Back to glossary

Wallet Drainer

Moderate

A malicious smart contract or script that, once granted a token approval or a signed permit, transfers all fungible and non-fungible tokens from a victim's wallet in a single transaction. Drainers are deployed as fake mint pages, phishing DApps, or compromised front-ends. SSP's 2-of-2 requirement means a drainer needs both devices to sign an approval; a single device interaction is insufficient.