Wallet drainer bots don't hack your wallet.
They get you to hand it over yourself.
The attack flow:
1. Fake site mimics a legitimate protocol (Uniswap, OpenSea, Coinbase)
2. User connects wallet - standard action, feels safe
3. Site requests a transaction signature, looks routine
4. Signature approves a drainer contract to move all assets
5. Wallet emptied. Funds gone. Irreversible.
Dark web discussions about drainer malware rose 135% between 2022 and 2024.
The tooling is commoditized. The barrier to launching a campaign is near zero.
The attack doesn't exploit code. It exploits the fact that users can't verify what they're actually signing.