Live on Robinhood Chain — launch tokens with locked liquidity via MintPlus →Arc is coming — Circle’s stablecoin L1, mainnet Sept 16 · Get ready →T-15
Arc

Wallet Drainers & Signature Scams: How They Actually Work

Last verified: August 2026By the TrustSwap Team
Today on Arc: mainnet countdown, ARC token news, and every launch — covered daily. → Read today’s briefing

Nobody "hacks" your wallet in the movie sense. Drainers work by getting you to sign one thing that means something other than what the screen implies — an approval, a permit, a delegation — and the theft follows from your own signature. Understanding the five mechanisms is most of the defense, because each has a tell you can learn to see. This is the mechanical explainer, with 2025's numbers attached so the scale is clear.

How big is the problem, actually?

Smaller than its peak and still enormous. Scam Sniffer's annual accounting put 2025 phishing-drainer losses at $83.85 million across 106,106 victims — down 83% in value and 68% in victims from 2024's $494 million, which the analysts attribute to better wallet warnings and simulation, not to attackers giving up. The largest single 2025 theft was $6.5 million via one Permit signature. Chainalysis counted personal-wallet compromises at roughly 20% of the $3.4 billion stolen across crypto in 2025. The FBI's Internet Crime Complaint Center logged $11.4 billion in crypto-related fraud complaints for 2025, with people over 60 losing $4.4 billion. Address poisoning — which involves no signature at all — produced a single $50 million loss in December 2025. Lower totals are not gone threats; they're a mature industry being partially contained.

Mechanism 1 — the malicious approval

The oldest trick. A site presents a "mint," "claim," or "verify wallet" button; the transaction behind it is an ERC-20 approve (or NFT setApprovalForAll) granting the attacker's contract the right to move your tokens. The theft may follow instantly or weeks later. The tell: your wallet's transaction preview says "approve" or "set approval for all" when you expected a mint or a claim, and the spender is an address you've never heard of. Defense: read the preview's action verb, not the site's button label; if it says approve and you didn't intend to grant spending rights, reject. Cleanup afterward: revoke the approval.

Mechanism 2 — Permit and Permit2 signatures

Newer and nastier, because no transaction appears. EIP-2612 permit and Uniswap's Permit2 let you authorize token spending with an off-chain signature — no gas, no on-chain record until the attacker submits it. Phishing sites request an innocuous-looking signature ("sign in," "verify ownership"); the typed data is actually a permit granting their address spending rights, redeemable any time. Scam Sniffer attributed $8.7 million of 2025's large-case losses to this class. The tell: a signature request (not a transaction) whose readable data includes fields like spender, value, deadline, or PermitSingle/PermitBatch. Defense: treat every signature request as seriously as a transaction, read the typed data, and never sign a permit on a site you didn't navigate to yourself. If you've signed one, revoking the token's allowance to the spender — or, for Permit2, the Permit2 allowance — neutralizes it before it's used.

Mechanism 3 — EIP-7702 delegation

The 2025 arrival. Ethereum's Pectra upgrade let ordinary accounts temporarily delegate their behavior to a contract via a type-4 transaction. Drainers immediately weaponized it: trick the victim into signing a delegation to a "sweeper" contract, and every asset that lands in the wallet is auto-forwarded to the attacker — including funds you deposit to try to pay gas for a rescue. Security researchers reported that the overwhelming majority of 7702 delegations observed in the wild pointed at malicious sweepers within months of launch. The tell: a transaction of type 0x04 or a prompt to "upgrade" or "enable smart account" on an unfamiliar site. Detection: your address's code beginning 0xef0100 followed by the delegate. Fix: submit a new delegation to the zero address, from a funded, clean signer — the triage guide covers the sequencing.

Mechanism 4 — address poisoning

No signature, no approval: pure misdirection. Attackers generate addresses whose first and last characters match someone you transact with, then send you dust from that lookalike so it appears in your transaction history. Next time you copy "the address you used last time," you copy theirs. Trust Wallet reported tens of thousands of these attempts per hour across the ecosystem in early 2026, and one victim lost roughly $50 million in USDT in December 2025 by copying from history. Defense: never copy addresses from transaction history; use your own address book, verify more than the first and last four characters, and send a test amount first — on Arc that costs a fraction of a cent (sending safely).

Mechanism 5 — blind signing

The institutional killer. Hardware wallets protect you by showing what you sign — but only when the interface provides readable data. When it can't, the device shows a hash and asks you to sign "blind." The Bybit theft of roughly $1.5 billion in February 2025 was signers on hardware devices approving a masked Safe transaction that their screens couldn't render. Defense: treat every blind-signing prompt as a stop sign; verify the app URL independently; prefer apps with Clear Signing support; and for treasuries, use a multisig with signers who verify independently (Ledger on Arc covers the setting).

What's the general immune system?

Five habits cover all five mechanisms. Navigate, don't click — type or bookmark app URLs; links in DMs, replies and ads are the delivery mechanism for every drainer. Read the verb in every prompt — approve, permit, delegate, setApprovalForAll — and match it against your intent. Segregate — a hot wallet for interacting, a cold wallet with no approvals for holding (self-custody basics). Audit approvals quarterly (how). And distrust urgency: "claim closes tonight" exists to stop you reading. Arc's launch window is a target-rich environment — new users, new apps, a credibility halo scammers dress up in (current Arc scams); the news property theradian.news tracks active waves. The mechanisms don't change; only the costumes do.

FAQ

Can a drainer take my funds if I only connected my wallet? No — connecting reveals your address and nothing more. Loss requires a signature or transaction you approved. That's why every prompt after "connect" deserves reading.

I signed something on a suspicious site but nothing was taken. Am I safe? Not necessarily — permits and approvals can be redeemed later. Revoke allowances to unknown spenders now, check for a 7702 delegation, and move valuable assets to a fresh wallet if in doubt.

Does a hardware wallet stop drainers? It stops key theft and shows you what you're signing — if the data is readable. It cannot stop you approving a malicious transaction you didn't read, and blind signing removes most of its benefit.

Are drainers a problem on Arc specifically? The mechanisms are EVM-wide and port to Arc unchanged. A launch window with many first-time users is exactly where they concentrate.

How do I report a drainer? Chainabuse (free, shared with exchanges and law enforcement), the FBI's IC3 if you're in the US, and the phishing-detection lists your wallet uses. Reporting rarely recovers funds but does get sites blocked.

Building on Arc? Team Finance's flows never request unlimited approvals by default and never ask claimants for anything beyond the claim transaction.Open Team Finance →

Sources: Scam Sniffer, 2025 crypto phishing report (Jan 2026); Chainalysis, 2025 crypto crime and stolen funds (Dec 2025, updated Jun 2026); FBI IC3 2025 annual report (Apr 2026); Trust Wallet address-poisoning statement via The Block (Mar 2026); Dec 2025 $50M address-poisoning loss coverage; EIP-7702 delegation-phishing research (2025); Ledger and Scam Sniffer on the Feb 2025 Bybit incident; Revoke.cash on Permit2.

Last verified: August 2026

Mainnet opens September 16. Be ready before it does.

Team Finance has secured $2.7B+ across 40,000+ projects since 2020. Mint the token, lock the liquidity, vest the team and run distribution — on a chain where the fees are quoted in dollars.

Launch a token on ArcLock your liquidityGet The Crypto App