Join our Newsletter — 33% off our NHI Course

What are the signs that a Web3 site may be a crypto drainer?

Common warning signs include unsolicited links, fake airdrop claims, requests to connect a wallet before any real service is visible, and branding that copies a known project or official account. Risk is especially high when the link comes from Discord or social media rather than a verified project channel. Unexpected transaction prompts should be treated as suspicious until confirmed independently.

How to recognise a crypto drainer before you interact

A crypto drainer usually looks legitimate until the moment a wallet is connected or a transaction is approved. The strongest warning sign is a mismatch between the promise and the destination: urgent rewards, airdrops, mint claims, or “verification” steps that arrive before any clear product, event, or official announcement. If the page is pushing action faster than it proves legitimacy, treat it as hostile until checked.

Look for behavioural cues rather than one isolated visual trick. Drainers often rely on time pressure, copied branding, and a path that makes the user sign something before they have enough context to understand what is being approved. If the site appears only after a DM, social post, or forwarded link, the delivery channel itself is part of the suspicion profile.

Unexpected transaction prompts are especially important. A normal site should not ask for approvals that do not obviously match the service you intended to use. When the request is vague, unusually broad, or occurs before the site demonstrates a real function, the safer assumption is that the prompt is the attack, not a required setup step.

Why fake airdrops, copied branding, and wallet prompts are so effective

Crypto drainers work because users are conditioned to treat web3 wallets as a routine part of access. That makes wallet connection itself a weak signal unless it is paired with strong context. Attackers exploit that habit by making the first interaction feel routine, then using the approval flow to extract assets or authorise a harmful action.

Copied logos, cloned account names, and near-identical domain names reduce the chance that a user pauses long enough to verify the source. A fake airdrop or mint claim also creates a believable reason to act quickly. The issue is not just deception, but sequence: the site asks for trust before it earns any trust.

For a practical comparison, treat a drainer page the way you would treat an unknown login page that appears out of nowhere, except that the transaction request can have immediate financial consequences. Once a wallet signature or approval is granted, the blast radius can be much larger than a simple page visit.

What should make you stop and verify independently

The most useful habit is to stop when the page and the context do not line up. If the link came from Discord, a direct message, a social post, or a reused community comment rather than a verified project channel, verify the project through a separate source before taking any action. Do not use the link’s own claims as proof of legitimacy.

Check whether the site’s request is consistent with the project’s normal behaviour. A legitimate application usually has a clear reason for connection, a recognisable flow, and a transaction that matches the task. If the page jumps straight to approval, presents an unexplained token interaction, or asks for repeated confirmations, that is a strong sign to leave.

For added context, review platform guidance on official verification and wallet approvals, such as NIST Cybersecurity Framework 2.0 and OWASP API Security Top 10. They are not drainer-specific guides, but they reinforce the core principle that trust should be verified before access or action is granted.

Risk and Threat Considerations

Crypto drainers are dangerous because the victim may authorise the attack voluntarily. The threat is not only theft of funds, but also the abuse of trust signals, copied identity, and transaction ambiguity to make a malicious approval look routine. The risk rises when users treat wallet prompts as harmless or assume a familiar logo means the source is safe.

Failure mechanism: The attacker presents a convincing lure, gains a wallet connection or signature, and then uses the approval flow to authorise asset transfer, token permissions, or another harmful action.

Impact: Funds, tokens, and valuable permissions can be lost immediately, and the victim may not realise the scope of the damage until after on-chain activity has already occurred.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST CSF 2.0 sets the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST CSF 2.0 ID.RA-01 — Asset Vulnerabilities Are Identified And Documented Verifying drainer lures depends on identifying suspicious exposure and weakness in the link flow.
PR.AA-05 — Identity Verification, Authentication, and Authorization Wallet connect and transaction approval are access decisions that should be verified before trust is granted.
DE.CM-09 — Malicious code is detected Drainer pages are hostile content and should be treated as potentially malicious activity to detect and block.
Recommendation — Document suspicious link and approval patterns before users interact with them. Require verified context before authorizing wallet connections or approvals. Monitor for malicious web content and suspicious approval flows in user traffic.
MITRE ATT&CK T1566 — Phishing Drainers commonly use deceptive links, copied branding, and lure messages to induce action.
Recommendation — Map drainer lures to phishing detections and user-reporting workflows.

Practitioner Guidance

What to verify: Verify the project’s claim from an independent channel, not from the page or message that delivered the link. If the site asks for wallet access before it has shown a real service, treat that as a stopping condition, not a normal onboarding step.

Decision rule: If the transaction request is unexpected, broad, or hard to explain in one sentence, do not approve it. When in doubt, assume the prompt is the risk and investigate the source before continuing.

Practitioner takeaway: The best defence is not recognising every drainer pattern perfectly, but refusing to grant wallet authority until the site has earned trust through an independently verified source and a clearly justified action.