Wallet Drainer Checker: Test Any Site Before You Connect
Free wallet drainer checker guide — how to test a site before you connect, what a drainer kit actually asks you to sign, the five checks that expose one in under three minutes, and how to revoke an approval you already signed.
You Never Sent a Thing. The Wallet Still Emptied.
A drainer only needs one signature — and it never looks like a payment.
What this guide says in 5 lines
- A drainer never asks for a payment — it asks for a signature that grants spending permission.
- Native coin first, then stablecoins: that drain order means an approval fired.
- "Unlimited" approval to an unknown contract is the single most dangerous thing you can sign.
- A wallet will happily show you the request without explaining whether the contract is trustworthy.
- Connect with a burner wallet holding pocket change, and revoke approvals monthly.
A wallet drainer is the most efficient theft tool in crypto. It does not need your password, your seed phrase or your cooperation beyond one click, and the click looks like a routine connection to a site you were invited to by someone you trust. This guide is the checker: what a drainer actually asks for, how to test a site before you connect, how to tell after the fact whether you already signed one, and how to defuse an approval that is sitting there waiting.
What a drainer asks you to sign — and why it looks harmless
Every drainer works through a standard wallet interface element: a request to sign. Wallets are designed to make signing frictionless, because that is what makes them usable. The interface shows a contract address, sometimes a function name, and a confirmation button. It almost never shows an explanation.
The consequence is that the risk is not in the wallet, which is functioning correctly, and not in the signature mechanics. It is in the identity of the contract — and nothing in the popup tells you whether the contract you are about to authorise is a legitimate protocol or a two-day-old address controlled by a thief.
A wallet popup is a disclosure of what you are signing, not a safety assessment of who you are signing with. Treating the popup as a green light is the entire attack.
The five checks that expose a drainer in three minutes
Run all five on any site before you connect a wallet holding real value. Together they take under three minutes and defeat the overwhelming majority of drainer kits, because drainer kits share infrastructure and every one of these checks looks at that infrastructure from the outside.
| # | Check | How to run it | Fail signal |
|---|---|---|---|
| 1 | How you arrived | Ask where the link came from | A DM, a comment, a sponsored post or a search ad — never a link you sought out |
| 2 | Domain age and spelling | WHOIS on the exact domain | Registered days or weeks ago, or a lookalike of a real protocol |
| 3 | Contract address identity | Search the contract on the chain explorer | No history, no verified source, brand new, or interacts only with wallets it drains |
| 4 | What the signature requests | Read the request detail before confirming | An "unlimited" allowance, a permit, or a value approval you cannot explain |
| 5 | Independent listing | Search the protocol on a site you did not reach from their link | Nothing outside their own pages, or warnings from researchers |
The signature patterns that should stop you cold
Four request shapes cause almost all drainer losses. If the popup contains any of these and you did not deliberately come to the protocol to do exactly this, decline and close the tab.
The first two are the ones people sign most often, because both arrive wrapped in language about staking, rewards or migration.
- 01An unlimited token allowance to a contract you do not recognise — this grants permanent permission to move that token, for as long as the approval exists.
- 02A permit or signature request where the amount field is blank or says "max" — you are authorising an open-ended transfer.
- 03A request to sign a plain message with no transaction attached, on a site whose only purpose is supposed to be a swap — the message may itself be an authorisation.
- 04A "migration", "validation", "sync" or "wallet restore" screen. No legitimate protocol ever needs a signature to fix an error.
The safe habit costs nothing: keep a separate hot wallet with pocket change for new or unfamiliar sites, and never let a wallet holding real value touch a page you have not verified.
After the fact: did I already sign one?
If funds are already gone and you never sent anything, the answer is almost certainly yes. This is the signature to look for, and the sequence that follows it tells you exactly which mechanism was used.
Notice that the drain order in the chart below is not random: native coin funds the fees, stablecoins carry the value, and contract permissions are read in the order the kit was configured to use them.
What victims report finding after a drainer fire
Share of drainer victims reporting each finding in the first hour
Reading: The last row is the important one. In the large majority of drainer cases no seed phrase was ever shared — which is why "I would never give anyone my seed phrase" provides no protection against this attack at all.
Defusing an approval you already signed
An active approval is a standing instruction that survives closing your browser, restarting your computer and forgetting the site existed. It is also reversible, which makes this the most valuable five minutes in crypto hygiene.
Do it from a device you trust, and do it on every chain you have used — approvals are per-chain and do not carry over.
- 01Open a token-approval checker for your address and list every active approval, on every chain you have transacted on.
- 02Revoke anything you cannot name the owner of. You do not need to be certain it is malicious; if you cannot explain it, revoke it.
- 03Revoke unlimited allowances even to services you recognise — a legitimate service can simply be asked again next time you use it.
- 04Disconnect the site from your wallet inside the wallet interface as well as revoking on-chain; they are different controls.
- 05Repeat monthly, or before any period where you will be interacting with new protocols.
Revoking is free apart from network fees, and it can only reduce your exposure. There is no scenario in which a dormant approval you do not need is working in your favour.
Common questions
See what an address has left behind
Run the address through the tracer to see outgoing flows, hop destinations and whether the funds reached somewhere a freeze request could still land.
Primary sources and further reading
- FTC — Crypto Scams Consumer Advice consumer.ftc.gov
- Chainalysis — Approvals and Drainer Analysis www.chainalysis.com
- IC3 — Digital Currency Fraud Reporting www.ic3.gov
External links open in a new tab and are provided so you can verify the underlying material yourself. TrueMoneyTalk is not affiliated with these organisations.
Keep reading
Someone you know may be in this situation right now.
Disclaimer: this guide is general information, not legal, financial or recovery advice, and it is not a substitute for advice from a licensed professional in your jurisdiction. Individual outcomes vary and are never guaranteed.