Cryptocurrency Phishing and Wallet Drainers
3 min read · Last updated
Phishing in the digital-asset context rarely steals a password. It obtains a signature — an approval or transfer authorisation granted by the victim's own wallet.
That distinction shapes both the attack and the investigation.
- 1Lure
- 2Cloned site
- 3Wallet connection
- 4Malicious signature
- 5Automated sweep
The lure
Airdrop announcements, urgent security notices, fake support agents and sponsored search results all direct users to a cloned interface at a near-identical domain.
The signature
The victim is prompted to sign a transaction whose readable content is obscured. Common payloads are unlimited token approvals or delegated transfer permissions.
- ›Unlimited ERC-20 approval to an attacker contract
- ›Off-chain permit signatures used later
- ›Direct transfer disguised as a claim
The sweep
Automation executes within seconds of the signature, moving tokens to fresh addresses and swapping them for liquid assets before the victim notices.
On-chain footprint
Drainer contracts serve many victims and are highly reusable, so a single incident often maps to a much larger campaign.
Immediate steps
Revoke outstanding approvals, move remaining assets to a fresh wallet, and record the malicious transaction hashes and contract addresses before analysis begins.
Case intake is confidential and handled by email at cybersec@securida.info.
Frequently asked questions
- Can a signed transaction be reversed?
- No. Settlement is final. Investigation focuses on tracing where the assets moved and identifying accountable endpoints.
- Does revoking approvals recover stolen assets?
- No, but it prevents further draining from the same wallet.

- Cyber Intelligence
- Blockchain Investigations
- Digital Forensics
The SEQRIA Research Team is the investigative research unit of SEQRIA, specialising in cyber intelligence, blockchain investigations and digital forensics.
Its work focuses on digital asset investigations, blockchain transaction analysis, cyber incident investigations and technical evidence collection. Published material is reviewed internally before release.
About the research teamRelated briefings
Request Confidential Consultation
SEQRIA provides technical investigation, forensic analysis and recovery assistance. Outcomes are never guaranteed. Case intake is confidential and handled by email.
cybersec@securida.info