Public blockchain data only — we never ask for seed phrases, private keys or upfront fees.
No wallet data stored Runs in your browser
All 20 guides
Basics 2026-09-22 · 4 min read

Wallet Drainer Checker: Test Any Site Before You Connect

Free wallet drainer checker guide — how to test a site before you connect, what a drainer kit actually asks you to sign, the five checks that expose one in under three minutes, and how to revoke an approval you already signed.

Wallet Drainer Checker: Test Any Site Before You Connect — illustrated hook

You Never Sent a Thing. The Wallet Still Emptied.

A drainer only needs one signature — and it never looks like a payment.

Safety note: we never guarantee recovery and never ask for seed phrases, private keys, crypto payments or upfront unlocking fees. Anyone who does is running a second scam.
The short version

What this guide says in 5 lines

  • A drainer never asks for a payment — it asks for a signature that grants spending permission.
  • Native coin first, then stablecoins: that drain order means an approval fired.
  • "Unlimited" approval to an unknown contract is the single most dangerous thing you can sign.
  • A wallet will happily show you the request without explaining whether the contract is trustworthy.
  • Connect with a burner wallet holding pocket change, and revoke approvals monthly.

A wallet drainer is the most efficient theft tool in crypto. It does not need your password, your seed phrase or your cooperation beyond one click, and the click looks like a routine connection to a site you were invited to by someone you trust. This guide is the checker: what a drainer actually asks for, how to test a site before you connect, how to tell after the fact whether you already signed one, and how to defuse an approval that is sitting there waiting.

What a drainer asks you to sign — and why it looks harmless

Every drainer works through a standard wallet interface element: a request to sign. Wallets are designed to make signing frictionless, because that is what makes them usable. The interface shows a contract address, sometimes a function name, and a confirmation button. It almost never shows an explanation.

The consequence is that the risk is not in the wallet, which is functioning correctly, and not in the signature mechanics. It is in the identity of the contract — and nothing in the popup tells you whether the contract you are about to authorise is a legitimate protocol or a two-day-old address controlled by a thief.

A wallet popup is a disclosure of what you are signing, not a safety assessment of who you are signing with. Treating the popup as a green light is the entire attack.

The five checks that expose a drainer in three minutes

Run all five on any site before you connect a wallet holding real value. Together they take under three minutes and defeat the overwhelming majority of drainer kits, because drainer kits share infrastructure and every one of these checks looks at that infrastructure from the outside.

Pre-connection drainer checks and the failure signal for each
#CheckHow to run itFail signal
1How you arrivedAsk where the link came fromA DM, a comment, a sponsored post or a search ad — never a link you sought out
2Domain age and spellingWHOIS on the exact domainRegistered days or weeks ago, or a lookalike of a real protocol
3Contract address identitySearch the contract on the chain explorerNo history, no verified source, brand new, or interacts only with wallets it drains
4What the signature requestsRead the request detail before confirmingAn "unlimited" allowance, a permit, or a value approval you cannot explain
5Independent listingSearch the protocol on a site you did not reach from their linkNothing outside their own pages, or warnings from researchers
Pre-connection drainer checks and the failure signal for each

The signature patterns that should stop you cold

Four request shapes cause almost all drainer losses. If the popup contains any of these and you did not deliberately come to the protocol to do exactly this, decline and close the tab.

The first two are the ones people sign most often, because both arrive wrapped in language about staking, rewards or migration.

  • 01An unlimited token allowance to a contract you do not recognise — this grants permanent permission to move that token, for as long as the approval exists.
  • 02A permit or signature request where the amount field is blank or says "max" — you are authorising an open-ended transfer.
  • 03A request to sign a plain message with no transaction attached, on a site whose only purpose is supposed to be a swap — the message may itself be an authorisation.
  • 04A "migration", "validation", "sync" or "wallet restore" screen. No legitimate protocol ever needs a signature to fix an error.

The safe habit costs nothing: keep a separate hot wallet with pocket change for new or unfamiliar sites, and never let a wallet holding real value touch a page you have not verified.

After the fact: did I already sign one?

If funds are already gone and you never sent anything, the answer is almost certainly yes. This is the signature to look for, and the sequence that follows it tells you exactly which mechanism was used.

Notice that the drain order in the chart below is not random: native coin funds the fees, stablecoins carry the value, and contract permissions are read in the order the kit was configured to use them.

Data

What victims report finding after a drainer fire

Share of drainer victims reporting each finding in the first hour

No outgoing transfer in wallet history 74
One unexplained signature or approval 68
Native balance emptied first 59
Stablecoins gone with tokens 44
Unsolicited token received days earlier 21
Seed phrase shared with anyone 9

Reading: The last row is the important one. In the large majority of drainer cases no seed phrase was ever shared — which is why "I would never give anyone my seed phrase" provides no protection against this attack at all.

Defusing an approval you already signed

An active approval is a standing instruction that survives closing your browser, restarting your computer and forgetting the site existed. It is also reversible, which makes this the most valuable five minutes in crypto hygiene.

Do it from a device you trust, and do it on every chain you have used — approvals are per-chain and do not carry over.

  • 01Open a token-approval checker for your address and list every active approval, on every chain you have transacted on.
  • 02Revoke anything you cannot name the owner of. You do not need to be certain it is malicious; if you cannot explain it, revoke it.
  • 03Revoke unlimited allowances even to services you recognise — a legitimate service can simply be asked again next time you use it.
  • 04Disconnect the site from your wallet inside the wallet interface as well as revoking on-chain; they are different controls.
  • 05Repeat monthly, or before any period where you will be interacting with new protocols.

Revoking is free apart from network fees, and it can only reduce your exposure. There is no scenario in which a dormant approval you do not need is working in your favour.

Supporting infographic for Wallet Drainer Checker: Test Any Site Before You Connect
Wallet Drainer Checker: Test Any Site Before You Connect — supporting infographic

Common questions

Yes — every check in this guide is free and needs no account. Approval checkers and block explorers are public tools. What none of them can do is tell you that a contract is safe; they can only show you what permission you have granted, which is what you actually need to decide.
An approval covers the specific asset and amount you authorised, so a single approval usually takes one token. Kits ask for several approvals in sequence to cover native coin, stablecoins and the main tokens, which is why the loss often looks like a partial then total emptying.
No. A hardware wallet faithfully signs whatever you approve — it protects the key, not your judgement. It does make the approval request harder to click through carelessly, which helps in practice, but the exploit itself works the same way.
Next step

See what an address has left behind

Run the address through the tracer to see outgoing flows, hop destinations and whether the funds reached somewhere a freeze request could still land.

Primary sources and further reading

External links open in a new tab and are provided so you can verify the underlying material yourself. TrueMoneyTalk is not affiliated with these organisations.

Keep reading

Share this guide

Someone you know may be in this situation right now.

Disclaimer: this guide is general information, not legal, financial or recovery advice, and it is not a substitute for advice from a licensed professional in your jurisdiction. Individual outcomes vary and are never guaranteed.