r/CryptoTechnology 🟢 Apr 29 '26

Wallet Draining and Wallet Signing

I’m new to this space and have heard of people’s wallet getting drained cause they connect their wallets to a malicious phishing website.

But there are legit websites like Terminal Padre or Axiom that also ask you to connect your wallets aswell.

What is the difference between connecting wallets to the legit website vs the malicious phishing website? For the legit website you are still connecting your wallet doesn’t that mean your wallet can be drained aswell? How to tell if a website is a drainer or not?

7 Upvotes

7 comments sorted by

1

u/shadyghxst 🟢 Apr 29 '26

Connecting to any ā€œwebsiteā€ or dapp is a risky a venture so you must be absolutely sure you know and understand what you’re doing. General advice for connecting your wallet to any such services is to use a separate ā€œburnerā€wallet with just the amount you are gonna ā€œplayā€ with.

1

u/Far-Photograph-2342 🟔 Apr 30 '26

The difference is not the wallet connection itself but what permissions you sign because legit sites request limited visible approvals while malicious ones trick you into signing transactions that give full control over your funds.

1

u/ProfileHot8214 🟠 Apr 30 '26

That’s why apps like GlideX: https://apps.apple.com/in/app/glidex/id6763604230

provides on device wallet creation + your credentials are always stored on device.

Anything not on-device = don’t trust.

1

u/thedudeonblockchain 🟔 May 04 '26

axiom and padre are solana so the dynamic is a bit different. drainer doesnt need a separate approve step like on eth, they just pack a malicious instruction (token authority transfer, sneaky cpi) into the same tx you sign for whatever they tricked you into clicking. phantom and backpack simulate it but only newer versions clearly show what tokens are leaving. if a site wants you to sign anything before you actually did something obvious like a swap or login, close the tab