نسخهٔ فارسی

Transparent, non-custodial, yours

The signature that empties a wallet later

Drainer kits request an approval or a permit signature on a page that looks harmless. Nothing moves at first, which is exactly why they work.

Mechanism An approval or permit signature you grant, used later
Why it works Nothing moves at signing time, so nothing looks wrong
Check Token, spender address and amount in your wallet prompt

FBT Swap

What you should know

A drainer does not break into anything. It persuades you to grant it permission, waits, and then uses that permission. The delay is deliberate — nothing appears to go wrong at the moment you are paying attention.

These kits are sold as a service with hosting, templates and a cut of the proceeds, which is why the pages look professional and the social accounts promoting them look established.

The two signatures they want

An ERC-20 approval, which authorises a contract to move a specific token up to a limit. Or an off-chain permit signature, which does the same thing without an on-chain transaction and therefore without a gas prompt — making it feel even less consequential.

A permit request is especially dangerous because it looks like "sign in with your wallet". It is not a login. It is a transferable authorisation.

The pages they use

Airdrop claim pages, NFT mints with a countdown, token migration notices, "your wallet is at risk, revoke here" pages, and staking dashboards that mirror a real protocol. The last category is effective because the real protocol does need an approval.

Traffic comes from advertisements on search results, replies to popular posts, compromised Discord servers and direct messages. Rarely from somewhere you navigated to yourself.

Reading the prompt properly

Your wallet shows the token, the spender address and the amount. Three questions: does this site need this token at all, do I recognise this spender, and why is the amount unlimited? A mismatch on any of them ends the interaction.

For signature requests, read the message. If it contains a spender, a token and a deadline, it is a permit, not a login, no matter what the button says.

After a compromise

Move remaining assets to a fresh wallet with a new phrase immediately — revoking first wastes time the attacker is using. Then revoke the allowances on the old address so anything arriving there later is not swept.

Treat the old address as public. Assume any permission granted from it is still live, and do not reuse it.

At a glance

At a glance

Mechanism

An approval or permit signature you grant, used later

Why it works

Nothing moves at signing time, so nothing looks wrong

Check

Token, spender address and amount in your wallet prompt

After

Move funds to a new wallet first, revoke second

FAQ

Frequently asked questions

Clear answers before you decide.

Can a site drain me without any signature?

No. Every transfer requires a signature from your key. What varies is how innocuous the request is made to look, which is why reading the prompt is the entire defence.

Is a signature request safe because it costs no gas?

No — that is precisely the danger. Permit-style signatures authorise token movement off-chain with no gas prompt, so they feel lighter than they are.

Would FBT Swap ever ask for an unlimited approval on a page I did not reach myself?

FBT Swap only requests an approval for the token you are swapping, for the aggregator router that will execute it, at the moment you initiate the swap. We never message you first and have one domain: fbtswap.ir.

Risk notice

Crypto assets are volatile and on-chain transactions cannot be reversed. You can lose money, including all of it. Nothing here is financial advice.