Fake wallet apps, cloned extensions and drainer sites are the top crypto loss vector in 2026. How each variant works, the signals that give them away, and what to do if you signed.

Fake wallets have overtaken exchange hacks as the way ordinary users lose crypto. They are cheap to run, need no exploit, and rely entirely on the user doing something reasonable-looking at the wrong moment.
Five variants account for almost all of it.
An app in an official store, using the real wallet's name and icon, sometimes with hundreds of reviews. On first launch it asks you to "import your existing wallet" — and the phrase goes straight to the attacker.
Signals: recent publish date on an established brand, a developer name that is not the real company, review text that is generic and clustered on the same dates, and a download count far below what the brand should have.
Rule: get the store link from the wallet's official website, not from search. Store search results are bought and gamed.
Same idea in the extension stores, and harder to spot because extension listings carry less signal. Some clones function normally for days before exfiltrating keys, so "it worked fine" proves nothing.
Signals: publisher name mismatch, a permissions list broader than the real extension needs, and a store URL that does not match the one linked from the official site.
No fake app at all. A website — an airdrop claim, a mint, a "migration" page — that connects to your real wallet and asks you to sign. The signature is not a transfer. It is an approval granting a contract permission to move your tokens, or a batched permit that does the same across several assets at once.
Your seed was never involved. One signature was enough.
Signals: urgency ("claim within 24 hours"), a request to sign something your wallet cannot decode, an approval for an unlimited amount, and a domain that is one character off the real one.
Mechanics in detail: wallet drainers and approval phishing.
You post a problem in a public channel. Within minutes, someone helpful DMs you. They are attentive, technically fluent, and eventually direct you to a "validation" page or ask you to share your screen.
Rule: real support never initiates a DM, and never needs your seed phrase or remote access. Anyone who does either is an attacker, without exception.
The attacker sends you a dust transaction from an address engineered to match the first and last characters of one you use regularly. Later you copy the address from your history — and hit the wrong one.
Rule: never copy an address from transaction history. Use a saved contact, and verify the middle characters, not just the ends.
This is not theoretical — vanity-generated lookalike addresses matching both ends of a target address are now routinely produced at scale.
Move quickly and in this order:
One thing worth understanding: if only an approval was signed, the attacker can move approved tokens but not the wallet itself. If the seed was entered, everything derived from it is gone, including addresses on other chains. The two situations need different responses.
The structural fix is not vigilance — it is compartmentalisation. Separate cold storage, a small hot wallet, and a burner for anything unfamiliar means a bad signature costs you a bounded amount.
Setup guidance in best self-custody wallets and the self-custody guide. The broader scam landscape is in crypto scams in 2026, and if you are moving off an exchange after a closure, crypto exchanges shutting down covers doing that safely.