Publication

Crypto drainers: how crypto assets are stolen and whether stolen assets can be recovered

04/08/2026

Marko Holovach

Senior Associate, Attorney-at-Law

ECHR case-law,
White Collar Crime

Over the past few years, the crypto asset market has grown rapidly not only in terms of capitalisation, but also in terms of the number of fraudulent schemes. One of the most widespread is crypto drainers. These are tools that allow malicious actors to drain assets from victims' wallets.

At first glance, this may appear to involve a conventional wallet hack. In practice, however, the mechanism operates differently. The user personally confirms the required actions and signs a smart contract that gives the malicious actor full control over the user’s assets, without understanding its actual content. This feature is precisely what makes crypto drainers so effective: from the blockchain’s perspective, such transactions appear legitimate because they are formally authorised by the wallet owner.

As a rule, this occurs when users interact with counterfeit websites or fake applications that imitate well-known services. The user connects a wallet and confirms the proposed action, believing it to be a technical formality. In reality, that action may grant access to the assets or directly initiate their transfer.

In reality, crypto drainers are less a matter of technical hacking than a combination of social engineering and the particular features of blockchain infrastructure. This is why typical use scenarios are always built around creating trust or the illusion of a secure interaction.

Typical fraud scenarios

The most common example of drainer deployment is an airdrop or NFT campaign in which a user is offered assets in just a few clicks. The user need only connect a wallet and confirm a transaction that, in reality, opens access to the funds or immediately triggers the mechanism for transferring them out.

The use of counterfeit websites of well-known services follows similar logic. Visually, such resources may completely replicate the original, with the differences limited to minor details in the domain name or interface. As a result, the user fails to identify the threat and interacts with the resource as though it were legitimate.

In addition, malicious actors actively exploit users’ trust in the source of information. This involves compromising accounts on social networks or in project communities and distributing malicious links through them. Because such messages appear to come from a well-known project, the likelihood that they will be perceived as safe increases substantially.

Particular attention should be paid to so-called approval schemes. In such cases, the user does not lose funds immediately, but signs a transaction granting a smart contract the right to control the assets in the future. In practice, these mechanisms are often used on fake exchanges or pseudo-DeFi services: after the approval is signed, the attackers simply wait until assets arrive in the wallet or its balance increases, after which they transfer them out automatically without any additional confirmation from the user. This is why the victim may remain unaware for some time that access to their assets has effectively already been transferred to third parties.

More sophisticated scenarios involve fake DeFi platforms or investment services that imitate genuine interaction with blockchain protocols. The ultimate result, however, remains the same: the user personally grants access to their assets, which are then transferred to addresses controlled by the fraudsters.

Can stolen assets be traced?

One of the key myths that works to fraudsters’ advantage is the notion that cryptocurrency is completely anonymous. In fact, most public blockchains, including Ethereum, operate on the principle of full transparency: every transaction, address and movement of assets is recorded in a public ledger. This means that, once stolen, the funds do not disappear; they continue to move, and that movement can be traced.

This is the basis for analysing blockchain data to establish links between addresses and trace asset flows. In practice, two basic approaches are used.

First, address clustering. This means grouping different crypto addresses into notional clusters that are highly likely to be controlled by the same person or service. This is done on the basis of behavioural patterns: joint use of funds, transaction characteristics, interaction with particular smart contracts and so on. As a result, a more coherent picture is formed instead of a set of disparate addresses.

Second, tracing the flow of funds. After an incident, a transaction chain is mapped: exactly where the assets were transferred, how they were split and whether they passed through other services. This analysis makes it possible to identify key points, including where the funds enter centralised infrastructure.

Specialised tools such as Chainalysis and TRM Labs are used for this purpose. They combine technical blockchain analysis with their own databases (for example, addresses of exchanges and services, and previously identified schemes), making it possible not only to see the movement of funds, but also to understand with whom or with what the address is interacting.

Another important element is so-called tagging (flagging) of funds as stolen. This is how it works in practice. After the incident has been recorded and a preliminary analysis conducted, the addresses that received the stolen assets or were used in the scheme are identified. These addresses are submitted to analytics platforms or directly to centralised services (for example, crypto exchanges). In their compliance systems, such addresses are assigned a high-risk status.

Thereafter, if funds from these addresses or related clusters reach a platform with KYC procedures, this may automatically trigger:

  • additional review of the transaction;
  • restrictions on transactions;
  • in certain cases, even the temporary freezing of assets.

Put simply, the assets become flagged: it becomes more difficult to use them without interaction with compliance teams, and any attempt to legitimise them increases the risk of identifying the user.

For the victim, this has entirely practical significance. Depending on the circumstances, the outcome of such work may include:

  • establishing the route taken by the funds;
  • identifying the services through which they passed;
  • identifying the point at which the funds entered a centralised environment;
  • the ability to initiate the freezing of assets by such services;
  • building an evidentiary basis for further legal action;
  • in certain cases, obtaining data that makes it possible to identify a person.

Thus, although crypto drainers create an illusion of being beyond control, the public nature of the blockchain makes it possible to turn the movement of funds into a traceable process. The subsequent outcome depends on how effectively this technical analysis is supported by legal tools.

Although the movement of funds on public blockchains can be analysed, identifying the scheme’s ultimate beneficiary remains difficult in practice. This is because malicious actors deliberately use tools and approaches that complicate or break the tracing chain.

One such tool is a mixer. Its purpose is to mix the funds of a large number of users: assets enter a common pool and are subsequently withdrawn to other addresses in a modified structure. As a result, the direct link between the initial and final transactions becomes significantly more difficult to establish or becomes statistical rather than deterministic. For analysts, this means losing a clean chain of funds and having to work with probabilistic models.

A similar effect is achieved through the use of cross-chain bridges. In this case, assets are transferred from one blockchain to another (for example, from Ethereum to another network), often with a simultaneous change in their form (wrapped tokens and so on). This transfer creates an additional break point for tracking, because further analysis requires data from different networks to be synchronised and the particular features of each network to be taken into account.

Particular attention should also be paid to the use of so-called anonymous cryptocurrencies, whose blockchain architecture is designed to make transaction tracing impossible or substantially restrict it. The best-known example is Monero.

Unlike public networks, Monero uses technologies that conceal the sender, recipient and transaction amount (including ring signatures, stealth addresses and confidential transactions). In practical terms, this means that conventional blockchain analysis based on data transparency either does not work at all or is subject to substantial limitations. If stolen funds are converted into such assets, further tracing becomes considerably more difficult.

Another factor is the use of centralised exchanges, which has a dual effect. On the one hand, the arrival of funds on a platform with KYC procedures creates an opportunity to identify the user. On the other hand, fraudsters often use several exchanges in succession, in different jurisdictions, or withdraw funds through services with less stringent verification requirements. This allows them to blur the trail and complicates a swift response.

This is directly related to jurisdictional difficulties. By their nature, crypto transactions are not tied to a particular state, while access to information about users of exchanges or services depends on national law. As a result, obtaining the necessary data may require:

  • international legal assistance;
  • cooperation with foreign regulators;
  • compliance with procedures that take a considerable amount of time.

Finally, the use of front persons (money mules or drops) is a common practice. In such cases, accounts on exchanges or other services are registered in the names of third parties who are knowingly or unknowingly involved in the scheme. This creates an additional layer of separation between the direct perpetrator and the organiser, making it more difficult to prove their respective roles.

Thus, although the technical ability to trace funds exists in most cases, in practice it encounters a number of technical and legal barriers. These factors determine the complexity of a particular case and the scope of the actions required to identify the persons involved and further protect the victim’s interests.

Legal protection mechanisms

Despite the technological complexity of such schemes, crypto drainers are gradually ceasing to be a grey area for law-enforcement and judicial systems. Ukrainian practice already includes both criminal proceedings against organisers of such schemes and court decisions ordering the seizure of crypto assets, indicating the gradual formation of procedural mechanisms to protect victims.

In most cases, criminal proceedings remain the primary instrument. Depending on the circumstances, the acts may be classified, among other things, as fraud, unauthorised interference with information systems, or other offences involving the use of electronic computing equipment.

Illustrative in this context is the judgment of 26 February 2026, in which the court considered a scheme involving the use of a drainer. According to the facts of the case, the victim was persuaded via Telegram to transfer assets to a wallet and connect it to a fictitious cryptocurrency transparency-checking service. The malicious actors then gained access to the digital assets and transferred them out. Importantly, the drainer mechanism itself already features expressly in criminal proceedings and is receiving a legal assessment from the court.

The recognition of crypto assets as property is of particular importance. This makes it possible to apply conventional procedural mechanisms to them: seizure of property, preservation of assets, and the subsequent determination of their return or special confiscation. Judicial practice in recent years demonstrates that Ukrainian courts increasingly accept the possibility of imposing seizure specifically on virtual assets.

In practice, one of the most effective mechanisms is to approach centralised exchanges with a request to freeze assets. If blockchain analysis establishes that stolen funds have reached a platform with KYC procedures, the victim or law-enforcement authorities may initiate restrictions on transactions involving those assets.

Although exchanges do not always respond with the same degree of speed, practice shows that cooperation is entirely possible when the incident has been properly documented and the relevant procedural documents are available, especially in the case of major centralised platforms.

In parallel, protective judicial measures are also used. In particular, in 2024–2026 Ukrainian courts repeatedly issued rulings seizing crypto assets held through accounts on the Binance exchange. In individual cases, courts expressly prohibited the use and disposal of virtual assets and blocked the functionality of the relevant accounts.

In effect, this is an adaptation of the conventional mechanism for seizing property to digital assets. This is particularly important given the speed at which cryptocurrency can be moved: without prompt protective measures, the assets may be transferred through several jurisdictions or converted into privacy cryptocurrencies such as Monero, where further tracking becomes significantly more difficult.

Another important procedural mechanism is obtaining information. In criminal proceedings or through international cooperation, the following may be obtained:

  • users’ KYC data;
  • login history and IP addresses;
  • information on asset movements;
  • related accounts and transactions.

It is often these data that are critical to moving from an anonymous address to a specific person. Because a significant part of crypto infrastructure is located outside Ukraine, international legal assistance plays a distinct role. In practice, cooperation may involve:

  • foreign crypto exchanges;
  • domain registrars;
  • hosting providers;
  • law-enforcement authorities of other states.

Without this stage, an effective investigation of cross-border schemes is often impossible.

Thus, despite the specific nature of crypto assets and the technical complexity of drainers, modern legal mechanisms already make it possible not only to document the theft, but also to take real procedural steps to locate, freeze and potentially recover the assets. Judicial practice in this area is still developing, but it already demonstrates the gradual adaptation of conventional legal tools to digital assets.

Action plan for a victim

In cases involving crypto drainers, the speed of the response is critical. Because of the characteristics of blockchain transactions, assets may move between dozens of addresses within a few minutes. The first actions after an incident therefore directly affect the prospects of subsequent tracing and the potential freezing of funds.

First of all, all transactions and related data must be recorded. This includes not only wallet addresses and transaction IDs (TXIDs), but also:

  • screenshots of the connected resource;
  • a link to the website;
  • correspondence;
  • messages on Telegram, Discord or X;
  • information about the timing and sequence of actions.

In practice, even minor details may be relevant to subsequent analysis and the formation of an evidentiary basis.

At the same time, it is advisable to seek legal assistance as quickly as possible. In such cases, not only the technical tracing of funds matters, but also the proper procedural documentation of the incident from the earliest stages. Timely involvement of lawyers makes it possible to:

  • promptly organise blockchain analysis;
  • prepare and preserve the evidentiary basis;
  • properly initiate criminal proceedings;
  • prepare submissions to crypto exchanges and other services;
  • minimise the loss of time, which is often critical in such cases.

The next step is to conduct blockchain analysis. Its purpose is to establish the route taken by the assets, identify related addresses and determine whether the funds have reached centralised services. This stage makes it possible to understand whether there are practical opportunities for the subsequent seizure of assets or identification of the user.

At the same time, it is important not to interact with the scam resource again. In practice, victims often attempt to cancel the transaction, reconnect the wallet or take additional steps that supposedly will help recover the funds. This may result in renewed compromise or the loss of other assets.

It is also advisable to:

  • revoke approvals;
  • disconnect the wallet from suspicious services;
  • transfer the remaining assets to a new wallet.

Only after this, with the involvement of lawyers, are criminal proceedings initiated and further cooperation with law-enforcement authorities undertaken. Despite the complexity and cross-border nature of such schemes, it is criminal proceedings that create procedural mechanisms for:

  • obtaining information;
  • international legal assistance;
  • the seizure of assets;
  • official communication with crypto exchanges and other platforms.

Taken together, these steps form the basis for the further protection of the victim’s interests and the potential recovery of the assets.

Is it realistic to recover the assets?

There is no universal answer to the question of recovering crypto assets. The practical prospects depend on how the attackers acted after stealing the funds, whether any points remain for further identification of the assets, and how quickly the victim began to respond.

The most favourable situations are those in which the stolen funds reach centralised exchanges (CEXs). In such cases, it becomes possible to identify the platform through which the assets passed, initiate a freeze of the funds and obtain user data through KYC procedures. This is why the speed of the response is critical: the earlier the blockchain analysis is conducted and the relevant requests are sent, the greater the chances that the funds have not yet been withdrawn or converted into other assets.

The prospects of asset recovery also increase substantially where a specific person can be identified or a link can be established between addresses and real accounts. In that situation, the matter involves not only technical tracking, but also the ability to apply comprehensive legal mechanisms: seizure of assets, obtaining information, criminal prosecution and subsequent recovery of the assets.

At the same time, there are scenarios in which recovering the funds becomes considerably more difficult. This primarily concerns cases where the assets pass through mixers, DeFi protocols or cross-chain services, and are also converted into privacy cryptocurrencies, including Monero. In such situations, the transaction chain partially or completely loses its transparency, and the capabilities of conventional blockchain analysis are substantially restricted.

The situation is further complicated by the use of a large number of intermediary addresses, accounts held by front persons, and services in jurisdictions that offer minimal cooperation with foreign law-enforcement authorities.

It should also be borne in mind that modern drainers are increasingly rarely limited to a fake website or a single phishing attack. An entire hybrid ecosystem is effectively emerging, combining conventional cybercrime, malware infrastructure and blockchain mechanisms. Cybersecurity researchers, including SOC Prime, have also drawn attention to this.

In practice, this means that after the initial theft of funds, malicious actors may use:

  • malware;
  • compromised browser extensions;
  • remote access to the device;
  • automated drainer-as-a-service platforms;
  • networks of phishing resources and Telegram infrastructure.

As a result, the victim sometimes faces not merely a one-off transfer of assets, but an ongoing compromise of their environment. This is why, after an incident, simply closing the website or creating a new wallet is insufficient; in certain cases, the device itself must also be checked for malware or browser compromise.

Moreover, modern drainers increasingly operate under a drainer-as-a-service model, effectively as ready-made criminal infrastructure: some persons administer the technical component, others conduct phishing campaigns and search for victims, and the proceeds are distributed among the participants in the scheme.

This also affects the prospects of asset recovery. On the one hand, a larger number of participants and the use of centralised infrastructure sometimes leave more digital traces for analysis. On the other hand, the scheme itself becomes more scalable and professional, and therefore more difficult to address promptly.

This is why, in cases involving drainers, it is important to assess not only the theft itself, but also whether the victim is part of a broader compromise incident involving access to accounts, the browser, email or other related services. This directly affects both the ongoing security of the assets and the effectiveness of legal and technical measures to recover them.

Conclusion

Just a few years ago, crypto drainers were perceived as a highly specialised problem of the crypto community. Today, they constitute a full-scale, scalable industry combining phishing, malware, blockchain infrastructure and elements of organised cybercrime.

Particularly noteworthy is the fact that some such services effectively operate openly and publicly position themselves as businesses. A telling example is CryptoGrab, a service that was linked to Nova Drainer and was officially registered as a company in the United Kingdom. Cybersecurity researchers expressly stated that the service advertised tools for stealing crypto assets and operated under a drainer-as-a-service model.

The very existence of structures of this kind demonstrates how professionalised the crypto-fraud environment has become. This is no longer a matter of lone hackers, but of ecosystems with their own infrastructure, affiliate models, technical support and allocation of roles among participants.

At the same time, the development of such schemes is also driving the parallel development of countermeasures. Blockchain analytics, cooperation with centralised platforms, mechanisms for freezing assets and the development of judicial practice on the seizure of crypto assets are gradually transforming cryptocurrency from an anonymous environment into a space where the movement of funds can be traced and used as evidence.

Ukrainian practice is also gradually adapting to these challenges: criminal proceedings concerning drainers, rulings ordering the seizure of crypto assets and procedural mechanisms for cooperation with crypto exchanges are emerging. This indicates that crypto fraud is no longer outside the legal framework.

At the same time, the effectiveness of protection depends directly on the speed of the response and the proper combination of technical and legal tools. In such cases, blockchain analysis without appropriate procedural support is often insufficient, just as formal criminal proceedings without an understanding of how crypto assets move are insufficient.

This is why a comprehensive approach is crucial in cases involving crypto drainers: from recording the incident and tracking the funds to cooperating with exchanges, law-enforcement authorities and foreign jurisdictions.

Author: Marko Holovach

What's new?

Most important updates in your mail.

similar publications

21/03/2023

The International Criminal Court (ICC) issued the arrest warrant for Vladimir Putin and Maria Lvova-Belova for the war crime of unlawful deportation and transfer of children from Ukraine to russia. It might be a significant development in applying international law and protecting human rights in Ukraine suffering from russian aggression.

Marko Holovach

07/09/2022

Terrorism is one more of those terms that everyone seems ready to use, but no one can agree on an exact definition. Let's add one more definition to the previous ones. The UN General Assembly use the following in its pronouncements on terrorism: "Criminal acts intended or calculated to provoke a state of terror in the general public, a group of persons or particular persons for political purposes are in any circumstance unjustifiable, whatever the considerations of a political, philosophical, ideological, racial, ethnic, religious or any other nature that may be invoked to justify them."

Marko Holovach