: the secret words that control a wallet, or the owner's approval of a transaction that hands over the funds. A wallet drainer is the software that does the second job.

How does crypto phishing work?

The bait arrives as an email, a text, a social media reply, a search ad or a direct message. It may warn of a security problem, announce a free token giveaway known as an airdrop, or offer help from "support staff." The link leads to a site that looks almost identical to the real one.

From there the scam takes one of two paths. On the first, the site asks the visitor to enter their seed phrase, the 12 or 24 words that back up a wallet. Anyone who has those words controls the wallet completely. On the second, the site asks the visitor to connect their wallet and approve a request.

What is a wallet drainer?

A drainer is a script built into a fake site. It presents an approval request dressed up as something harmless, such as "claim," "verify" or "sign in."

The trick relies on a normal feature. Apps on networks such as Ethereum need permission before they can move a user's tokens, and users grant it by signing an approval. A drainer asks for the same kind of permission, often with no spending limit. Once it is signed, the attacker can move those tokens out without any further prompt.

What is address poisoning?

This scam targets habit. An attacker sends a tiny or zero-value transaction from an address that starts and ends with the same characters as one the victim has used before. It then sits in the victim's history.

Later, the victim copies what looks like a familiar wallet address from that history and sends real funds to the attacker.

How can a request be checked before signing?

Security researchers and wallet makers point to the same habits:

  • Treat the seed phrase as off limits. No genuine exchange, wallet maker or support agent asks for it. A request for it is a scam every time.
  • Check the web address. Reaching a site from a saved bookmark is safer than following a link from an ad, email or message.
  • Read the prompt. The wallet shows which site is asking and what it wants. An approval to spend tokens is not needed just to view a page or prove ownership.
  • Check the whole address. Matching first and last characters is not enough.
  • Review old approvals. Permissions granted to apps stay active until they are revoked.

A hardware wallet keeps keys offline and shows transaction details on its own screen. It cannot protect an owner who approves a malicious request.

This guide explains how things work. It is not financial, legal or tax advice. Last updated .