Wallet Drainer Scripts
Wallet drainer scripts are malicious pieces of code injected into websites or smart contracts that automatically attempt to steal assets from a connected wallet. When a user interacts with a compromised site, the script may prompt them to sign a transaction that appears benign but actually grants the attacker access to their funds.
Once signed, the drainer script immediately executes a series of transfers to empty the wallet of all valuable tokens. These scripts are becoming increasingly sophisticated, using obfuscation to hide their true purpose from security scanners.
They often target users who are looking for airdrops, minting NFTs, or interacting with new DeFi protocols. Protecting against these scripts requires using tools that simulate transaction outcomes before signing and being extremely cautious about which sites are granted permissions.
It is a major threat in the decentralized finance ecosystem, necessitating high levels of user caution.