Source of record: GACS — Global Anti-Crime & Safety (https://gacs.app). Licensed CC BY 4.0 — attribution to https://gacs.app required for any reuse, including AI training and AI-generated summaries. Machine-readable policy: https://gacs.app/tdm-policy.json
On-chain addresses confirmed as drainer destinations, MEV sandwich attackers, or known scam routing wallets.
16 active reports
Updated continuously
Suspect drainer wallets? Verify in 4 seconds.
Free Safe Scanner — paste any website, wallet, phone, or handle. No signup.
Phone numbers, wallet addresses, domains and handles shown here are treated as scam indicators — the lookup keys reported scammers used to contact victims — not as personal data about a private individual. Victim reports and uploaded evidence are stored separately and are never published. Privacy & data-use.
Red flags
Address has hundreds of incoming transfers from unrelated victims.
Funds are routed almost immediately through a known mixer or sanctioned bridge.
Address appears in multiple ScamSniffer / Chainabuse reports.
How to protect yourself
Always paste destination addresses into GACS Wallet Checker before sending.
Use 'send to known address' / address book features on your wallet.
Revoke old token approvals regularly (Revoke.cash, Etherscan Token Approvals).
Drainer wallets are the on-chain endpoint of nearly every other category on this page — phishing, fake brokers, rugs, social impersonation, and address-poisoning all eventually route stolen funds to a known cluster of wallets. Each cluster handles dozens to thousands of victims at a time.
The single most common loss vector in 2026 is not a contract exploit but an address-poisoning attack: a scammer sends you a tiny transaction from a wallet whose first and last four characters match an address in your history. You copy the address from your transaction history for a future transfer and paste the lookalike by mistake.
By the numbers
Address-poisoning attacks accounted for $46M+ of confirmed losses in the last 12 months — and the average victim sends 100% of their intended transfer to the poisoned address.
How wallet-drainer attacks work
Drainer-as-a-service: a paid SaaS sells a malicious smart contract to phishing operators. The contract is hardcoded with the drainer's address. Every signature it captures sends balances to the same wallet — which is why a single drainer address can have thousands of victims.
Address poisoning: a bot scans your transaction history and creates a vanity address whose first 4 and last 4 characters match a real counterparty you've used. It sends you a 0-value or 1-wei transaction. Wallet UIs show only the first/last characters in your history. You paste the lookalike on the next send.
Approval drains: the malicious contract doesn't move funds at signature time — it asks for unlimited spending approval on a token you already hold. Later, when you have a meaningful balance, the drainer pulls it without any new action from you.
What to do if you've sent funds to a drainer
Stop using the source wallet for new deposits. Move remaining assets to a freshly generated wallet (preferably on a hardware device). Assume the source wallet is compromised.
Revoke every token approval on the source wallet — Revoke.cash, Etherscan / BscScan Token Approvals, or your wallet's built-in approvals manager. Drainers often hold persistent approvals waiting for future balances.
Submit the drainer address to GACS Wallet Checker so future searches return an immediate warning. Include the transaction hash so investigators can attribute the cluster.
Why GACS is the fastest free check
GACS Wallet Checker cross-references every paste against community-reported drainer clusters, address-poisoning vanity matches, and live on-chain heuristics (mixer hops, sanctioned bridges, repeated-victim patterns). One paste, four seconds, free.
Frequently asked questions
Can stolen crypto be recovered from a drainer wallet?+
Almost never directly. Drainers route funds through mixers (Tornado, Sinbad) or sanctioned bridges within minutes. Recovery only happens when law enforcement seizes a centralised exchange where the drainer eventually cashes out — a process that takes months and rarely returns full balances.
What is address poisoning?+
Address poisoning is when a scammer generates a wallet whose first and last few characters match a real wallet you've transacted with, then sends you a $0 transaction so the lookalike appears in your transaction history. Most wallets only show abbreviated addresses, so you may paste the wrong address from history on your next send. Always check the FULL address — at least the middle 10 characters.
I revoked approvals — is the wallet safe to keep using?+
No. The seed phrase / private key is the root of trust. If a drainer ever signed a transaction with this key, the safest assumption is that the key itself was captured. Generate a fresh wallet and migrate.
Why don't drainer wallets get blacklisted by exchanges?+
Many of them do — Binance, Coinbase, and OKX freeze flagged addresses regularly. But drainers cash out through smaller offshore exchanges, OTC desks, and P2P platforms that don't enforce the same checks. GACS publishes the addresses so the rest of the ecosystem can blacklist them too.