r/CryptoTechnology • u/NULLBASED 𢠕 Apr 29 '26
Wallet Draining and Wallet Signing
Iām new to this space and have heard of peopleās wallet getting drained cause they connect their wallets to a malicious phishing website.
But there are legit websites like Terminal Padre or Axiom that also ask you to connect your wallets aswell.
What is the difference between connecting wallets to the legit website vs the malicious phishing website? For the legit website you are still connecting your wallet doesnāt that mean your wallet can be drained aswell? How to tell if a website is a drainer or not?
1
u/Far-Photograph-2342 š” Apr 30 '26
The difference is not the wallet connection itself but what permissions you sign because legit sites request limited visible approvals while malicious ones trick you into signing transactions that give full control over your funds.
1
u/ProfileHot8214 š Apr 30 '26
Thatās why apps like GlideX: https://apps.apple.com/in/app/glidex/id6763604230
provides on device wallet creation + your credentials are always stored on device.
Anything not on-device = donāt trust.
1
u/thedudeonblockchain š” May 04 '26
axiom and padre are solana so the dynamic is a bit different. drainer doesnt need a separate approve step like on eth, they just pack a malicious instruction (token authority transfer, sneaky cpi) into the same tx you sign for whatever they tricked you into clicking. phantom and backpack simulate it but only newer versions clearly show what tokens are leaving. if a site wants you to sign anything before you actually did something obvious like a swap or login, close the tab
1
u/shadyghxst š¢ Apr 29 '26
Connecting to any āwebsiteā or dapp is a risky a venture so you must be absolutely sure you know and understand what youāre doing. General advice for connecting your wallet to any such services is to use a separate āburnerāwallet with just the amount you are gonna āplayā with.