Can a scammer drain my crypto wallet through a 'connect wallet' button on a website?
Yes. Malicious 'connect wallet' buttons can prompt you to approve a transaction that grants the scammer unlimited access to your tokens.
Last reviewed: 1 August 2026
Explanation
Wallet-draining scams disguise themselves as NFT mints, DeFi platforms, airdrop claim pages, or charity donation sites. When you click 'connect wallet' and then approve the transaction in your wallet app, you may be approving a smart contract permission that grants the scammer's contract the right to transfer all of your tokens. These are called malicious approvals or 'approval phishing'. The initial connection itself is not always dangerous, but the approval transaction that follows can be.
The distinction that matters is between connecting and signing. Connecting a wallet reveals your address and lets a site read public information; it moves nothing. Signing is where the risk lives: an approval for an 'unlimited' token allowance, a signature on a message you cannot read, or a transaction whose contents differ from what the page describes can each hand over control of assets. Drainer kits are sold ready-made to scammers, which is why the same fake mint or claim page reappears endlessly under new domains, often promoted through hacked social accounts and paid ads.
Before approving any transaction, read what the wallet prompt actually says it is granting, verify the website address character by character, and only interact with contracts reached through official project links — not through DMs, ads, or comment-section URLs. Review your existing allowances with a reputable token approval checker periodically and revoke anything you do not recognise, and consider keeping long-term holdings in a wallet that never touches new sites.
Common red flags
- Website prompts a wallet approval for an amount labelled 'unlimited' or a very large number
- Site URL has minor spelling differences from the genuine project
- You found the site through a social media ad rather than an official project link
- The transaction gas fee seems very low, suggesting a pre-signed malicious transaction
What to do now
- Reject any wallet transaction you do not fully understand
- Check existing approvals with a reputable token approval checker and revoke suspicious ones
- If you approved a malicious contract, move remaining funds to a new wallet immediately
- Report the site to your national cybercrime unit and the platform that hosted the ad
Frequently asked questions
Is it safe to connect my wallet to read-only sites?
Connecting your wallet for read-only portfolio tracking is generally low risk, but you should still verify the site is genuine and never approve any transaction on a site you have not thoroughly verified.
Does a hardware wallet protect me from approval phishing?
Only partly. A hardware wallet stops key theft, but if you approve a malicious transaction on the device, the approval is just as valid. The protection comes from reading and understanding every signature request, whatever wallet you use.
I approved something suspicious but nothing has been taken yet. Am I safe?
No — a granted allowance can be exercised at any time, including much later. Revoke the approval immediately using a reputable allowance checker, and if you cannot be sure what was signed, move assets to a fresh wallet.