Key Takeaways
Phishing in crypto is not a variation on email scams; it is a distinct discipline built around one structural fact: a self-custody wallet requires no institution's permission to move funds, only a valid signature from its owner. That single fact is why phishing and wallet drainers cause more direct, irreversible loss to individual crypto holders than almost any other attack category. Attackers no longer need to steal a password and log in somewhere; they need one convincing page and one signature. This page maps the threat: the vectors attackers use to put a malicious page in front of you, the channels they deliver through, the mechanics that make a drainer script work once you connect, and the defenses that close each gap.
Direct answer: A crypto phishing attack works by getting a wallet holder to visit a fake or compromised destination and sign a transaction or message there. The destination might be a cloned exchange login, a fake airdrop-claim page, a malicious dApp, or a message from a fake support account, but the mechanism converges on the same outcome: an approval, permit, or transfer that a drainer script then exercises to move tokens, NFTs, or native currency out of the wallet, often within seconds of the signature and without any further action from the victim.
- Phishing and wallet drainers work through a signature, not a stolen password; the seed phrase is frequently never touched.
- Attackers reach victims through many vectors and channels beyond email, including Discord, X, paid search ads, QR codes, and SIM swaps.
- A drainer script's real target is usually a token approval or a permit signature, which grants standing or immediate spending rights.
- Crypto transactions are irreversible; once a drainer executes, there is no bank, card network, or central authority that can undo it.
- This page is the full technical hub for the topic; fourteen linked guides below cover each vector, channel, mechanic, and defense in depth.
- For the broader scam landscape phishing sits within, see Common Crypto Scams, which surveys rug pulls, recovery scams, and impersonation alongside a shorter phishing summary.
Scope of This Guide
Swoopr's Common Crypto Scams page surveys seven categories of crypto fraud in brief, phishing and wallet drainers among them, alongside rug pulls, romance scams, recovery fraud, and impersonation, and is the right starting point for a broad orientation across scam types. This page is different in purpose: it is the phishing-specific deep dive, covering only phishing and wallet-drainer attacks, but going considerably further into the distinct vectors attackers use to reach a victim, the channels they deliver through, and the technical mechanics, token approvals, permit signatures, malicious dApp connections, that turn a single click into a drained wallet.
Before working through the vector, channel, and mechanics groups below, it's worth reading How Phishing Attacks Work first. That guide lays out the five-stage lifecycle common to nearly every phishing attack, reconnaissance, lure, delivery, fake destination, and payoff. This page organizes the specifics of that lifecycle by category so you can go straight to the vector or channel most relevant to you.
Every Guide in This Cluster
Every guide in the Phishing & Wallet Drainers cluster, in one list for quick navigation. The sections below group these by theme with a summary of each.
- How Phishing Attacks Work
- Wallet-Drainer Scripts Explained
- Fake Airdrop Phishing
- Discord and Telegram Phishing
- Fake Browser Extensions
- Malicious dApp Connections
- Typosquatting and Fake Domains
- Fake Customer Support Scams
- SIM-Swap Attacks
- Clipboard-Hijacking Malware
- Fake Wallet Apps
- QR Code Phishing
- Social Media Impersonation
- How to Verify a Legitimate Site
Attack Vectors: The Fake Surface You Interact With
An attack vector, in this context, is the specific fake or compromised surface an attacker puts in front of a victim: a page, an app, a code, or a piece of malware. These five vectors cover the range from a convincing website down to malware that never shows a fake page at all.
Fake Airdrop and Claim Sites
Legitimate airdrops are ordinary; new protocols routinely distribute tokens to early users or liquidity providers, and claiming one usually asks for nothing beyond a signed transaction. Attackers exploit that normalcy by building lookalike claim pages, complete with countdown timers and familiar branding, that request a wallet connection and a signature disguised as the claim itself. Some also "dust" a wallet with a real but worthless token to draw curiosity toward a linked phishing page.
Read the full guide: Fake Airdrop Phishing
Fake Customer Support
Fake support accounts reply inside a real company's own comment sections, run ads that surface above genuine help pages, or DM users who publicly complained about an issue, offering to "help" resolve it. Because the contact often appears adjacent to something real, whether a genuine post or a name matching an actual employee, it borrows credibility it hasn't earned, and the eventual ask is almost always a wallet connection, a remote-access tool, or a seed phrase framed as necessary for "verification."
Read the full guide: Fake Customer Support Scams
Fake Browser Extensions
Malicious extensions reach victims through official browser stores, either as outright clones of a real wallet's interface, capturing a seed phrase the moment it's typed to "restore" the wallet, or as trojanized utility extensions that quietly monitor page activity and clipboard content in the background after a broad permissions grant most people never read closely.
Read the full guide: Fake Browser Extensions
QR Code Phishing
A QR code hides its destination until scanned, which is exactly what makes it useful to attackers: a sticker over a legitimate poster, a code in a phishing email, or a printed code at a fake in-person booth can point to a cloned wallet-connect page instead of the real one, and a phone camera gives no easy way to preview the URL before it loads.
Read the full guide: QR Code Phishing
Clipboard-Hijacking Malware
This malware runs silently in the background and watches the clipboard for anything that looks like a wallet address, then swaps it for an attacker-controlled address that is often generated to superficially resemble the copied one. The victim pastes a destination address they never actually typed or re-checked, and the funds move to the wrong address the moment the transaction is confirmed.
Delivery Channels: How the Link Reaches You
A vector needs a delivery channel to reach a victim. These three channels account for most of how crypto phishing links and pretexts arrive, and each borrows a kind of trust native to the platform it runs on.
Discord and Telegram
Nearly every serious crypto project maintains an official Discord server or Telegram group as its primary community and support surface, which gathers a large, trusting audience in one place that attackers don't have to build themselves. Fake support accounts, hijacked moderator logins, cloned servers, and "verification" bots that DM new members all exploit the platform-native assumption that a message from someone with a staff-looking role or badge is legitimate.
Read the full guide: Discord and Telegram Phishing
Social Media Impersonation
Cloned profile photos, copied bios, purchased or bot-driven follower counts, and replies posted directly under a real company's or influencer's genuine content all let an attacker's account borrow the appearance of an established, trusted identity. On platforms like X, a reply to a real support thread from a lookalike account can reach a victim faster than the platform's own genuine support team does.
Read the full guide: Social Media Impersonation
SIM-Swap Attacks
A SIM swap doesn't deliver a phishing link at all; it hijacks the phone number behind SMS-based two-factor authentication and password resets by social-engineering a mobile carrier into porting the victim's number to an attacker-controlled SIM. From there, an attacker can intercept login codes for exchange accounts directly, bypassing the need for a fake site entirely, which is why it's grouped here as a delivery channel of last resort for high-value, targeted attacks.
Technical Mechanics: What Actually Moves the Funds
Once a victim reaches a fake destination, something has to convert a click into a loss. These three guides cover the technical layer: the code that executes the theft, the connection that delivers the malicious request, and the domain trickery behind the fake page itself.
Wallet-Drainer Scripts
A wallet-drainer script is the code embedded in a fake site that constructs the malicious transaction or signature request, checks a connected wallet's holdings to decide what's worth taking, and often prioritizes the most valuable assets automatically. Several drainer-as-a-service kits have been documented by blockchain security researchers, sold or rented to affiliate scammers who deploy them on their own fake sites in exchange for a cut of whatever is stolen, which is part of why the same underlying drainer code turns up behind many unrelated-looking scam campaigns.
Read the full guide: Wallet-Drainer Scripts Explained
Malicious dApp Connections
Connecting a wallet to a dApp is a routine, expected action in crypto, and that's precisely what makes it dangerous when the dApp is fake or has been compromised. A malicious dApp can request an oversized or unlimited token approval disguised as a normal swap or mint, or exploit a wallet-connect session to send transaction requests that don't match what the interface displayed to the user.
Read the full guide: Malicious dApp Connections
Typosquatting and Fake Domains
Typosquatting registers domains that are one character off from a real one, a swapped letter, an added hyphen, an extra word, or a different top-level domain, so that a rushed or careless read of the URL bar doesn't catch the difference. Combined with a free SSL certificate and a cloned page, a typosquatted domain can be functionally indistinguishable from the real site to anyone who isn't checking the address character-by-character.
Defense: Verifying What's Real
Every vector, channel, and mechanic above depends on the victim failing to independently verify something, an identity, a domain, or an app. These two guides cover the verification habits that catch a fake before any signature is requested.
Verifying a Legitimate Site
Confirming a site is genuine comes down to a short, repeatable process: reaching it only through a saved bookmark or the project's own official documentation rather than a search result or a link in a message, checking the domain character-by-character, and cross-referencing the site against the organization's verified social accounts rather than the other way around.
Read the full guide: How to Verify a Legitimate Site
Verifying Wallet Apps
The same verification discipline applies before installing a wallet app, not just before visiting a website. Fake wallet apps have appeared in official app stores disguised as popular wallets, sometimes ranking above the genuine app through paid placement or inflated reviews, and function identically to the real thing right up until a seed phrase is entered to "restore" or "import" an existing wallet.
Worked Example: A Full Wallet-Drain Attack Chain
Hypothetical walkthrough — for education only.
The individual guides above cover each piece in isolation. This walkthrough follows one attack end to end, from the moment a link arrives to the moment funds leave the wallet, showing exactly how the vectors, delivery channel, and technical mechanics described above connect into a single working attack chain.
Step 1 — Delivery. A trader who holds an NFT collection sees a reply under the collection's official X post, from an account using the project's logo and a name like "[Project] Team," announcing a surprise "loyalty mint" open for the next hour to holders only. The reply includes a link to what appears to be the project's own domain, differing from the real one by a single added letter.
Step 2 — The fake destination. The link opens a page that is a pixel-identical clone of the project's real minting site, complete with the correct logo, fonts, and layout, served over a valid SSL certificate obtained for the typosquatted domain. A countdown timer shows 47 minutes remaining. A "Connect Wallet" button sits exactly where the real site places it.
Step 3 — Connecting the wallet. The trader connects their wallet, which is a normal, low-risk action on the real site and therefore doesn't itself raise suspicion. Behind the scenes, the page's embedded drainer script reads the connected wallet's holdings, identifies the NFT collection and a stablecoin balance as the highest-value targets, and prepares a transaction request accordingly.
Step 4 — The signature request. Instead of a mint transaction, the wallet displays a signature request labeled by the site as "Confirm Loyalty Status." What it actually requests is a setApprovalForAll call for the NFT collection's contract, granting the attacker's address blanket permission to transfer any NFT from that collection out of the wallet, paired with a Permit2 signature covering the stablecoin balance. Because both are signatures rather than on-chain transactions, neither requires gas the trader would notice as unusual, and the wallet's default display shows the destination contract address rather than plain-language text explaining "this grants unlimited transfer rights over your entire NFT collection."
Step 5 — The payoff. The trader signs, believing they've claimed a loyalty mint. Nothing appears to move at that instant; the NFT and stablecoin balance are both still visibly present in the wallet immediately afterward, which is what makes this style of attack so effective; there's no obvious loss to notice. Within minutes, the drainer script's backend submits a batch of transferFrom calls using the newly granted approval and Permit2 signature, sweeping the NFTs and stablecoin balance to the attacker's wallet in a small number of transactions the trader never separately authorized one by one.
Where the chain could have been broken. Four independent points could have stopped this: verifying the "loyalty mint" announcement through the project's own pinned channel rather than a reply (delivery), checking the domain character-by-character before clicking through (fake destination), recognizing that a "confirm loyalty status" action has no legitimate reason to request a blanket NFT approval and a stablecoin permit together (technical mechanics), or using a wallet that decodes and plainly labels what a signature authorizes before approving it (defense). The attack succeeded because all four were skipped under the pressure of a closing countdown timer, not because any single defense failed catastrophically.
Misconceptions Versus Reality
| Misconception | Reality |
|---|---|
| Phishing only happens over email | Most crypto phishing arrives through Discord and Telegram DMs, fake X support replies, sponsored search ads, QR codes, and SIM-swap-enabled account takeovers; email is a minority channel |
| You have to type your seed phrase to get drained | A single malicious token approval or permit signature can authorize a drainer to move funds without the victim ever exposing a seed phrase or private key |
| Nothing is wrong if my balances still show up right after signing | An approval or permit is a standing authorization, not an immediate transfer; a drainer script can execute the actual sweep minutes, hours, or days later |
| A valid SSL certificate or padlock icon proves a site is legitimate | Certificates are free and trivial to obtain for any domain, including a typosquatted one; they encrypt the connection but say nothing about who controls it |
| Only careless or inexperienced holders fall for wallet drainers | Personalized, well-researched attacks target experienced, high-value holders specifically, and confidence in one's own caution is not itself a defense |
Risks, Limitations, and Exceptions
- Attackers continuously develop new vectors, channels, and drainer techniques; this page describes the current landscape, not a permanently exhaustive one.
- No wallet, browser extension, or hardware device can stop a phishing attack outright, since the victim's own valid signature is what authorizes the loss.
- Approval-checking and revocation tools depend on accurate on-chain indexing and can lag behind newly deployed drainer contracts.
- Recovering funds after a signed, confirmed drain is rare regardless of who is contacted afterward; prevention is the primary defense, not recovery.
- A legitimate site or app can itself be compromised temporarily through a supply-chain or DNS attack, which domain-checking habits alone will not catch.
- The worked example above is illustrative; real attack chains vary in pretext, platform, number of steps, and which specific assets are targeted.
- SIM-swap and clipboard-hijacking attacks can bypass wallet-signature defenses entirely, since they target account access or the copy-paste step directly.
Practical Implementation Checklist
- Bookmark every official site and app you use for crypto, and stop reaching them through search results, ads, or links in messages.
- Use a hardware wallet for any holdings beyond what you're actively trading; keeping keys offline removes a large share of remote attack surface.
- Verify a domain character-by-character before entering credentials or connecting a wallet anywhere; look-alike spellings are the norm, not the exception.
- Never sign a transaction or approval you don't understand; use a wallet that decodes and previews what a signature actually authorizes.
- Treat unsolicited DMs, comments, and support contact as unverified until confirmed through an independent, official channel you found yourself.
- Periodically review and revoke unused or unlimited token approvals with a reputable approval-checking tool.
- Use app-based or hardware-key two-factor authentication instead of SMS, which is vulnerable to SIM-swap attacks.
- Never connect a wallet purely to "verify," "sync," or resolve a support issue; legitimate services don't require this.
- Confirm a destination address against a saved contact or a hardware wallet's own screen rather than trusting a pasted value.
- If you've already signed something suspicious, revoke the approval and move remaining funds to a new wallet immediately.
Frequently Asked Questions
What exactly is a "wallet drainer"?
A wallet drainer is a piece of malicious code, usually embedded in a fake or compromised website, that is built specifically to extract value from a connected crypto wallet in a single interaction. Rather than stealing a password, it presents a transaction or signature request designed to look routine, and once approved, it transfers or gains standing permission over the wallet's tokens, NFTs, or native currency. Drainer kits are often built and rented out by one group to many affiliate scammers, who deploy them on their own fake sites in exchange for a cut of whatever is stolen.
How does a phishing attack drain a wallet if I never share my seed phrase or private key?
A self-custody wallet doesn't need a stolen seed phrase to lose funds; it only needs one valid signature from the owner. A fake site can present a token approval or a permit signature disguised as a routine "claim," "verify," or "mint" action. Signing it authorizes the attacker's contract to move tokens directly, using the wallet's own cryptographic signature as proof of authorization. The seed phrase stays untouched throughout; the damage comes entirely from what was approved.
What's the difference between this guide and Swoopr's Common Crypto Scams page?
Common Crypto Scams surveys the full landscape of crypto fraud, phishing, rug pulls, romance scams, fake tokens, recovery scams, and giveaway fraud, in brief summaries of each. This page is the phishing-specific deep dive: it covers only phishing and wallet-drainer attacks, but goes much further into how they actually work, the specific vectors and delivery channels attackers use, and the technical mechanics of a drainer script.
Does crypto phishing only happen through email?
No. Email phishing exists in crypto, but it is a minority channel compared to Discord and Telegram DMs from fake support accounts, replies from cloned or hijacked profiles under real posts on X and other social platforms, sponsored search ads that outrank the genuine site for its own brand name, and SMS or voice-call pretexts tied to SIM-swap attacks. Assuming phishing only arrives by email leaves every other channel unguarded.
What is a permit or Permit2 signature, and why do drainer kits rely on it?
A permit signature (from the ERC-2612 standard) or a Permit2 signature (from a widely adopted router contract) lets a wallet holder authorize a token transfer or approval entirely off-chain, by signing a message rather than sending a separate on-chain transaction. Drainer kits favor these because the signature is free to obtain, doesn't need gas the victim would notice, and, unlike a typical approve call, can sometimes be structured to allow an immediate transfer rather than just a standing allowance, letting a single signature complete the theft in one step.
Can a hardware wallet fully protect me from phishing and drainers?
A hardware wallet protects the private key from malware and remote theft, which stops a large share of attacks, but it cannot stop a phishing attack on its own. If the owner approves a malicious signature on the device's own screen, believing it to be legitimate, the hardware wallet will sign it correctly and the funds will still move. A hardware wallet is a strong layer of defense against key theft, not a substitute for reading what a transaction actually authorizes.
How can I verify a site is legitimate before connecting my wallet?
Reach the site only through a saved bookmark or a link typed from the project's own official documentation, never a link in a message, comment, or ad. Check the full domain character-by-character for swapped letters, extra words, or an unfamiliar top-level domain. See How to Verify a Legitimate Site for the complete checklist, including certificate checks and cross-referencing official social accounts.
What should I do immediately if I think I signed a malicious approval?
Revoke the approval right away using a reputable approval-checking and revocation tool, then move any remaining assets in that wallet to a new wallet with a freshly generated seed phrase, since the compromised wallet may remain exposed to further approvals or a drainer script that re-checks it. Speed matters: an outstanding approval or permit remains usable by the attacker until it is revoked or its allowance is spent.
Sources and Methodology
This guide describes the general structure, vectors, and technical mechanics of crypto phishing and wallet-drainer attacks based on publicly available law-enforcement, industry, and wallet-security documentation as of mid-2026. Key sources include:
- FBI Internet Crime Complaint Center (IC3): IC3's annual Internet Crime Reports and public service announcements repeatedly identify cryptocurrency phishing and wallet-related fraud as one of the fastest-growing categories of reported financial loss, and document the impersonation and urgency tactics referenced throughout this guide.
- Chainalysis Crypto Crime Report: Chainalysis's annual crime reports track on-chain fraud and theft trends, including the scale of funds moved through approval-based and drainer-script wallet theft and the growth of drainer-as-a-service infrastructure.
- MetaMask Security and Phishing Detection documentation: MetaMask publishes guidance on its phishing-detection features, blocklists, and how to read a transaction confirmation screen before signing, directly relevant to the signature-mechanics content in this guide.
- Etherscan phishing and scam address labeling: Etherscan maintains community-sourced labels flagging known phishing and drainer-associated addresses, which underpin the domain- and address-verification habits recommended throughout this guide.
The worked example in this guide is a hypothetical, illustrative scenario constructed for educational purposes and does not describe a specific real incident, project, or account.
This content was reviewed by the Swoopr Editorial Team in August 2026 and reflects publicly available information at that time. Phishing and drainer techniques evolve quickly; treat this guide as a structural framework rather than an exhaustive or permanently current list of tactics.
Conclusion
Phishing and wallet drainers succeed by converting a routine action, clicking a link, connecting a wallet, signing a transaction, into an irreversible transfer of value, through a wide and growing range of vectors and channels that go far beyond a suspicious email. Recognizing the underlying structure, a fake surface, a channel that borrows trust, a signature mechanic that grants more than it appears to, and a verification step that was skipped, generalizes far better than memorizing any single scam script. Use this page as the map, then move to whichever of the fourteen linked guides matches your situation.
Related Reading
- Crypto Security and Scam Center — the parent hub for wallet security, scam awareness, and incident response across all of Swoopr's security content.
- Common Crypto Scams — the broader scam-type survey phishing sits within, covering rug pulls, recovery scams, impersonation, and more alongside a shorter phishing summary.
- How Phishing Attacks Work — the five-stage attack lifecycle and psychology behind every phishing pattern described on this page.
- Hot Wallets vs. Cold Wallets — how storage choice affects exposure to the phishing and drainer attacks described here.