Learn · Threat research

How wallet drainers actually work: approvals, permits, and signatures that empty accounts

By Nova Team Published Oct 8, 2026 Updated Oct 30, 2026 ~9 min read Intermediate
Nova Wallet · Learn

A wallet drainer doesn't steal your keys. It gets you to sign a permission slip — then spends your balance whenever it wants. Here is the mechanism, the kits behind it, and the twenty-second check that stops it.

On this page 7 sections
Key takeaways
  • Wallet drainers stole $494 million from 332,000 victims in 2024 — up 67% year over year (Scam Sniffer).
  • At sign time, nothing moves. The signature stores permission; the drainer spends it later.
  • Four calls do almost all the damage: approve, setApprovalForAll, permit, and Permit2 signatures.
  • Inferno, Angel, and Pink turned draining into rented infrastructure — the phishing site is a franchise.
  • Reading three fields — domain, action, spender — before signing stops most attempts cold.

The scale of the problem§

Drainers are now the single largest category of wallet theft. Scam Sniffer's 2024 report counted $494 million stolen across 332,000 victims — up 67% from the year before. The number matters less than the mechanism: almost none of those victims had a seed phrase compromised. They signed something.

$494Mstolen by wallet drainers in 2024
332Kvictim wallets affected
+67%growth over 2023

Source: Scam Sniffer, 2024 wallet-drainer report.

A drainer is not malware and not a keylogger. It is a contract — or a harvested signature — that you authorized yourself, inside your own wallet, on a site that looked legitimate. The whole business model rests on one UX failure: wallets ask you to sign, and people sign.

How an approval drains your wallet§

ERC-20 tokens track allowances — standing permissions saying "address X may move up to N of my tokens." You create one by calling approve(spender, amount). Legitimate dapps need it: a DEX cannot swap tokens it cannot move. The problem is what a malicious one asks for.

Drainer sites request approve with the spender set to the drainer contract and the amount set to type(uint256).max — "unlimited." From the moment that transaction confirms, the contract can call transferFrom and pull your entire balance — not just now, but forever, until you revoke it. No further signature is ever needed.

NFTs carry the same shape in setApprovalForAll(operator, true): one confirmation hands an operator transfer rights over every token you hold in that collection.

The four selectors that matter§

Strip away the phishing page and a drainer request is always one of four things:

RequestWhat it grantsWhy it's dangerous
approve(spender, amount)ERC-20 allowance — spender may transferFrom up to amountUnlimited amount = your whole balance, now and later
setApprovalForAll(op, true)Blanket transfer rights over an NFT collectionOne click, every NFT in the collection is movable
permit(owner, spender, …)Off-chain signature that becomes an allowance when submittedGasless — no transaction to inspect, looks like a "Sign in"
Permit2 signatureSignature-based token permission via the Permit2 contractOne signed message can authorize batch transfers

Notice what the last two have in common: they are messages, not transactions. Nothing lands on-chain when you sign. The drainer stores your signature and submits it — or sells it — later.

Blind signing: eth_sign and gasless permits§

The oldest primitive is still the worst. eth_sign asks the wallet to sign a raw 32-byte hash rendered as opaque hex. It can encode an approval, a permit, an order selling your NFTs for nothing — you cannot tell from what you are shown. Most wallets now warn on it or refuse outright; it still appears on phishing pages, because the requests that do get through are the profitable ones.

Permits are the polished version of the same trick. A permit or Permit2 signature produces valid authorization — owner, spender, amount, deadline — that anyone can submit on-chain. The prompt looks like a login: "Sign to verify your wallet." Gasless means no fee estimate, no simulation preview, no confirmation screen — three moments where a drainer would normally lose you.

Drainer-as-a-service kits§

You rarely face a lone phisher. Inferno, Angel, and Pink — the best-documented kits — are sold as drainer-as-a-service. The kit operator supplies the draining contract, the phishing templates, the domain rotation, and the dashboard; affiliates drive traffic through fake airdrops, hijacked Discord announcements, malvertising, and compromised frontends; the operator takes a cut of every drained wallet.

That is why the same drainer shows up on hundreds of domains and why takedowns don't stick — the infrastructure is rented, not owned. It is also why "the site looked professional" means nothing: professionalism is the product.

A pre-sign checklist that works§

Urgency is the payload. "Claim ends in 3:00," "your wallet will be suspended," "final eligibility check" — the countdown exists to move you past reading. Any page that hurries you toward a signature is hostile until proven otherwise.

  • Read the domain, character by character. Lookalikes swap glyphs; a real airdrop lives on the project's actual domain, not one registered last week.
  • Read the action. "Connect" is harmless; approve, setApprovalForAll, and permit are not. If a read-only check asks for a signature that moves money, walk away.
  • Read the spender and the amount. An unlimited grant to an address that isn't the dapp's well-known contract is the theft itself — everything else is decoration.
  • Refuse opaque hashes. If the wallet cannot decode what you're signing (eth_sign), the answer is no.
  • Revoke stale approvals. Old unlimited grants to contracts you no longer use are pre-loaded drainers, waiting for those contracts to be exploited.

What Nova Shield does — and doesn't§

Nova Shield screens signature requests before you sign — on-device, across eight exploit classes. It decodes approval and permit payloads instead of showing raw hex, surfaces the spender and allowance in plain language, and flags spenders that match known drainer infrastructure. There is no remote kill switch: Shield tells you what you're about to sign; the signature is still yours.

What it can't do
  • It can't recover anything after broadcast — an approval you confirmed anyway is on-chain.
  • It can't classify a drainer contract deployed an hour ago; screening improves the odds, it doesn't make signatures safe.
  • It can't protect signatures you make in other wallets or on other devices.

Shield's job is to make the checklist above automatic — but the read is still worth learning, because the request that matters most is always the one in front of you.

See every signature before it costs you.

Nova Wallet decodes approvals, permits, and recipients on-device before you sign. Keys never leave the window; nothing is phoned home.