Home

Security

Phishing and Wallet Drainers: How Crypto Phishing Attacks Actually Work

Spot the edge. Swoop in.

Phishing and wallet drainers are the single largest category of crypto theft aimed at individual holders, and nearly all of it works the same underlying way: a victim clicks a link, connects a wallet to a fake site, and signs something that looks routine but grants an attacker control over their funds. This pillar page is the full technical map of that threat, every vector attackers use to reach you, every channel they deliver through, the code and signature mechanics that make a drainer work, and the defenses that actually stop it, with links to fourteen focused guides underneath it.

By Swoopr Editorial Team

Published · Updated

AI-assisted content · Swoopr is responsible for the final published article.

Key Takeaways

Phishing in crypto is not a variation on email scams; it is a distinct discipline built around one structural fact: a self-custody wallet requires no institution's permission to move funds, only a valid signature from its owner. That single fact is why phishing and wallet drainers cause more direct, irreversible loss to individual crypto holders than almost any other attack category. Attackers no longer need to steal a password and log in somewhere; they need one convincing page and one signature. This page maps the threat: the vectors attackers use to put a malicious page in front of you, the channels they deliver through, the mechanics that make a drainer script work once you connect, and the defenses that close each gap.

Direct answer: A crypto phishing attack works by getting a wallet holder to visit a fake or compromised destination and sign a transaction or message there. The destination might be a cloned exchange login, a fake airdrop-claim page, a malicious dApp, or a message from a fake support account, but the mechanism converges on the same outcome: an approval, permit, or transfer that a drainer script then exercises to move tokens, NFTs, or native currency out of the wallet, often within seconds of the signature and without any further action from the victim.

Scope of This Guide

Swoopr's Common Crypto Scams page surveys seven categories of crypto fraud in brief, phishing and wallet drainers among them, alongside rug pulls, romance scams, recovery fraud, and impersonation, and is the right starting point for a broad orientation across scam types. This page is different in purpose: it is the phishing-specific deep dive, covering only phishing and wallet-drainer attacks, but going considerably further into the distinct vectors attackers use to reach a victim, the channels they deliver through, and the technical mechanics, token approvals, permit signatures, malicious dApp connections, that turn a single click into a drained wallet.

Before working through the vector, channel, and mechanics groups below, it's worth reading How Phishing Attacks Work first. That guide lays out the five-stage lifecycle common to nearly every phishing attack, reconnaissance, lure, delivery, fake destination, and payoff. This page organizes the specifics of that lifecycle by category so you can go straight to the vector or channel most relevant to you.

Every Guide in This Cluster

Every guide in the Phishing & Wallet Drainers cluster, in one list for quick navigation. The sections below group these by theme with a summary of each.

  1. How Phishing Attacks Work
  2. Wallet-Drainer Scripts Explained
  3. Fake Airdrop Phishing
  4. Discord and Telegram Phishing
  5. Fake Browser Extensions
  6. Malicious dApp Connections
  7. Typosquatting and Fake Domains
  8. Fake Customer Support Scams
  9. SIM-Swap Attacks
  10. Clipboard-Hijacking Malware
  11. Fake Wallet Apps
  12. QR Code Phishing
  13. Social Media Impersonation
  14. How to Verify a Legitimate Site

Attack Vectors: The Fake Surface You Interact With

An attack vector, in this context, is the specific fake or compromised surface an attacker puts in front of a victim: a page, an app, a code, or a piece of malware. These five vectors cover the range from a convincing website down to malware that never shows a fake page at all.

Fake Airdrop and Claim Sites

Legitimate airdrops are ordinary; new protocols routinely distribute tokens to early users or liquidity providers, and claiming one usually asks for nothing beyond a signed transaction. Attackers exploit that normalcy by building lookalike claim pages, complete with countdown timers and familiar branding, that request a wallet connection and a signature disguised as the claim itself. Some also "dust" a wallet with a real but worthless token to draw curiosity toward a linked phishing page.

Read the full guide: Fake Airdrop Phishing

Fake Customer Support

Fake support accounts reply inside a real company's own comment sections, run ads that surface above genuine help pages, or DM users who publicly complained about an issue, offering to "help" resolve it. Because the contact often appears adjacent to something real, whether a genuine post or a name matching an actual employee, it borrows credibility it hasn't earned, and the eventual ask is almost always a wallet connection, a remote-access tool, or a seed phrase framed as necessary for "verification."

Read the full guide: Fake Customer Support Scams

Fake Browser Extensions

Malicious extensions reach victims through official browser stores, either as outright clones of a real wallet's interface, capturing a seed phrase the moment it's typed to "restore" the wallet, or as trojanized utility extensions that quietly monitor page activity and clipboard content in the background after a broad permissions grant most people never read closely.

Read the full guide: Fake Browser Extensions

QR Code Phishing

A QR code hides its destination until scanned, which is exactly what makes it useful to attackers: a sticker over a legitimate poster, a code in a phishing email, or a printed code at a fake in-person booth can point to a cloned wallet-connect page instead of the real one, and a phone camera gives no easy way to preview the URL before it loads.

Read the full guide: QR Code Phishing

Clipboard-Hijacking Malware

This malware runs silently in the background and watches the clipboard for anything that looks like a wallet address, then swaps it for an attacker-controlled address that is often generated to superficially resemble the copied one. The victim pastes a destination address they never actually typed or re-checked, and the funds move to the wrong address the moment the transaction is confirmed.

Read the full guide: Clipboard-Hijacking Malware

Delivery Channels: How the Link Reaches You

A vector needs a delivery channel to reach a victim. These three channels account for most of how crypto phishing links and pretexts arrive, and each borrows a kind of trust native to the platform it runs on.

Discord and Telegram

Nearly every serious crypto project maintains an official Discord server or Telegram group as its primary community and support surface, which gathers a large, trusting audience in one place that attackers don't have to build themselves. Fake support accounts, hijacked moderator logins, cloned servers, and "verification" bots that DM new members all exploit the platform-native assumption that a message from someone with a staff-looking role or badge is legitimate.

Read the full guide: Discord and Telegram Phishing

Social Media Impersonation

Cloned profile photos, copied bios, purchased or bot-driven follower counts, and replies posted directly under a real company's or influencer's genuine content all let an attacker's account borrow the appearance of an established, trusted identity. On platforms like X, a reply to a real support thread from a lookalike account can reach a victim faster than the platform's own genuine support team does.

Read the full guide: Social Media Impersonation

SIM-Swap Attacks

A SIM swap doesn't deliver a phishing link at all; it hijacks the phone number behind SMS-based two-factor authentication and password resets by social-engineering a mobile carrier into porting the victim's number to an attacker-controlled SIM. From there, an attacker can intercept login codes for exchange accounts directly, bypassing the need for a fake site entirely, which is why it's grouped here as a delivery channel of last resort for high-value, targeted attacks.

Read the full guide: SIM-Swap Attacks

Technical Mechanics: What Actually Moves the Funds

Once a victim reaches a fake destination, something has to convert a click into a loss. These three guides cover the technical layer: the code that executes the theft, the connection that delivers the malicious request, and the domain trickery behind the fake page itself.

Wallet-Drainer Scripts

A wallet-drainer script is the code embedded in a fake site that constructs the malicious transaction or signature request, checks a connected wallet's holdings to decide what's worth taking, and often prioritizes the most valuable assets automatically. Several drainer-as-a-service kits have been documented by blockchain security researchers, sold or rented to affiliate scammers who deploy them on their own fake sites in exchange for a cut of whatever is stolen, which is part of why the same underlying drainer code turns up behind many unrelated-looking scam campaigns.

Read the full guide: Wallet-Drainer Scripts Explained

Malicious dApp Connections

Connecting a wallet to a dApp is a routine, expected action in crypto, and that's precisely what makes it dangerous when the dApp is fake or has been compromised. A malicious dApp can request an oversized or unlimited token approval disguised as a normal swap or mint, or exploit a wallet-connect session to send transaction requests that don't match what the interface displayed to the user.

Read the full guide: Malicious dApp Connections

Typosquatting and Fake Domains

Typosquatting registers domains that are one character off from a real one, a swapped letter, an added hyphen, an extra word, or a different top-level domain, so that a rushed or careless read of the URL bar doesn't catch the difference. Combined with a free SSL certificate and a cloned page, a typosquatted domain can be functionally indistinguishable from the real site to anyone who isn't checking the address character-by-character.

Read the full guide: Typosquatting and Fake Domains

Defense: Verifying What's Real

Every vector, channel, and mechanic above depends on the victim failing to independently verify something, an identity, a domain, or an app. These two guides cover the verification habits that catch a fake before any signature is requested.

Verifying a Legitimate Site

Confirming a site is genuine comes down to a short, repeatable process: reaching it only through a saved bookmark or the project's own official documentation rather than a search result or a link in a message, checking the domain character-by-character, and cross-referencing the site against the organization's verified social accounts rather than the other way around.

Read the full guide: How to Verify a Legitimate Site

Verifying Wallet Apps

The same verification discipline applies before installing a wallet app, not just before visiting a website. Fake wallet apps have appeared in official app stores disguised as popular wallets, sometimes ranking above the genuine app through paid placement or inflated reviews, and function identically to the real thing right up until a seed phrase is entered to "restore" or "import" an existing wallet.

Read the full guide: Fake Wallet Apps

Worked Example: A Full Wallet-Drain Attack Chain

Hypothetical walkthrough — for education only.

The individual guides above cover each piece in isolation. This walkthrough follows one attack end to end, from the moment a link arrives to the moment funds leave the wallet, showing exactly how the vectors, delivery channel, and technical mechanics described above connect into a single working attack chain.

Step 1 — Delivery. A trader who holds an NFT collection sees a reply under the collection's official X post, from an account using the project's logo and a name like "[Project] Team," announcing a surprise "loyalty mint" open for the next hour to holders only. The reply includes a link to what appears to be the project's own domain, differing from the real one by a single added letter.

Step 2 — The fake destination. The link opens a page that is a pixel-identical clone of the project's real minting site, complete with the correct logo, fonts, and layout, served over a valid SSL certificate obtained for the typosquatted domain. A countdown timer shows 47 minutes remaining. A "Connect Wallet" button sits exactly where the real site places it.

Step 3 — Connecting the wallet. The trader connects their wallet, which is a normal, low-risk action on the real site and therefore doesn't itself raise suspicion. Behind the scenes, the page's embedded drainer script reads the connected wallet's holdings, identifies the NFT collection and a stablecoin balance as the highest-value targets, and prepares a transaction request accordingly.

Step 4 — The signature request. Instead of a mint transaction, the wallet displays a signature request labeled by the site as "Confirm Loyalty Status." What it actually requests is a setApprovalForAll call for the NFT collection's contract, granting the attacker's address blanket permission to transfer any NFT from that collection out of the wallet, paired with a Permit2 signature covering the stablecoin balance. Because both are signatures rather than on-chain transactions, neither requires gas the trader would notice as unusual, and the wallet's default display shows the destination contract address rather than plain-language text explaining "this grants unlimited transfer rights over your entire NFT collection."

Step 5 — The payoff. The trader signs, believing they've claimed a loyalty mint. Nothing appears to move at that instant; the NFT and stablecoin balance are both still visibly present in the wallet immediately afterward, which is what makes this style of attack so effective; there's no obvious loss to notice. Within minutes, the drainer script's backend submits a batch of transferFrom calls using the newly granted approval and Permit2 signature, sweeping the NFTs and stablecoin balance to the attacker's wallet in a small number of transactions the trader never separately authorized one by one.

Where the chain could have been broken. Four independent points could have stopped this: verifying the "loyalty mint" announcement through the project's own pinned channel rather than a reply (delivery), checking the domain character-by-character before clicking through (fake destination), recognizing that a "confirm loyalty status" action has no legitimate reason to request a blanket NFT approval and a stablecoin permit together (technical mechanics), or using a wallet that decodes and plainly labels what a signature authorizes before approving it (defense). The attack succeeded because all four were skipped under the pressure of a closing countdown timer, not because any single defense failed catastrophically.

Misconceptions Versus Reality

MisconceptionReality
Phishing only happens over emailMost crypto phishing arrives through Discord and Telegram DMs, fake X support replies, sponsored search ads, QR codes, and SIM-swap-enabled account takeovers; email is a minority channel
You have to type your seed phrase to get drainedA single malicious token approval or permit signature can authorize a drainer to move funds without the victim ever exposing a seed phrase or private key
Nothing is wrong if my balances still show up right after signingAn approval or permit is a standing authorization, not an immediate transfer; a drainer script can execute the actual sweep minutes, hours, or days later
A valid SSL certificate or padlock icon proves a site is legitimateCertificates are free and trivial to obtain for any domain, including a typosquatted one; they encrypt the connection but say nothing about who controls it
Only careless or inexperienced holders fall for wallet drainersPersonalized, well-researched attacks target experienced, high-value holders specifically, and confidence in one's own caution is not itself a defense

Risks, Limitations, and Exceptions

Practical Implementation Checklist

  1. Bookmark every official site and app you use for crypto, and stop reaching them through search results, ads, or links in messages.
  2. Use a hardware wallet for any holdings beyond what you're actively trading; keeping keys offline removes a large share of remote attack surface.
  3. Verify a domain character-by-character before entering credentials or connecting a wallet anywhere; look-alike spellings are the norm, not the exception.
  4. Never sign a transaction or approval you don't understand; use a wallet that decodes and previews what a signature actually authorizes.
  5. Treat unsolicited DMs, comments, and support contact as unverified until confirmed through an independent, official channel you found yourself.
  6. Periodically review and revoke unused or unlimited token approvals with a reputable approval-checking tool.
  7. Use app-based or hardware-key two-factor authentication instead of SMS, which is vulnerable to SIM-swap attacks.
  8. Never connect a wallet purely to "verify," "sync," or resolve a support issue; legitimate services don't require this.
  9. Confirm a destination address against a saved contact or a hardware wallet's own screen rather than trusting a pasted value.
  10. If you've already signed something suspicious, revoke the approval and move remaining funds to a new wallet immediately.

Frequently Asked Questions

What exactly is a "wallet drainer"?

A wallet drainer is a piece of malicious code, usually embedded in a fake or compromised website, that is built specifically to extract value from a connected crypto wallet in a single interaction. Rather than stealing a password, it presents a transaction or signature request designed to look routine, and once approved, it transfers or gains standing permission over the wallet's tokens, NFTs, or native currency. Drainer kits are often built and rented out by one group to many affiliate scammers, who deploy them on their own fake sites in exchange for a cut of whatever is stolen.

How does a phishing attack drain a wallet if I never share my seed phrase or private key?

A self-custody wallet doesn't need a stolen seed phrase to lose funds; it only needs one valid signature from the owner. A fake site can present a token approval or a permit signature disguised as a routine "claim," "verify," or "mint" action. Signing it authorizes the attacker's contract to move tokens directly, using the wallet's own cryptographic signature as proof of authorization. The seed phrase stays untouched throughout; the damage comes entirely from what was approved.

What's the difference between this guide and Swoopr's Common Crypto Scams page?

Common Crypto Scams surveys the full landscape of crypto fraud, phishing, rug pulls, romance scams, fake tokens, recovery scams, and giveaway fraud, in brief summaries of each. This page is the phishing-specific deep dive: it covers only phishing and wallet-drainer attacks, but goes much further into how they actually work, the specific vectors and delivery channels attackers use, and the technical mechanics of a drainer script.

Does crypto phishing only happen through email?

No. Email phishing exists in crypto, but it is a minority channel compared to Discord and Telegram DMs from fake support accounts, replies from cloned or hijacked profiles under real posts on X and other social platforms, sponsored search ads that outrank the genuine site for its own brand name, and SMS or voice-call pretexts tied to SIM-swap attacks. Assuming phishing only arrives by email leaves every other channel unguarded.

What is a permit or Permit2 signature, and why do drainer kits rely on it?

A permit signature (from the ERC-2612 standard) or a Permit2 signature (from a widely adopted router contract) lets a wallet holder authorize a token transfer or approval entirely off-chain, by signing a message rather than sending a separate on-chain transaction. Drainer kits favor these because the signature is free to obtain, doesn't need gas the victim would notice, and, unlike a typical approve call, can sometimes be structured to allow an immediate transfer rather than just a standing allowance, letting a single signature complete the theft in one step.

Can a hardware wallet fully protect me from phishing and drainers?

A hardware wallet protects the private key from malware and remote theft, which stops a large share of attacks, but it cannot stop a phishing attack on its own. If the owner approves a malicious signature on the device's own screen, believing it to be legitimate, the hardware wallet will sign it correctly and the funds will still move. A hardware wallet is a strong layer of defense against key theft, not a substitute for reading what a transaction actually authorizes.

How can I verify a site is legitimate before connecting my wallet?

Reach the site only through a saved bookmark or a link typed from the project's own official documentation, never a link in a message, comment, or ad. Check the full domain character-by-character for swapped letters, extra words, or an unfamiliar top-level domain. See How to Verify a Legitimate Site for the complete checklist, including certificate checks and cross-referencing official social accounts.

What should I do immediately if I think I signed a malicious approval?

Revoke the approval right away using a reputable approval-checking and revocation tool, then move any remaining assets in that wallet to a new wallet with a freshly generated seed phrase, since the compromised wallet may remain exposed to further approvals or a drainer script that re-checks it. Speed matters: an outstanding approval or permit remains usable by the attacker until it is revoked or its allowance is spent.

Sources and Methodology

This guide describes the general structure, vectors, and technical mechanics of crypto phishing and wallet-drainer attacks based on publicly available law-enforcement, industry, and wallet-security documentation as of mid-2026. Key sources include:

The worked example in this guide is a hypothetical, illustrative scenario constructed for educational purposes and does not describe a specific real incident, project, or account.

This content was reviewed by the Swoopr Editorial Team in August 2026 and reflects publicly available information at that time. Phishing and drainer techniques evolve quickly; treat this guide as a structural framework rather than an exhaustive or permanently current list of tactics.

Conclusion

Phishing and wallet drainers succeed by converting a routine action, clicking a link, connecting a wallet, signing a transaction, into an irreversible transfer of value, through a wide and growing range of vectors and channels that go far beyond a suspicious email. Recognizing the underlying structure, a fake surface, a channel that borrows trust, a signature mechanic that grants more than it appears to, and a verification step that was skipped, generalizes far better than memorizing any single scam script. Use this page as the map, then move to whichever of the fourteen linked guides matches your situation.

Related Reading