Guides
Aug 25, 2026

Fake Wallet Scams in 2026: How to Spot a Drainer Before You Sign

Fake wallet apps, cloned extensions and drainer sites are the top crypto loss vector in 2026. How each variant works, the signals that give them away, and what to do if you signed.

Fake Wallet Scams in 2026: How to Spot a Drainer Before You Sign

Fake wallets have overtaken exchange hacks as the way ordinary users lose crypto. They are cheap to run, need no exploit, and rely entirely on the user doing something reasonable-looking at the wrong moment.

Five variants account for almost all of it.

1. Cloned mobile apps

An app in an official store, using the real wallet's name and icon, sometimes with hundreds of reviews. On first launch it asks you to "import your existing wallet" — and the phrase goes straight to the attacker.

Signals: recent publish date on an established brand, a developer name that is not the real company, review text that is generic and clustered on the same dates, and a download count far below what the brand should have.

Rule: get the store link from the wallet's official website, not from search. Store search results are bought and gamed.

2. Cloned browser extensions

Same idea in the extension stores, and harder to spot because extension listings carry less signal. Some clones function normally for days before exfiltrating keys, so "it worked fine" proves nothing.

Signals: publisher name mismatch, a permissions list broader than the real extension needs, and a store URL that does not match the one linked from the official site.

3. Drainer sites

No fake app at all. A website — an airdrop claim, a mint, a "migration" page — that connects to your real wallet and asks you to sign. The signature is not a transfer. It is an approval granting a contract permission to move your tokens, or a batched permit that does the same across several assets at once.

Your seed was never involved. One signature was enough.

Signals: urgency ("claim within 24 hours"), a request to sign something your wallet cannot decode, an approval for an unlimited amount, and a domain that is one character off the real one.

Mechanics in detail: wallet drainers and approval phishing.

4. Fake support

You post a problem in a public channel. Within minutes, someone helpful DMs you. They are attentive, technically fluent, and eventually direct you to a "validation" page or ask you to share your screen.

Rule: real support never initiates a DM, and never needs your seed phrase or remote access. Anyone who does either is an attacker, without exception.

5. Address poisoning

The attacker sends you a dust transaction from an address engineered to match the first and last characters of one you use regularly. Later you copy the address from your history — and hit the wrong one.

Rule: never copy an address from transaction history. Use a saved contact, and verify the middle characters, not just the ends.

This is not theoretical — vanity-generated lookalike addresses matching both ends of a target address are now routinely produced at scale.

What you are actually signing when a drainer succeeds

Almost every drain comes down to an approval the user granted deliberately, believing it was something else. Understanding the four signature types makes the danger legible at the moment it matters.

  • Token approvals. Granting a contract permission to move a token on your behalf, frequently for an unlimited amount. It persists until revoked, which is why a site visited once can drain a wallet months later.
  • NFT collection approvals. A single approval that covers an entire collection rather than one item. Requested by every legitimate marketplace, which is exactly why it does not look alarming.
  • Off-chain permit signatures. A gasless signature granting spending rights. It costs nothing, produces no pending transaction, and looks harmless precisely because no gas is involved — the most dangerous variant for that reason.
  • Blind signatures. A raw hash with no human-readable decoding. If your wallet cannot tell you what a signature does, you cannot consent to it.

The pattern to internalise: a transfer moves funds once, an approval grants standing permission. Drainers overwhelmingly want the second.

The five-second check before any signature

  1. Does the wallet show what the transaction does? If it shows an undecodable blob, stop.
  2. Is it an approval? If so, for what amount? Unlimited is almost never necessary.
  3. Which contract is being approved? Does it match the site you are on?
  4. Did you initiate this, or did something prompt you? Unprompted urgency is the tell.
  5. Would losing this wallet's full balance be survivable? If not, you should not be signing from it — use a burner.

Revoking approvals properly

Revocation is a transaction, so it costs gas and must be done per token, per chain, on the chain where the approval was granted. Revoking on one network does nothing for the same wallet's exposure elsewhere.

A sensible cadence: review approvals quarterly, immediately after interacting with an unfamiliar contract, and immediately if you suspect a bad signature. Revoke unlimited approvals on anything you no longer use, and prefer setting a finite allowance where the interface offers it.

If you already signed

Move quickly and in this order:

  1. Move remaining assets out first. Do not revoke first — revoking is a transaction that takes time, and drainers often run bots watching for exactly that.
  2. Send to a fresh wallet generated on a clean device, not one you have connected to anything.
  3. Then revoke approvals on the compromised address.
  4. Treat the compromised wallet as permanently burned. If the seed was exposed, it is exposed forever — there is no way to un-leak a private key. Never reuse it, even after revoking.
  5. Do not pay a recovery service. Almost all are second-stage scams. See crypto recovery scams.

One thing worth understanding: if only an approval was signed, the attacker can move approved tokens but not the wallet itself. If the seed was entered, everything derived from it is gone, including addresses on other chains. The two situations need different responses.

The second wave: recovery scams

Publicly reporting a loss makes you a qualified lead for the follow-on fraud. Within hours of a visible drain, victims are approached by accounts offering blockchain forensics, "whitehat" recovery, or a fixer with exchange contacts.

The tells are consistent: an upfront fee, a request for your seed phrase to "trace" funds, a guarantee of recovery, or a demand for a small "gas deposit" to release a larger sum. No legitimate service asks for a seed phrase, and none can reverse a settled on-chain transfer — the ledger does not have an undo.

Reducing the blast radius

The structural fix is not vigilance — it is compartmentalisation. Separate cold storage, a small hot wallet, and a burner for anything unfamiliar means a bad signature costs you a bounded amount.

Setup guidance in best self-custody wallets and the self-custody guide. The broader scam landscape is in crypto scams in 2026, and if you are moving off an exchange after a closure, crypto exchanges shutting down covers doing that safely.

Frequently asked questions

How can I tell a fake wallet app from the real one?

Install only from the link on the project's own verified site rather than searching the app store, where cloned listings with plausible review counts are routine. Check the developer name against the official one, and treat any wallet that asks you to import a seed phrase on first launch to "verify" or "sync" as hostile — legitimate wallets never require this to open.

Is a signature request safe if it does not cost gas?

No, and that is the most common misconception behind large losses. Off-chain permit signatures are gasless and grant spending rights immediately. The absence of a gas fee means no transaction is pending, not that nothing was authorised.

What should I do the moment I realise I signed something malicious?

Move remaining assets to a fresh wallet first if the drain is still in progress, because revocation itself can be front-run. Then revoke the approval, on the chain where it was granted. Then stop using the compromised wallet for anything of value — a wallet that has signed a malicious approval should be considered permanently untrusted.

Can drained funds be recovered?

Almost never. Settled transfers are final, and no service can reverse them. If funds reach a centralised exchange, a law-enforcement report can occasionally result in a freeze, but that depends on the exchange and the jurisdiction and is not something a paid recovery service can promise or deliver.

Does a hardware wallet prevent this?

It prevents key extraction, not bad approvals. If you approve a malicious contract on a hardware wallet, the drain proceeds exactly the same way — the signature was valid and you provided it. Hardware helps because it forces you to confirm on a separate screen, which is only protective if you read what that screen says.

What is address poisoning?

An attacker sends a zero-value transfer from an address whose first and last characters match one you have used, so it appears in your history. Later you copy the address from that history and send funds to the attacker. The defence is never copying from transaction history — use a saved address book and verify the middle characters, not just the ends.

About the author.

Co-Founder at JewelSwap & CMO at iDenfy. Viktor brings his successful track record of superb development & project management.