Loading article…
Crypto drainer scams are surging, with phishing losses hitting $366.3 million in early 2026. Learn how attackers use fake sites to steal digital assets.
Sophisticated "crypto drainer" scams are increasingly targeting investors through a combination of AI-driven impersonation and malicious token approvals, contributing to a broader security crisis that saw Web3 losses exceed $1.31 billion in the first half of 2026 [1]. These attacks, which often rely on fake websites and search engine advertisements to deceive users, resulted in the loss of 1.9 million FXRP tokens—roughly 1.3% of the total supply—from a single wallet after the victim signed a malicious approval [2].
| At a glance | |
|---|---|
| H1 2026 Web3 Losses | $1.31 Billion |
| H1 2026 Phishing Losses | $366.3 Million |
| 2025 Total Scam Theft | $14 Billion |
| Primary Attack Vector | Malicious Token Approvals |
The recent theft of 1.9 million FXRP, valued by the victim at approximately $2.1 million, highlights the danger of "approval phishing" [2]. In this scheme, attackers register lookalike domains and purchase search engine ads to intercept users seeking legitimate platforms [2, 3]. Once a user connects their wallet to a fraudulent site, they are prompted to sign a transaction that grants the attacker an unlimited spending limit on their tokens [2]. This signature allows the drainer contract to move assets from the victim's wallet without further interaction [2].
These scams are becoming more difficult to detect as criminals integrate AI to create convincing deepfake videos, cloned voices, and personalized phishing messages [1]. Chainalysis reported that impersonation-related scam activity jumped 1,400% in 2025 compared to the previous year [1]. Furthermore, the use of malware frameworks like Okobot allows attackers to harvest seed phrases and credentials directly from user devices, expanding the scope of potential wallet takeovers [1].
The financial impact of these schemes is reaching record levels. While Chainalysis estimates that crypto scams and fraud stole at least $14 billion in 2025, that figure could ultimately climb to $17 billion as more illicit addresses are identified [1]. Security firm CertiK noted that wallet takeovers accounted for over $444 million of the total Web3 losses recorded in the first half of 2026 [1].
The prevalence of these attacks is compounded by the ease with which scammers can seed the web with fraudulent links [2]. In one instance, a user was directed to a fake network site after asking an AI chatbot for help with a token swap [2]. Because the fake site mimicked the interface of a legitimate decentralized finance application, the victim was prompted to sign permissions that ultimately drained their holdings [2].
As scammers refine their use of AI and search engine manipulation, the burden of security remains heavily on the individual to verify every interaction before signing. The core question for the industry is whether decentralized platforms can implement better user-facing safeguards to prevent the signing of malicious, high-risk approvals.
Coverage is mostly measured — 216 of 218 reports stay neutral.
Every Monday — the token unlocks, Fed dates & catalysts set to move crypto and markets this week. So you’re never blindsided.
Free · 3-min read · one-click unsubscribe
AI-assisted synthesis by the TrendWatcher Editorial Desk · sourced from 4 outlets · Sep 13, 2026 · How we report
As of 14 September 2026, the Peru Ministry of Economy and Finance reported that its official X account was compromised by attackers who used the platform to promote a fraudulent token called $HYLO. The ministry confirmed the posts were unauthorized and stated that no financial losses were reported in connection with the incident.
The Revolut data disclosure, reported in September 2026, involved the release of customer full names, birth dates, occupations, postal addresses, email addresses, and telephone numbers. Additionally, the impersonator obtained copies of passports or driving licenses, verification selfies, IBANs, and complete Bitcoin transaction histories.
MetaMask utilizes AI-powered security partners like Blockaid to analyze websites, social feeds, and on-chain bytecode to identify phishing and malicious behavior in real time. The wallet also employs Added Protection, a feature that automatically reverts transactions that do not match their previews, and provides warnings for lookalike addresses and first-time recipients.
Scammers exploit government accounts because these platforms command high levels of public trust, which can be used to legitimize fraudulent schemes. By posting on official channels, perpetrators can more effectively use urgency—such as fake token launch dates—to bypass the critical thinking of potential victims.