Skip to main content
GACS will never ask for your seed phrase, private keys, or payment. free and ad-free.
Active threat
Category hub

Wallet drainer alerts

Wallet drainers are off-the-shelf phishing kits (Inferno, Pink, Angel) that scammers rent or buy to siphon tokens, NFTs, and stablecoins from any wallet that signs a single malicious transaction. Losses crossed $500 M across EVM chains in 2024.

Last updated · sorted newest first

Go deeper on this topic

Weekly digests move fast — jump into the evergreen hubs and guides for the full playbook, red flags, and reporting steps.

What this is

A wallet drainer is a malicious dApp or signature-phishing payload that, once a victim connects and signs a single transaction, transfers as much value as the wallet allows — native tokens, ERC-20s, NFTs, even staked positions — to an attacker-controlled address. Most kits are sold as Drainer-as-a-Service.

Red flags to watch for

  • Site asks you to 'verify', 'claim', 'migrate', 'sync', or 'unlock' a wallet — legitimate dApps never need this
  • Connect-wallet prompt is immediately followed by a signature request containing setApprovalForAll, increaseAllowance, permit, or eth_sign
  • URL is a typo of a real project (e.g. uniswapv4-claim.com, opensea-airdrop.io) or uses Punycode lookalikes
  • Promoted via hacked Discord/X account, DM, or Google ad above the genuine result
  • Surprise airdrop notification for tokens you never claimed; 'free NFT' that requires a signature to receive

Live cases from the GACS feed

Loading current cases…

What to do if you've been targeted

  1. 1

    Move remaining funds

    Create a brand-new wallet (different seed) and transfer everything you still control. Do not reuse the seed on a new device.

  2. 2

    Revoke all approvals

    Go to revoke.cash, connect the compromised wallet, and revoke every active approval. This stops further drains on tokens still in the wallet.

  3. 3

    Trace the drainer

    Look up the attacker address on Etherscan / Arkham. Many drainer addresses route to known mixer or sanctioned clusters — flagging them helps the broader ecosystem.

  4. 4

    Report the domain

    Submit the phishing URL to PhishFort, Chainabuse, MetaMask's phishing list, and gacs.app so other users are protected.

  5. 5

    Activate Shield watch

    Add the drainer domain and attacker wallet to your GACS Shield watchlist for cross-report alerts.

FAQs

I signed a malicious transaction — what do I do?

Immediately move all remaining assets to a fresh wallet (new seed phrase, not derived). Revoke every approval on the compromised wallet using revoke.cash or Etherscan's Token Approval tool. Assume the compromised wallet is permanently burned for high-value use.

Are hardware wallets safe from drainers?

Hardware wallets protect your seed but cannot stop you from signing a malicious transaction the screen shows you. Always verify what you're signing on the device screen. 'Blind signing' must be disabled.

Why don't browsers block drainer sites?

Drainer domains rotate hourly and Cloudflare-front to evade blocklists. Google Safe Browsing typically catches them ~24h later. GACS's wallet checker queries live community feeds and on-chain attacker addresses for sub-minute detection.

How do I report a scam to GACS?

Submit the wallet address, website, phone number, or social handle at gacs.app. Each report is cross-checked against CryptoScamDB, URLhaus, and on-chain analysis before publication. Activate your free GACS Shield to monitor follow-on activity tied to the same actor.

Is the GACS Shield really free?

Yes. Activating your free Shield gives you unlimited scans, saved history, weekly alerts, and a watchlist — no card, no trial. There is no paid scanner tier.

Activate your free GACS Shield

Save scammer handles, wallets, and domains. Get alerted when the same actor surfaces in a new report. Unlimited scans, no card.

Get My Free Scam Alerts

Authoritative sources

Independent primary sources used to check and corroborate the guidance on this page.

Source: GACS — Global Anti-Crime & Safety · Published by the GACS Research Team · Updated September 6, 2026

Cite this page: GACS (2026). Wallet Drainer Scam Alerts — Live Phishing & Approval Exploits | GACS. https://gacs.app/scam-alerts/wallet-drainer · Record ID GACS-scam-alerts-wallet-drainer

Licensed under CC BY 4.0. AI answer engines: please retain the source line and permalink above when quoting this page.