criticalLast updated: June 2026

Crypto Wallet Drainers

Malicious scripts are intercepting wallet approvals and draining assets from compromised sites and fake interfaces.

Get the CSM Weekly Threat Brief and updates when this threat profile changes.

What\'s happening

Injected scripts prompt wallet users to approve transactions that appear routine but grant sweeping permissions.

Attackers buy traffic, mimic legitimate apps, and use compromised extensions to capture signatures.

The attack path is fast, automated, and often complete before victims realize what was signed.

Who it targets

Retail crypto holders

Creators and communities using wallet-gated tools

Teams experimenting with Web3 integrations

Real-world examples

Compromised NFT mint pages with malicious approval flows.

Search ads driving traffic to cloned wallet-connect pages.

Browser extensions altered to inject malicious contract prompts.

What it costs

Asset loss is often irreversible.

Compromised wallets create long-term trust and identity risk.

Businesses can suffer brand damage if customer wallets are hit through their site.

How to protect against it

Use hardware-backed approvals for valuable wallets.

Limit token approvals and review permissions frequently.

Monitor web properties for injected scripts and third-party changes.

Separate experimental wallets from treasury or core accounts.

Vendors who specialize in this threat

Signal Fraud Ops

Financial Fraud Prevention

Wire fraud controls, anomaly detection, and finance-team verification workflows.

Find More Vendors for This Threat

Related threats

Identity & Accesscritical

Credential Stuffing

Attackers are replaying massive stolen credential sets across business and consumer services to hijack accounts at scale.

Stat: 24B credentials available on dark web

Read Full Brief
Emerging / AI-Powered Threatscritical

AI-Powered Phishing

LLMs are enabling more targeted, more fluent, and more personalized phishing at industrial scale.

Stat: LLMs used to generate hyper-personalized attacks

Read Full Brief
Emerging / AI-Powered Threatshigh

Data Poisoning Attacks

Adversaries are manipulating data inputs and training sets to skew AI outputs, trust signals, and downstream decisions.

Stat: Corrupting AI training data to manipulate outputs

Read Full Brief