Wallet Drainer Attack
š Key Takeaway: Wallet drainers abuse approvals, signatures, and account upgradesānot always seed phrases. Identify the drainer type first; recovery steps differ for approvals versus full key control.
If youāve been sent this document, then we believe that your funds have been stolen by a wallet drainer. This document will give you some information about drainers, how they work, and how you can protect yourself going forward.
In general, when we refer to a drainer, weāre referring to one of a small number of popular drainer software available. A drainer customer (or āaffiliateā) will purchase access to the drainer software from the drainer developer. From there, the affiliate will upload it to phishing websites and promote it via social media, such as Twitter. You can think of drainers like how a franchised restaurant owner will buy the rights to use the logo from the corporation and then pay royalties for every sale.

Drainers use a variety of different tactics to gain control over your wallet and tokens. For example, drainers have been known to:
- Request approval to spend your tokens directly
- Request signatures to buy your tokens via a DEX that youāve already approved
- Request permission to upgrade your wallet to a 7702 wallet, which gives them full control
- Request your private key or seed phrase directly, which gives them full control
Depending on which type of drainer affected you, you might need to take different actions to recover control of your wallet.
Further reading
- Playbooks overview: how the playbooks in this section fit together
- Smart Contract Interaction Security: approvals and signing hygiene that prevent this
- Understanding Threat Vectors: how drainer lures reach users
- SEAL 911 War Room Guidelines: reaching outside help fast