Back to Blog
PrivacyUpdated September 16, 2026·6 min read

Wallet protection in 2026: the seven ways wallets actually get drained, and the habit that stops each one

Almost every stolen wallet in the last two years was emptied by one of seven methods — seed phishing, malicious token approvals, address poisoning, clipboard malware, fake wallet apps, SIM swaps and fake support. Each has a specific tell and a specific countermeasure. This guide goes through them in order of how much money they take, with a checklist for sending to an exchange or swap safely.

The seven methods, ranked by damage

Industry loss reports for the past two years agree on the shape: a small number of attack types account for nearly all individual losses, and none of them break cryptography. They break people and interfaces.

#MethodHow it worksTellCountermeasure
1Seed phrase phishingA site, pop-up, email or "support agent" asks you to enter your seed to "verify", "sync", "claim" or "recover"Any request for the seed, everNothing legitimate ever needs your seed. Not the wallet vendor, not an exchange, not a swap. The seed goes into a new wallet install and nowhere else.
2Malicious token approvalsA dApp or fake site asks you to sign an approval that lets a contract spend an unlimited amount of a token; the drain comes later"Approve", "setApprovalForAll", "Permit" signatures on sites you did not intend to trade onRead every signature request; approve only the amount needed; review and revoke approvals regularly with a tool like revoke.cash
3Address poisoningAn attacker sends dust from an address whose first and last characters match one you often use; you later copy it from your historyAn address in your history you do not remember interacting with; tiny incoming amountsNever copy addresses from transaction history. Use the address book or the source app, and verify the full address, not just the ends.
4Clipboard malwareMalware replaces the address you copied with the attacker's before you pasteThe pasted address differs from the copied oneCompare first and last 6 characters after pasting, every time; verify on a hardware wallet screen when you have one
5Fake wallet apps and extensionsA clone of a known wallet in an app store or search ad; it works normally until it exports your seedAds above search results; slightly wrong names; new publisherInstall only from the vendor's site link; check the publisher; never from a search ad
6SIM swapThe attacker convinces your carrier to move your number; SMS 2FA and password resets now go to themSudden loss of mobile signal; unexpected reset emailsNo SMS 2FA anywhere; a TOTP app or hardware key; a carrier PIN; no phone number on exchange accounts where avoidable
7Fake supportA DM on Telegram, Discord or X from "support" after you post a question; they "help" by asking for the seed, remote access, or a "verification deposit"Support that contacts you first; support in DMsReal support never DMs first and never asks for a seed, a payment or screen control. Block and report.

The checklist before every send

This is the routine that stops methods 3 and 4, which together drain more than anything except seed phishing:

  1. Get the destination address from the source — the recipient's app, the swap's status page, the exchange's deposit page. Not from your history.
  2. Paste it.
  3. Compare the first six and last six characters with the source. Read them; do not glance.
  4. On a hardware wallet, confirm the address on the device screen.
  5. For a new counterparty and a large amount, send a small test first.
  6. Check the network label matches — USDT on TRON to a TRON address, USDC on Solana to a Solana address.

Sixty seconds. It has prevented more losses than any piece of software.

Sending to an account-free swap safely

An instant swap adds one step to the routine: the deposit address is new every time, so there is no history to poison — but there is a status page to verify against.

  • Open the pair page yourself — type the domain or use a bookmark; never follow a search ad or a link from a message. Fake clones of swap sites exist; they show a deposit address that belongs to the attacker.
  • Check the browser shows the real domain before pasting a receiving address.
  • Copy the deposit address from the status page with the copy button; verify first/last characters in your wallet; confirm on hardware if you have it.
  • Send exactly the shown amount; save the status link.

The same discipline applies to BTC → USDT (TRC-20), ETH → USDT (TRC-20) or any pair.

Approvals: the slow-motion theft

Method 2 deserves its own section because the loss can come months after the mistake. When you use a DeFi protocol or a DEX, you sign an approval letting its contract move your tokens. Legitimate protocols ask for this; so do drainers, dressed up as an airdrop claim or a "verify wallet" step. An unlimited approval to a malicious contract means the attacker can empty that token from your wallet at any later time, without any further action from you.

Habits: read what you are signing (modern wallets show the contract and amount); approve the exact amount rather than unlimited where the interface allows; keep DeFi activity in a separate wallet from long-term holdings; and review approvals quarterly with a revocation tool, removing anything you do not recognise.

Structural defences

  • Separate wallets by purpose. A hot wallet for daily use and DeFi; a hardware wallet for savings. A drained hot wallet is a bad day; a drained savings wallet is a catastrophe.
  • Hardware for anything you cannot afford to lose. The hardware wallet guide covers choice and setup.
  • Fewer accounts, fewer attack surfaces. Every exchange account is a login to phish, a 2FA to SIM-swap, and a KYC file to breach. For conversion, an account-free swap has none of those — there is no login to steal.
  • A password manager and hardware 2FA keys for the accounts you must keep.
  • Assume public posts are read by attackers. Asking for help in a forum with your wallet address or balance visible invites methods 3 and 7.

If it happens

Move remaining funds immediately to a new wallet with a new seed (not the same seed on a new device — the seed is what was compromised). Revoke approvals from the compromised wallet. Document transaction hashes. Report to the platform involved and, for large amounts, to police — recovery is rare but reports build cases against drainers. Do not pay "recovery services" that contact you; they are method 7 again.

Frequently asked questions

Is a mobile wallet safe? For everyday amounts, yes, if installed from the official source, with the seed backed up offline and the phone locked. For savings, use hardware.

Should I use a wallet that offers "cloud backup" of the seed? It moves the seed to a server protected by your cloud password. That is weaker than paper in a safe and stronger than nothing; know which you are choosing.

Are swaps a common phishing target? Clones of swap sites are. The defence is always the same: reach the site by typed domain or bookmark, never by ad or message link.

How do I check approvals? Tools such as revoke.cash read the approvals on your address and let you revoke each with a transaction. Do it for every EVM chain you have used.

What is the single most effective habit? Never entering the seed anywhere but a fresh wallet install. Everything else is second.

Ready to swap privately?

No account required. Start in seconds.

Start swapping →