Skip to main content
Important: We do not provide financial advice or custody funds. All transactions occur on third-party platforms.

Phishing, Social Engineering, and Wallet Drainers

How attackers actually steal crypto from real people, with current 2024-2026 case studies and concrete defenses.

11 min · intermediate · part of Security Mastery: Protecting Your Assets

Why Social Engineering Wins

The single most important truth about crypto security: most theft is not technical. It is social. The cryptography that secures Bitcoin and Ethereum is mathematically unbroken. There has never been a successful attack on the SHA-256 or secp256k1 primitives that secure Bitcoin. There has never been a successful attack on the underlying ECDSA or Schnorr signature schemes. Yet billions of dollars in crypto are stolen every year. How? By tricking the people who hold the keys into doing the wrong thing. Per Chainalysis 2025 data, private key compromises were the #1 theft vector at 43.8% of stolen value in 2024. Most of those compromises trace back to social engineering: phishing emails that tricked the user into entering a seed phrase, fake "support" accounts on Twitter or Discord that walked victims through "wallet recovery," romance scams that built trust over months before pivoting to "investment opportunities." The FBI IC3 2024 report counted approximately $9.32 billion in cryptocurrency-nexus fraud losses across 149,686 complaints (+66 percent year-over-year). About $2.8 billion of that was suffered by victims aged 60 and over, many of them targeted by sophisticated long-running social engineering operations. This lesson is about how those operations actually work, and how to recognize and defend against them.

Also in this lesson

  • Phishing: The Most Common Attack
  • Pig Butchering: The Long-Game Scam
  • Building Defensive Habits
  • For Deeper Reading

Key terms

Phishing
Fraudulent communications (email, SMS, DMs, fake websites) that appear legitimate but are designed to steal credentials or trick users into harmful actions.
Wallet drainer
Malicious dApp or smart contract that, when interacted with, drains all approved tokens or assets from a victim's wallet. Inferno Drainer and Pink Drainer are dominant 2024 platforms.
setApprovalForAll
An ERC-721/ERC-1155 function that grants permission to move ALL tokens of a specific type. Frequently abused by drainers to take all NFTs at once.
Permit2 (Uniswap)
An off-chain signature standard that authorizes token spending without an on-chain transaction. Convenient but a major attack vector when phished.
Pig butchering / Sha zhu pan
A long-game romance-investment scam that builds emotional connection over months before pivoting to fake investment platforms. FBI estimates $4-5B+ annual losses.
SIM swapping
An attack transferring your phone number to a SIM controlled by the attacker, defeating SMS-based 2FA. Why hardware tokens or authenticator apps are preferred.
Hardware token / U2F (YubiKey)
A physical USB device that produces cryptographic 2FA tokens. Phishing-resistant: cannot be tricked into producing tokens for fake sites.
Authenticator app (TOTP)
Apps like Google Authenticator, Authy, or 1Password that produce time-based one-time passwords. Stronger than SMS but weaker than hardware tokens.
revoke.cash
A web tool for reviewing and revoking token approvals across many networks. Periodic use is part of basic hygiene.
Scam Sniffer
A browser extension that warns users about known phishing domains and suspicious dApps. Among the standard defenses.
Burner wallet
A separate wallet with minimal funds, used for experimental or risky dApp interactions. Compromise of the burner does not affect main holdings.
Whitelisted withdrawal addresses
A security feature on many exchanges that restricts withdrawals to pre-approved addresses, often with a time delay. Limits damage if the account is compromised.

Continue this lesson — 4 more sections in the CryptoBipto app.

Open lesson

Educational only — not financial advice.