Guides
Aug 8, 2026

Fake Wallet Scams in 2026: How to Spot a Drainer Before You Sign

Fake wallet apps, cloned extensions and drainer sites are the top crypto loss vector in 2026. How each variant works, the signals that give them away, and what to do if you signed.

Fake Wallet Scams in 2026: How to Spot a Drainer Before You Sign

Fake wallets have overtaken exchange hacks as the way ordinary users lose crypto. They are cheap to run, need no exploit, and rely entirely on the user doing something reasonable-looking at the wrong moment.

Five variants account for almost all of it.

1. Cloned mobile apps

An app in an official store, using the real wallet's name and icon, sometimes with hundreds of reviews. On first launch it asks you to "import your existing wallet" — and the phrase goes straight to the attacker.

Signals: recent publish date on an established brand, a developer name that is not the real company, review text that is generic and clustered on the same dates, and a download count far below what the brand should have.

Rule: get the store link from the wallet's official website, not from search. Store search results are bought and gamed.

2. Cloned browser extensions

Same idea in the extension stores, and harder to spot because extension listings carry less signal. Some clones function normally for days before exfiltrating keys, so "it worked fine" proves nothing.

Signals: publisher name mismatch, a permissions list broader than the real extension needs, and a store URL that does not match the one linked from the official site.

3. Drainer sites

No fake app at all. A website — an airdrop claim, a mint, a "migration" page — that connects to your real wallet and asks you to sign. The signature is not a transfer. It is an approval granting a contract permission to move your tokens, or a batched permit that does the same across several assets at once.

Your seed was never involved. One signature was enough.

Signals: urgency ("claim within 24 hours"), a request to sign something your wallet cannot decode, an approval for an unlimited amount, and a domain that is one character off the real one.

Mechanics in detail: wallet drainers and approval phishing.

4. Fake support

You post a problem in a public channel. Within minutes, someone helpful DMs you. They are attentive, technically fluent, and eventually direct you to a "validation" page or ask you to share your screen.

Rule: real support never initiates a DM, and never needs your seed phrase or remote access. Anyone who does either is an attacker, without exception.

5. Address poisoning

The attacker sends you a dust transaction from an address engineered to match the first and last characters of one you use regularly. Later you copy the address from your history — and hit the wrong one.

Rule: never copy an address from transaction history. Use a saved contact, and verify the middle characters, not just the ends.

This is not theoretical — vanity-generated lookalike addresses matching both ends of a target address are now routinely produced at scale.

The five-second check before any signature

  1. Does the wallet show what the transaction does? If it shows an undecodable blob, stop.
  2. Is it an approval? If so, for what amount? Unlimited is almost never necessary.
  3. Which contract is being approved? Does it match the site you are on?
  4. Did you initiate this, or did something prompt you? Unprompted urgency is the tell.
  5. Would losing this wallet's full balance be survivable? If not, you should not be signing from it — use a burner.

If you already signed

Move quickly and in this order:

  1. Move remaining assets out first. Do not revoke first — revoking is a transaction that takes time, and drainers often run bots watching for exactly that.
  2. Send to a fresh wallet generated on a clean device, not one you have connected to anything.
  3. Then revoke approvals on the compromised address.
  4. Treat the compromised wallet as permanently burned. If the seed was exposed, it is exposed forever — there is no way to un-leak a private key. Never reuse it, even after revoking.
  5. Do not pay a recovery service. Almost all are second-stage scams. See crypto recovery scams.

One thing worth understanding: if only an approval was signed, the attacker can move approved tokens but not the wallet itself. If the seed was entered, everything derived from it is gone, including addresses on other chains. The two situations need different responses.

Reducing the blast radius

The structural fix is not vigilance — it is compartmentalisation. Separate cold storage, a small hot wallet, and a burner for anything unfamiliar means a bad signature costs you a bounded amount.

Setup guidance in best self-custody wallets and the self-custody guide. The broader scam landscape is in crypto scams in 2026, and if you are moving off an exchange after a closure, crypto exchanges shutting down covers doing that safely.

About the author.

Co-Founder at JewelSwap & CMO at iDenfy. Viktor brings his successful track record of superb development & project management.