Know the play
Address poisoning and wallet drainers: how money disappears without a password
Blockchain Fraud · Forensic Intelligence · October 5, 2026
Short answerNobody needs your password if you send the money yourself. Address poisoning plants a look-alike address in your wallet history so you copy the wrong one. Wallet drainers get you to sign a permission that lets a contract move your tokens. A few habits prevent both.
Many crypto thefts never touch a password. On a blockchain, a transfer you sign is final, and a permission you grant keeps working until you take it back. These two scams target those moments instead of your password.
Address poisoning: the look-alike in your history
Crypto addresses are long strings nobody memorises, so people copy them, often from their own recent transactions. Address poisoning exploits that habit.
Chainalysis, a blockchain analytics firm, laid out the steps in Anatomy of an Address Poisoning Scam (October 2024). The scammer studies a target's transactions to find addresses they use often. They then generate a new address that looks the same at a glance. In the case Chainalysis examined, the fake matched the real address's first six characters. Finally they send a tiny, harmless-looking transaction from it, so the fake address now sits in the victim's history right next to the real one. The next time the victim copies "the usual" address from that list, the money goes to the scammer.
It is not rare. A team of researchers presenting Blockchain Address Poisoning at the USENIX Security Symposium in 2025 measured 270 million poisoning attempts targeting 17 million victims over two years on Ethereum and Binance Smart Chain. They counted 6,633 incidents that caused at least $83.8 million in losses. Most attempts fail, but the ones that succeed can be large: in the May 2024 case Chainalysis examined, a victim sent $68 million in wrapped bitcoin to a poisoned address whose opening characters matched the real one, before the attacker returned the funds. That campaign alone used more than 82,000 seeded addresses.
Wallet drainers: the signature that empties the wallet
A wallet drainer is a phishing kit. Scam Sniffer, a security firm that tracks these kits, describes them as infrastructure on malicious websites that induces users to sign harmful transactions so assets can be taken quickly. The bait is often something free, such as an airdrop or a rewards claim, as in the FBI case below. You connect your wallet and approve what looks like a routine request. What you actually signed is permission for someone else's contract to move your tokens.
That permission is called a token approval. Legitimate apps use approvals too. The ethereum.org guide on revoking token access notes that platforms sometimes ask for permission to spend an unlimited number of tokens to save small amounts later, that this carries increased risk, and that a permission you grant can still be used years later. Drainers also abuse a signed message called a Permit, which can carry the same kind of spending power.
In its 2025 crypto phishing report, Scam Sniffer counted $83.85 million stolen from 106,106 victims through drainer phishing in 2025, down from about $494 million and 332,000 victims in 2024. The largest single theft of 2025, $6.5 million, came from one malicious Permit signature, and Permit and Permit2 signatures made up about 38% of losses in cases above $1 million.
Some drainers skip the signature trick and ask for the seed phrase directly. The FBI warned in a June 3, 2025 public service announcement that criminals were sending NFT airdrops disguised as free rewards to users of one blockchain network. The links led to fake sites that asked people to enter their seed phrase to "connect," after which the criminals moved the funds out.
How to protect yourself
- Never copy an address from your transaction history. Use a saved, verified entry in your wallet's address book, or get it fresh from the person or platform you are paying.
- Check the whole address, character by character, as Chainalysis advises. Look-alikes are built to match the parts people glance at.
- Send a small test payment first for large transfers, as Chainalysis recommends, and confirm it arrived before sending the rest.
- Be suspicious of small incoming transfers from addresses you do not know. That is how a look-alike gets into your history.
- Never type your seed phrase into a website. The FBI's advice is not to respond to any request for it.
- Read what you are signing. If a site asks for an unlimited approval or a permit you did not expect, reject it.
- Treat unexpected airdrops as suspect. Verify them with the project through its official channels before you click anything.
- Review and revoke old approvals using the tools ethereum.org lists. Revoking costs a network fee and stops future use; it does not undo a transfer that already happened.
What to do if it already happened
- Assume the wallet is compromised if you entered a seed phrase anywhere. Move what remains to a new wallet with a new phrase.
- Revoke approvals on the affected wallet so the same contract cannot take more.
- Save the evidence: transaction hashes, the website address, screenshots, and the time it happened.
- Report it to the FBI at ic3.gov with the transaction details.
- Check the address the money went to with our free risk rating, then unlock the $9.95 full forensic report for address screening and a PDF you can share.
- If the loss is significant, read our first-hours checklist and talk to an analyst about a trace.
Did your money go to the wrong address?
Paste the address or transaction into our free check. It tells you what pattern it matches, privately, in seconds.
Run the free check →
Frequently asked
How did they take my crypto without my password?
Either you sent it to a look-alike address planted in your history, or you signed an approval or permit that let a contract move your tokens. Neither needs your password.
Does revoking an approval get my money back?
No. Revoking stops the contract from taking more. It does not reverse a transfer that is already on the blockchain.
Can stolen funds be recovered?
Sometimes, if they are traced to an exchange or a token issuer that can freeze them, but nobody can guarantee recovery. Report quickly, and be wary of anyone who offers to recover funds for an upfront fee.
Sources
- Chainalysis. Anatomy of an Address Poisoning Scam, October 23, 2024. https://www.chainalysis.com/blog/address-poisoning-scam/
- Taro Tsuchiya, Jin-Dong Dong, Kyle Soska, Nicolas Christin. Blockchain Address Poisoning, 34th USENIX Security Symposium, 2025. https://www.usenix.org/conference/usenixsecurity25/presentation/tsuchiya
- Scam Sniffer. Scam Sniffer 2025: Crypto Phishing Losses Fall 83% to $84 Million, January 3, 2026. https://drops.scamsniffer.io/scam-sniffer-2025-crypto-phishing-losses-fall-83-to-84-million/
- ethereum.org. How to revoke smart contract access to your crypto funds. https://ethereum.org/guides/how-to-revoke-token-access/
- Federal Bureau of Investigation, Internet Crime Complaint Center. Cyber Criminals Defraud Hedera Hashgraph Network Non-Custodial Wallet Users Through Nonfungible Token Airdrops Disguised as Free Rewards, Public Service Announcement I-060325-PSA, June 3, 2025. https://www.ic3.gov/PSA/2025/PSA250603
← More insights
Blockchain Fraud is a service of UnyKorn LLC (Wyoming). Educational information and risk analysis, not legal advice. We do not guarantee the recovery of any funds. We charge a flat fee or retainer, never a percentage of recovered funds.