A crypto drainer is a scam tool that empties your wallet after tricking you into signing one malicious transaction, often a prompt that looks like a routine wallet connection. Chainalysis reported in 2025 that known drainer kits stole over $1 billion from victims in 2024, mostly through fake airdrop sites and hijacked social accounts. The defense is refusing to sign transactions you did not initiate.
L4 News publishes information, not financial or security advice, and covering a scam mechanism is never a suggestion that any asset is worth holding.
How does a drainer actually steal funds?
The mechanism is an approval, not a password theft. Ethereum-style wallets let one address spend tokens held by another once the owner signs an approval, and drainers abuse that feature: the fake site shows a mint or claim button, the button triggers a transaction that grants the drainer unlimited spending rights, and the theft follows in a separate transaction the scammer controls.
Think of it like handing a parking valet your entire keyring instead of the car key. The analogy breaks down here: an approval can be granted for an unlimited amount and stays valid until you revoke it, sometimes for months.
What are the warning signs on the page?
Drainer pages follow a small set of patterns, and every one is visible before you connect a wallet:
- A free token, NFT, or airdrop that only requires "claiming" with a wallet connection
- A domain that imitates a known project with one character changed or a wrong ending
- Urgency: a countdown timer or "last chance" claim for something you never signed up for
- A signature request that appears the moment you connect, before you do anything else
The U.S. Federal Trade Commission's 2024 alerts describe the same pattern under broader crypto impersonation scams.
What does the wallet actually show me?
Modern wallet apps display what a transaction does before you sign, but the quality varies. A transfer shows the amount and destination. An approval shows the spender and an allowance, and the allowance is the field to read: "unlimited" means exactly that. MetaMask's 2024 security documentation advises users to treat unexpected approval requests as hostile and to verify the destination address independently.
Which habits actually prevent this?
Four habits cover nearly every documented drainer case:
- Never connect a wallet to a site you reached from a link in a post, DM, or email — navigate to known projects by typing the domain.
- Use a separate "burner" wallet for minting and claiming, holding only what that task needs.
- Read allowance fields before approving; reject anything requesting unlimited spend.
- Revoke old approvals periodically with a revocation tool, on a day when nothing else is happening.
What if I already signed something suspicious?
Act in this order: revoke the approval with a revocation tool if the theft has not happened yet, move remaining assets to a fresh wallet if it has, and then report the address. Reporting rarely recovers funds on public chains, but platform takedowns of the scam pages do follow reports. Loss stories are not minimized here: on public blockchains, a confirmed transfer is usually final.
Custodial versus self-custody: which is safer against drainers?
Neither is simply safer; they fail differently.
| Risk | Custodial (exchange holds keys) | Self-custody (you hold keys) |
|---|---|---|
| Drainer scams | Not exposed — you sign nothing | Directly exposed via approvals |
| Exchange failure | Fully exposed | Not exposed |
| Recovery if compromised | Support and account freeze possible | Usually none |
Self-custody is not risk-free, and the table is the honest reason why: it trades one set of risks for another.
What the evidence shows is that drainers exploit a specific mechanism — blind approval signing — and that the defense is behavioral, not a product you can buy. What remains unknown is how quickly wallet interfaces will make allowances impossible to overlook by default.

