Ilia Zavialov

Wallet drainers

How an Approval Drainer Empties a Wallet: Ilia Zavialov on the Signature Behind It

English version for the United Kingdom.

A wallet can lose every token inside it while its owner still knows the password and still holds the seed phrase safely on paper. The theft runs through a signature instead, a single approval clicked in the seconds it takes to read one line inside a wallet pop-up window. That signature hands a smart contract the right to move tokens whenever the other side chooses. This piece looks at what that permission grants, why connecting a wallet to an unfamiliar site already carries risk, and what revoking an old approval involves.

·10 min read·Ilia Zavialov

Ilia Zavialov explaining how an approval drainer empties a wallet through a single signed permission
Ilia Zavialov explaining how an approval drainer empties a wallet through a single signed permission

01The signature that replaces the password

Two different kinds of wallet compromise often get discussed as though they were the same event. One needs a secret, a password typed into a fake login screen, or a seed phrase read aloud to a fake support agent. The other needs a valid, correctly signed authorisation that the wallet's own owner produces using keys nobody else ever touched.

Approval phishing belongs entirely to the second kind, and it sits inside a small set of message types that every modern wallet already knows how to produce. A signature called approve grants a chosen address the right to move a set amount of one token. A signature called setApprovalForAll hands one address control over an entire collection of tokens in a single click.

Chainalysis, which tracks this category directly, sums up the mechanism in one line: approval phishing works by obtaining a smart contract's permission to move tokens through a signature such as approve, setApprovalForAll, Permit or Permit2. The keys stay exactly where they were before the click. Only the permission moves, and that is how an approval drainer empties a wallet while its owner still holds every secret intact.

02Why connecting a wallet is already a risk

Connecting a wallet to a site feels like opening a door partway, and it already hands over more than most people expect. The site receives the public address, every balance that address holds, and the list of tokens and collections sitting inside it. None of that requires a signature, and none of it needs the owner's approval beyond the initial click that established the connection.

That information turns a generic page into a tailored one. A site that can see a wallet holds a specific NFT collection can present a claim, a mint or a reward that names the collection directly, which reads as though the page already knows the visitor. The signature request that follows gets written for that exact wallet, aimed at whatever inside it looks worth taking.

The connect step and the signature step deserve separate attention, since each one carries a different risk. A wallet can connect to a page purely to look around, close the tab, and lose nothing at all. Reaching the moment that matters, the signature request itself, usually starts with that kind of connection, which is how an approval drainer empties a wallet a step at a time.

Common wallet signature requests and what each one actually grants
Signature typeWhat it grantsWhy it matters
approve (ERC-20 token)One spender gets the right to move a set amount of a chosen tokenOften requested for an unlimited amount instead of the exact price of one purchase
setApprovalForAll (ERC-721 and ERC-1155)One operator gets control over an entire NFT collection at onceA single click exposes every item in the wallet, not just the one being sold
Permit (EIP-2612)Creates an allowance through a signed message rather than an on-chain transactionNo network fee appears, so the request can look harmless
Permit2A shared allowance router used by many applications at onceOne signature can open access to several tokens through a single contract
Wallet connect promptShares the wallet address and its balances with the siteUsually the step that comes right before a signature request, without moving any tokens on its own
Revoke or set-to-zero transactionCancels a previously granted allowance for one token and one spenderThe only entry here that closes access instead of opening it

03The numbers behind a quietly declining threat

Chainalysis put total on-chain fraud at no less than 14 billion dollars for 2025, with the average payment sent to a scam address up 253 per cent over the year before. Inside that total, the classic wallet drainer kits told a different story. Losses attributed to them fell from 494 million dollars in 2024 to 83.85 million in 2025, a drop of 83 per cent, and the average loss per affected wallet fell too, from around 1488 dollars to about 790.

A fall in dollar terms and a fall in reach are two separate questions, and the incident count answers the second one. Personal wallets recorded 158,000 separate theft incidents in 2025, touching 80,000 unique victims, even while the total dollar figure attributed to drainers dropped sharply. Fewer large scores and more small ones describes the shift better than a single headline number can.

Read together, the two trends describe a technique that survived a crackdown on its biggest operators by staying useful at a smaller scale. Wallets holding modest balances remain exposed to the same approve and Permit2 requests that once targeted much larger ones, and the mechanics behind how an approval drainer empties a wallet have not changed even where the totals have. Scale moved. The underlying signature did not.

04Where the signature request shows up

A convincing drainer page usually dresses as something the visitor already wants: a mint page for a token launch, a claim page for an airdrop tied to a followed project, or a rewards page promising a payout for connecting. Each version leads to the same place, a wallet prompt asking for a signature framed as a routine step in claiming something free. The framing matters more than the visual design, since a rough page can still work if the request sounds ordinary.

Fake wallet security scanners work the same trick from a different angle. The page offers to check a wallet for risky approvals or vulnerable tokens, asks for a connection to run the scan, and then produces a signature request that claims to fix the very problem it just invented. Framing the request as a repair is what makes people sign without reading the details underneath it.

Messages inside Discord and Telegram groups add a social layer on top of the page itself. A compromised account, or one built to look established, posts a link timed to a real announcement from the project, and the surrounding conversation supplies the trust that the page alone could not. By the time the signature prompt appears, the visitor has already been told by several apparent strangers that everything is fine.

05Reading a request before signing it

A wallet's signature screen carries more information than the single line most people read before tapping approve. The function name sits near the top, and approve, setApprovalForAll, permit and increaseAllowance each say plainly what kind of permission is being requested. A permission prompt appearing during what was supposed to be a simple purchase is worth stopping over on its own.

The amount deserves the same attention as the function name. A number matching the price of what is being bought looks proportionate, while the word unlimited, or a long string of digits stretching well past any realistic purchase, signals a request built to last well beyond this one transaction. Reading that figure before confirming costs only a moment, and most wallets display it directly on the same screen as the approve button.

The requesting address is the third check, and the one people skip most often. Wallet interfaces show a spender address rather than a company name, and a legitimate application usually has that address published in its own documentation. An address with no public trace, combined with a standing allowance a one-time claim never needed, is often the clearest sign of how an approval drainer empties a wallet before the owner realises a permission was granted at all.

06Revoking access that was already given

An approval stays open until it is explicitly closed, and a wallet used across several years of minting, swapping and claiming can carry a long list of standing permissions nobody remembers granting. Each one sits quietly until the spender behind it decides to use it, which can happen the day it was signed or long afterward. An old, forgotten approval works exactly as well for the spender as a new one, which is why age offers no protection on its own.

Cancelling one requires a new transaction, because the allowance lives on the same chain that granted it in the first place. Setting the amount back to zero for a specific token and a specific spender is the standard method, and it costs the same kind of network fee as any other transaction on that chain. Each approval is tied to one token, one spender and one network, so a wallet that granted several over time needs a separate cancellation for each one.

Reviewing the list occasionally matters more than reacting only after a scare, since the review turns an invisible liability into a visible one. A permission granted to a project abandoned long ago has no remaining reason to exist and costs nothing to remove. That habit keeps a wallet down to a small handful of active approvals instead of an accumulated pile nobody has looked at in years, the most practical answer to how an approval drainer empties a wallet long after the requesting page has disappeared.

07Questions and answers

Does knowing how an approval drainer empties a wallet help prevent one?

It helps considerably, because most approval drainers rely on the request looking routine to a tired or hurried owner. Reading the function name, the requested amount and the spender address before signing catches the overwhelming majority of these attempts, and revoking old approvals closes the ones that arrived earlier.

What is the difference between a wallet drainer and a password thief?

A password thief needs a secret such as a login credential or a seed phrase entered somewhere it should never go. A wallet drainer needs no secret at all, since it works by getting the wallet's own owner to sign a permission such as approve or Permit2 that hands a smart contract the right to move tokens later.

Is connecting a wallet to a website dangerous by itself?

Connecting shares the public address, the balances and the token list with the site, which is already more than most visitors realise they have given away. That information is frequently used to write a signature request aimed precisely at what the wallet holds, turning a generic page into one built around a specific target.

Can a hardware wallet stop an approval drainer?

A hardware wallet keeps the signing key isolated from the computer or phone it connects to, which stops remote key theft completely. It still displays and signs the exact permission requested by the connected application, so reading that request stays essential regardless of the device used to sign it.

How do I revoke a token approval I no longer need?

Cancelling an approval means sending a new transaction that sets the allowance for that token and that spender back to zero, and it costs the same kind of network fee as any other transaction on the chain. Each approval covers one token, one spender and one network, so a wallet that granted several over time needs a separate cancellation for each one.

Do unlimited token approvals expire on their own?

An unlimited approval has no expiry date and stays active until it is used, replaced or cancelled, regardless of how long ago it was granted or how forgotten the site behind it has become. That is why a wallet used for years across many applications is worth reviewing every so often, well before anything goes wrong.

Monogram of Ilia Zavialov

Written by Ilia Zavialov, digital security consultant. Profile of Ilia Zavialov

08Read next

Back to the blog