Non-custodial · read-only

What is a wallet drainer?

A wallet drainer is a script that tricks you into signing one transaction or approval that hands your assets to an attacker. Here's how they work: and how to check your exposure read-only.

Scan your wallet: free Watch 24/7 on Telegram

Public address only. No wallet connection. Nothing to sign.

The one-signature trap

A drainer doesn't 'hack' your wallet, it gets you to sign something. A fake mint, airdrop claim, or 'revoke' site presents a transaction that looks routine but actually approves a spender, signs a Permit, or delegates your account. One signature, and the attacker can move your tokens.

Drainer-as-a-service

Most drainers are rented kits (Inferno, Angel, etc.) that split the loot with the operator. They're polished, localized, and seeded through hacked Discords, fake job offers, and lookalike dapp domains, which is why 'it looked official' is the most common victim story.

The signatures that cost you

Three do the damage: an unlimited token approval, an off-chain Permit/Permit2 signature (no gas, no popup you recognize), and, live since the 2025 Pectra upgrade, an EIP-7702 account delegation that points your EOA at attacker code. Veriql's Guardian flags all three before you sign.

Check your exposure: read-only

You can inspect what a wallet has already approved using only its public address; nothing to sign, no connection. If a drainer already got an approval, revoking it closes the door.

FAQ

Can a drainer take funds with just my address?

No: a public address is read-only. A drainer needs a signature or approval from you. That's exactly why checking your approvals is safe and revoking works.

I think I signed something, what now?

Scan your address, revoke any risky approval immediately, and if you may have exposed your seed phrase, move remaining assets to a fresh wallet. See our recovery guide.

Related