BLOCKCHAIN FRAUDForensic Intelligence
Know the play

Address poisoning and wallet drainers: how money disappears without a password

Blockchain Fraud · Forensic Intelligence · October 5, 2026
Short answer

Nobody needs your password if you send the money yourself. Address poisoning plants a look-alike address in your wallet history so you copy the wrong one. Wallet drainers get you to sign a permission that lets a contract move your tokens. A few habits prevent both.

Many crypto thefts never touch a password. On a blockchain, a transfer you sign is final, and a permission you grant keeps working until you take it back. These two scams target those moments instead of your password.

Address poisoning: the look-alike in your history

Crypto addresses are long strings nobody memorises, so people copy them, often from their own recent transactions. Address poisoning exploits that habit.

Chainalysis, a blockchain analytics firm, laid out the steps in Anatomy of an Address Poisoning Scam (October 2024). The scammer studies a target's transactions to find addresses they use often. They then generate a new address that looks the same at a glance. In the case Chainalysis examined, the fake matched the real address's first six characters. Finally they send a tiny, harmless-looking transaction from it, so the fake address now sits in the victim's history right next to the real one. The next time the victim copies "the usual" address from that list, the money goes to the scammer.

It is not rare. A team of researchers presenting Blockchain Address Poisoning at the USENIX Security Symposium in 2025 measured 270 million poisoning attempts targeting 17 million victims over two years on Ethereum and Binance Smart Chain. They counted 6,633 incidents that caused at least $83.8 million in losses. Most attempts fail, but the ones that succeed can be large: in the May 2024 case Chainalysis examined, a victim sent $68 million in wrapped bitcoin to a poisoned address whose opening characters matched the real one, before the attacker returned the funds. That campaign alone used more than 82,000 seeded addresses.

Wallet drainers: the signature that empties the wallet

A wallet drainer is a phishing kit. Scam Sniffer, a security firm that tracks these kits, describes them as infrastructure on malicious websites that induces users to sign harmful transactions so assets can be taken quickly. The bait is often something free, such as an airdrop or a rewards claim, as in the FBI case below. You connect your wallet and approve what looks like a routine request. What you actually signed is permission for someone else's contract to move your tokens.

That permission is called a token approval. Legitimate apps use approvals too. The ethereum.org guide on revoking token access notes that platforms sometimes ask for permission to spend an unlimited number of tokens to save small amounts later, that this carries increased risk, and that a permission you grant can still be used years later. Drainers also abuse a signed message called a Permit, which can carry the same kind of spending power.

In its 2025 crypto phishing report, Scam Sniffer counted $83.85 million stolen from 106,106 victims through drainer phishing in 2025, down from about $494 million and 332,000 victims in 2024. The largest single theft of 2025, $6.5 million, came from one malicious Permit signature, and Permit and Permit2 signatures made up about 38% of losses in cases above $1 million.

Some drainers skip the signature trick and ask for the seed phrase directly. The FBI warned in a June 3, 2025 public service announcement that criminals were sending NFT airdrops disguised as free rewards to users of one blockchain network. The links led to fake sites that asked people to enter their seed phrase to "connect," after which the criminals moved the funds out.

How to protect yourself

What to do if it already happened

Did your money go to the wrong address?

Paste the address or transaction into our free check. It tells you what pattern it matches, privately, in seconds.

Run the free check →

Frequently asked

How did they take my crypto without my password?

Either you sent it to a look-alike address planted in your history, or you signed an approval or permit that let a contract move your tokens. Neither needs your password.

Does revoking an approval get my money back?

No. Revoking stops the contract from taking more. It does not reverse a transfer that is already on the blockchain.

Can stolen funds be recovered?

Sometimes, if they are traced to an exchange or a token issuer that can freeze them, but nobody can guarantee recovery. Report quickly, and be wary of anyone who offers to recover funds for an upfront fee.

Sources

  1. Chainalysis. Anatomy of an Address Poisoning Scam, October 23, 2024. https://www.chainalysis.com/blog/address-poisoning-scam/
  2. Taro Tsuchiya, Jin-Dong Dong, Kyle Soska, Nicolas Christin. Blockchain Address Poisoning, 34th USENIX Security Symposium, 2025. https://www.usenix.org/conference/usenixsecurity25/presentation/tsuchiya
  3. Scam Sniffer. Scam Sniffer 2025: Crypto Phishing Losses Fall 83% to $84 Million, January 3, 2026. https://drops.scamsniffer.io/scam-sniffer-2025-crypto-phishing-losses-fall-83-to-84-million/
  4. ethereum.org. How to revoke smart contract access to your crypto funds. https://ethereum.org/guides/how-to-revoke-token-access/
  5. Federal Bureau of Investigation, Internet Crime Complaint Center. Cyber Criminals Defraud Hedera Hashgraph Network Non-Custodial Wallet Users Through Nonfungible Token Airdrops Disguised as Free Rewards, Public Service Announcement I-060325-PSA, June 3, 2025. https://www.ic3.gov/PSA/2025/PSA250603
← More insights

Blockchain Fraud is a service of UnyKorn LLC (Wyoming). Educational information and risk analysis, not legal advice. We do not guarantee the recovery of any funds. We charge a flat fee or retainer, never a percentage of recovered funds.

Operated by

UnyKorn LLC, a Wyoming limited liability company formed July 1, 2026 (Wyoming filing 2026-002019968). Managing Member: Kevan Burns.

Contact: kevan@unykorn.org · cases: cases@blockchainfraud.org · partners: partners@blockchainfraud.org · security: security@blockchainfraud.org

Network: UnyKorn · Blockchain Fraud · Y3K Markets · FlashRouter · Our commitments

UnyKorn LLC is a technology and administration service provider. It is not a bank, broker-dealer, exchange, custodian, trustee, transfer agent, appraiser, auditor, investment adviser, money transmitter, or issuer. It issues no tokens and never holds client funds.