On this page
Key takeaways
- Wallet drainers rarely need your seed phrase; they trick you into signing a token approval or permit that lets them move your tokens later.
- Permit-style signatures can look like a harmless login message yet grant spending rights, so read every wallet prompt and reject anything you do not understand.
- Review and revoke old approvals regularly with tools such as Revoke.cash or a block explorer's approval checker, and keep long-term funds in a separate wallet.
Most modern crypto phishing does not steal your seed phrase. Instead, a fake website asks your wallet to sign a permission, and that permission lets a wallet drainer move your tokens. Learning to read those prompts, and to revoke old permissions, closes the door.
How wallet drainers work
A wallet drainer is a ready-made phishing kit that criminals rent out. The attacker builds a convincing copy of a real app, airdrop claim or NFT mint, then promotes it through hacked social accounts, fake ads, Discord and Telegram links, or search results.
When you click “connect wallet,” the site checks what tokens you hold and requests the signature most likely to empty your wallet. Researchers at Scam Sniffer tracked $83.85 million in signature-phishing losses across roughly 106,000 victims on Ethereum-compatible networks in 2025, down from $494 million in 2024. The report stresses that the threat persists and that harder-to-track attacks may be filling the gap.
Malicious approvals and permit signatures
Token approvals
On Ethereum and similar networks, a token approval lets a smart contract spend a set amount of a specific token from your wallet. Legitimate apps use approvals so you can trade or lend. Many request an “unlimited” amount for convenience, and those approvals stay active until you revoke them.
A drainer asks you to approve its contract, often disguised as a “claim,” “verify” or “mint” button. Once approved, it can transfer your tokens whenever it likes.
Permit signatures
The EIP-2612 permit standard lets you grant an approval by signing a message instead of sending a transaction. That saves gas, but it also means a signature that costs nothing and looks like text can authorize spending. Permit2, a widely used approval system, works on a similar idea.
Scam Sniffer found that Permit and Permit2 signatures accounted for 38% of losses in large drainer cases in 2025. It also reported attackers abusing EIP-7702, a 2025 Ethereum upgrade feature, to bundle several malicious actions into one signature.
How to read wallet prompts
- Know which action you expect. Logging in should be a plain message with no token amounts. Swapping should show the token you are swapping.
- Look for the words approve, permit, spender, setApprovalForAll or increaseAllowance. These grant spending rights.
- Check the site address letter by letter and use bookmarks for apps you use often.
- Turn on your wallet's transaction simulation or warnings if it offers them, but remember simulations can be fooled.
- Use a hardware wallet so every signature needs a physical confirmation, and read what its screen shows.
- Separate your funds. Use a low-balance “hot” wallet for new apps and keep savings in a wallet that never connects to unfamiliar sites.
How to check and revoke approvals
- Open a reputable approval checker such as Revoke.cash or your network's block explorer approval tool. Type the address yourself rather than following a link.
- Enter your wallet address, or connect your wallet, and select the network.
- Review each approval: the token, the spender, and the allowance amount. Unknown spenders and unlimited allowances deserve the most attention.
- Click revoke and confirm in your wallet. Revoking is an on-chain transaction, so it costs a small network fee.
- Repeat on every network you use.
MetaMask and other wallets also offer built-in ways to review allowances. Make this a monthly habit, not just an emergency step.
If you were drained
- Revoke any approvals you can still find, then move remaining assets to a fresh wallet.
- If you entered your seed phrase anywhere, abandon that wallet entirely.
- Save the phishing link, the transaction hashes and the attacker addresses.
- Report at ic3.gov, add the address to Chainabuse, and ignore anyone offering paid recovery. See our recovery scams guide.
Learn more about how apps use approvals in what is DeFi, or return to the security and scams hub.
Frequently asked questions
What is a wallet drainer?
A wallet drainer is a phishing kit that scammers rent or buy. It runs on a fake website and asks your wallet to sign approvals or permits that let the attacker transfer your tokens.
Does revoking an approval get my stolen tokens back?
No. Revoking stops future transfers under that approval, but tokens already taken are gone. It is still important to revoke quickly to protect what remains.
Is signing a message free and safe?
Signing costs no gas, but it is not automatically safe. A typed-data signature such as a permit can authorize spending of your tokens without any on-chain transaction from you.
What if I typed my seed phrase into a phishing site?
Revoking will not help. Create a new wallet with a new seed phrase on a clean device and move everything that remains as quickly as possible.
Sources
- Scam Sniffer 2025: Crypto Phishing Losses Fall 83% to $84 Million — Scam Sniffer
- EIP-2612: Permit extension for EIP-20 signed approvals — Ethereum Improvement Proposals
- How to Revoke Token Approvals and Permissions — Revoke.cash
- How to revoke smart contract allowances/token approvals — MetaMask
- 2026 Crypto Crime Report: Scams — Chainalysis
Updated October 4, 2026 by The Crypto Guide editorial team. Educational content, not financial, legal or tax advice. Spot an error? Request a correction.