SardineCon SF/2026

Learn More

¿Qué es Crypto drainer?

SUBSCRIBE

A crypto drainer is malicious code, often sold as a ready-made kit or drainer-as-a-service, that empties a victim's wallet once they connect it to a fake site or sign a malicious transaction or approval. It turns one bad click into a total loss, and the kit authors take a cut of everything stolen.

What is a crypto drainer, in plain English?

A crypto drainer is packaged theft software. Instead of writing an attack from scratch, a scammer buys or rents a drainer kit, plugs it into a fake website, and lets it do the work. When a victim connects their wallet and signs what looks like a routine action, the drainer figures out what is valuable in the wallet and pulls it out, often sweeping the entire balance in one go.

The business model is the notable part. Many drainers are sold as drainer-as-a-service: the authors provide the code, the phishing templates, and the infrastructure, and in return take a percentage of everything their customers steal. That lowers the skill needed to run a wallet-draining scam and lets the same tooling power many campaigns at once.

Drainers ride on phishing spread through fake airdrops, malicious ads, cloned apps, and hijacked social accounts. Under the hood, the theft usually happens through a malicious transfer or an approval the victim signs. The clearest on-chain tell is a sudden full-balance sweep into a fresh consolidation address that gathers loot from many victims.

How a drainer campaign works

  1. Acquire — Buy or rent the kit. A scammer obtains a drainer-as-a-service package with code, templates, and infrastructure.
  2. Lure — Spread the phishing. Fake airdrops, ads, and cloned apps drive victims to a malicious site.
  3. Trigger — Victim connects and signs. A single malicious transaction or approval hands the drainer the access it needs.
  4. Sweep — Wallet emptied, cut taken. The balance is swept to a consolidation address and the kit authors keep their share.

Who is involved?

Who

Their role

The kit authors

Build and rent the drainer, take a cut of every theft, and maintain the infrastructure.

The affiliate scammer

Runs the phishing campaign that lures victims and points them at the drainer.

The victim

Connects a wallet and signs one malicious action, losing the balance instantly.

Wallets and analytics

Detect drains, blocklist known malicious sites and contracts, and warn before risky signatures.

What it looks like in practice

In practice

A user clicks an ad promoting a token airdrop from a project they follow. The site looks right, asks them to connect their wallet, and prompts a signature to claim. It is a malicious approval, and the moment they sign, the drainer moves every token of value out of the wallet in seconds.

On-chain, the funds land in a fresh address that is also collecting sweeps from dozens of other victims that day. The kit author automatically skims a percentage as it flows through. The victim did nothing after signing; the single signature was the whole attack, and a warning at the prompt would have been the last chance to stop it.

Why it is dangerous for operators

Drainers industrialize wallet theft. Because they are sold as a service, the barrier to running a professional-grade draining scam is low, so many unskilled scammers can field polished campaigns using the same tooling. That means volume: a single drainer family can be behind a flood of losses across many fake sites and lures at the same time.

They are also fast and final. The theft completes in one signature and settles on-chain with no reversal, so the defensible moment is before the victim signs. Effective defenses include wallet-drain detection, blocklists of known malicious sites and contracts, and clear, specific warnings at the point a user is about to sign something risky. After the sweep, response shifts to tracing the consolidation address toward an off-ramp.

What to watch in the data

  • Full-balance sweep to a fresh address. A wallet emptied of everything valuable into a newly created address is the core drainer tell.
  • Shared consolidation address. One destination gathering sweeps from many unrelated victims points to a single campaign.
  • Malicious approval before the sweep. A risky approval or transfer signed just before the drain is the trigger event.
  • Phishing infrastructure links. Sites tied to fake airdrops, cloned apps, or malicious ads recurring across victims.
  • Skim to the kit author. A percentage split off to a separate address on each theft signals drainer-as-a-service.

Quick questions

What is drainer-as-a-service?

It is a rental model where kit authors provide the draining code, phishing templates, and infrastructure, and take a cut of everything their affiliates steal. It lets low-skill scammers run professional campaigns and spreads the same tooling across many attacks.

How does a drainer actually take the funds?

Usually through a malicious transaction or token approval the victim signs on a fake site. Once signed, the drainer moves the wallet's valuable assets out, often sweeping the full balance in a single automated pass.

How is a drainer different from approval phishing?

Approval phishing is the technique of tricking someone into signing a bad approval. A drainer is the packaged tooling that automates the whole scam, and it frequently uses approval phishing as one of its methods. One is the trick; the other is the kit.

Can drained funds be recovered?

Rarely and with difficulty. The sweep is a valid on-chain transaction with no reversal. Recovery depends on tracing the consolidation address to a KYC off-ramp and involving the venue or law enforcement quickly.

How do victims end up on the fake site?

Through phishing: malicious ads, fake airdrop promotions, cloned versions of real apps, and hijacked social media accounts. The lure usually promises a reward that requires connecting a wallet and signing.

What is the best defense?

Prevention at the signing moment. Wallet-drain detection, blocklists of known malicious sites and contracts, and clear warnings before a risky signature give the user a chance to stop. After a drain, the focus turns to tracing the funds.

Go deeper

  • FATF ↗ — The global standard-setter for AML, counter-terrorist-financing, and counter-proliferation. Recommendations, guidance, and jurisdiction lists.
  • OFAC, US Treasury ↗ — Administers US sanctions programs, the SDN list, and licensing.

Qué saber junto con Crypto drainer