Beginner· Lesson 6 of 6· 4 min
Scams, drainers and how to stay safe
Every drain ends the same way: a key you leaked or a signature you gave. Here is what you will be asked to sign, what it can do, and the habits that make it not matter.
Non-custodial cuts both ways. No one can move your funds without your signature — and no one can undo a signature you gave. Scams therefore come in exactly three shapes: get the key, get a signature that does more than it says, or get a signature that grants standing permission. Everything you will ever see is a variation.
The three ways funds leave
| The key leaks | A seed phrase typed into a site, a screenshot in a cloud photo library, a “wallet sync” form. Total loss, every derived account, no transaction needed. |
|---|---|
| A transaction does more than it says | The button says “claim”; the transaction transfers every token you hold and closes the accounts. One signature, one popup, all gone. |
| A permission is granted | An Approve instruction lets a delegate spend up to an amount from a token account, later, without you. Also SetAuthority, which hands the account over entirely. |
What a drainer transaction looks like
Drainer kits build one transaction per victim, tailored to what the wallet holds: transfers for every token account with a balance, a SOL transfer for the remainder minus fees, sometimes an Approve for anything that can't be moved now. The site around it is a fake mint, a fake airdrop claim, a fake customer-support portal or a lookalike of a real app. The transaction is the tell; the site is just the wrapper. How wallet drainers work dissects a real one.
Read the simulation
Every modern wallet simulates a transaction before you sign and shows the balance changes. This is your one reliable defence, because it comes from running the actual transaction, not from what the site claims. Check four things:
- Direction. Are assets leaving that you did not intend to send?
- Amount. Does the SOL debit match the button, plus a small fee and any deposit you expect?
- Destination. Do you recognise where assets go? A transfer to an address you have never seen is the drain.
- Permissions. Does the wallet warn about an approval, an authority change or an account close? Those persist after the popup.
If the wallet says the simulation failed, do not sign anyway. Drainers sometimes deliberately break simulation so you can't see the changes.
The patterns you will actually meet
- Airdropped tokens or NFTs with a URL in the name. The token is bait; the site at the URL is the drainer. Ignore, or burn it with Token Burner.
- Address poisoning: dust sent from an address whose first and last characters match one you use, hoping you copy it from history later. Copy recipients from the source, never from history.
- Fake support in DMs. No project's support will ever message first or ask you to “validate” a wallet.
- Lookalike sites: the real app's name with one character changed, often as a paid search ad. Bookmark the real one.
- Fake wallet updates and browser extensions. Install only from the wallet's own site.
- “Recovery services” after a drain, which take a fee and drain again.
- Devnet tokens presented as live, and tokens whose name copies a real one. Verify by mint address.
Token-level traps
Some scams are in the token rather than the transaction. A live mint authority can print unlimited supply; a live freeze authority can lock your balance; a Token-2022 transfer fee or permanent delegate can take from you on every move. A honeypot lets everyone buy and no one sell. Token Inspector reads all of these from the mint before you buy.
Habits
- Hardware wallet for anything you would mind losing. Its screen shows what you sign, and the key never touches the computer.
- A burner with a little SOL for mints, new apps and anything unproven. If it is drained, that is all.
- Never type a seed phrase anywhere except a wallet you are restoring, on a device you own.
- Sign nothing from a link in a message. Go to the bookmarked site yourself.
- When in doubt, reject. A legitimate transaction can be sent again; a drain cannot be undone.
If it happens
Move whatever is left to a fresh wallet immediately — a drainer with a standing approval may come back. Assume the seed is burned if there is any chance it leaked. Report the address on the explorers so it gets labelled. Do not pay anyone who promises recovery.
What to remember
- Funds leave three ways: a leaked key, a transaction that does more than it says, or a standing approval.
- The wallet's simulation is the one thing the site cannot fake. Read direction, amount, destination, permissions.
- A failed simulation is a reason to reject, not to sign anyway.
- Copy addresses from the source, never from history. Verify tokens by mint address.
- Hardware wallet for what matters, burner for what's unproven, reject when unsure.