Blog · Crypto & freelance

How crypto wallets actually get drained.

The cryptography holds. What happens instead is that somebody hands over twelve words, or signs something they did not read, or pays an address that looks right and is not. All three are social problems in a technical costume, which is why technical people lose money to them too.

Read enough incident reports and the same thing stands out: the interesting technical detail is almost always missing. Nobody broke elliptic curve cryptography. Nobody guessed a private key. What there is instead, in report after report, is a person, a screen, and a decision made in about ninety seconds.

So this is a list of decisions rather than a list of exploits, in the order they actually cost people money.

The seed phrase, given away

This is the biggest category by a distance, and the phrasing matters: given away, not stolen. Somebody types twelve words into something.

The scenarios repeat because they work:

  • Fake support. You post a question in a public channel about a stuck transaction. Within minutes you have two or three direct messages from people whose display names match the wallet, the exchange, or the project. One of them will eventually ask you to "validate" or "restore" your wallet.
  • A form that looks like your wallet. A page, an app, a browser extension update, asking for the phrase to "sync", "verify" or "migrate". Real wallets do not need it. There is no legitimate reason for anything on the internet to receive your seed phrase.
  • A backup that is not offline. A photo in your camera roll. A note that syncs to a cloud account protected by a password from 2019 and no second factor. An email to yourself. Every one of these turns wallet security into the security of a different account entirely.
  • Help from a friend. Somebody trustworthy walks you through a fix over a screen share. The phrase appears on screen for four seconds. That is a recording now, on a machine you do not control.

The rule that covers all of it: the phrase is never typed into anything and never appears on a screen. Not for support, not for verification, not for a migration, not for anybody. Written on paper, or stamped in metal, stored where a burglar and a flood both cannot reach it. That is the whole protocol.

The signature, given away

The second category is subtler because nothing secret leaves your hands. You just approve something whose meaning you did not read.

Token approvals. Connecting to a site and approving it to spend a token is normal, and the approval usually has no expiry and no limit. A site that turns malicious next year still has it. Review your approvals occasionally and revoke the ones you no longer use.

Blind signing. A wallet showing you a wall of hex and an approve button is asking you to sign an intention you cannot read. Sometimes that intention is "transfer everything".

Permit signatures. These look harmless because they are not transactions and cost no fee. Signing one can hand over spending rights just as effectively as a transaction would, and it is the mechanic behind a good share of drainer sites.

If a signing request is not something you understand, the correct action is to reject it and lose nothing.

The address, quietly swapped

Two versions, both exploiting the same habit: reading the first four and last four characters of an address instead of the whole thing.

Address poisoning. An attacker generates an address whose start and end match one you have used, then sends you a dust transaction from it so it appears in your history. Later you copy an address from that history and pay them instead.

Email interception. Somebody with access to a mail thread sends a polite follow-up with an updated payment address. This one has taken very large amounts from businesses that did nothing else wrong.

Two habits fix most of it. Compare the middle of an address, not the ends. And with a new counterparty, send a small amount first, confirm it arrived, then send the rest.

Social engineering, described plainly

The technical patterns above are the exit. Social engineering is the entrance, and it is worth naming its shape, because the shape is stable even when the story is new.

An attack tends to have four of these:

  1. Urgency. A window that closes. Your funds are at risk right now. The allocation ends in an hour.
  2. Authority. A name, a logo, a title, a display name matching the wallet or the exchange. Sometimes a real employee's photo.
  3. A problem only you can solve, and only now. You are unusual, chosen, mistakenly locked out, uniquely affected.
  4. An action that cannot be reversed. A signature, a transfer, twelve words.

The useful thing about this list is that it does not require you to identify the scam. It requires you to notice the pressure. Nobody legitimate needs your seed phrase, your screen, or a signature in the next five minutes. When those three appear together, the answer is to stop and go slowly, and the honest people will still be there afterwards.

One more, because it keeps working on the careful: the job offer. A recruiter, a real-looking company, a take-home task in a repository, a file to run. This one bypasses the whole discussion above because it never mentions crypto until the money is gone.

Splitting money by how much it would hurt

The single most useful structural decision is not a habit, it is an arrangement.

Savings go on a hardware wallet. A device where the key never touches an internet-connected machine, and where a transaction must be confirmed on a screen you hold. This is the category of protection you cannot get any other way, and for an amount that would genuinely hurt to lose it is not optional.

Working money goes in a hot wallet. The balance you invoice with, pay with and cash out from. Convenient by design, and therefore holding an amount you could survive losing.

Almost every large individual loss comes from having one wallet doing both jobs.

What Orla does, and what it does not

We hold a hot wallet, and we are not going to pretend otherwise. Keys are generated and encrypted in your browser and never leave it; only the public address is stored. Creating a wallet makes you type three of the twelve words back, because a tick box saying you wrote them down proves nothing.

Where we can take the specific attacks above off the table, we do:

  • The confirmation screen shows the recipient address in full, never shortened, which is what address poisoning depends on, and says so when you have never sent to that address before.
  • An EVM address whose capitalisation does not check out is flagged as you type: right shape, wrong character.
  • On Solana, pasting a token account instead of a wallet address is refused with an explanation, because money sent there cannot be recovered.
  • Sends can require a passkey every time, and an AML check on the destination sits on the same screen.
  • Whenever the encrypted key is released to a session, the owner gets a notification, at most one a day per wallet, so a release nobody made stands out. Releases are rate limited.
  • Airdropped scam tokens are filtered out of holdings and history, so the bait does not sit in your ledger looking like a balance.
  • The wallet password has a twelve character minimum and refuses the common ones, because it is the only thing protecting an encrypted key that can be attacked offline where nothing slows an attacker down.

And the limit, stated as plainly as the features: this is not a replacement for a hardware wallet. For savings, buy one. Use Orla for the money that moves, and keep the money that sits somewhere a browser cannot reach. The rest of what protects the account around the wallet, passkeys, two factor, device sessions, the security log, is on the trust page.

The short version

Never type the phrase. Never sign what you cannot read. Compare the middle of the address. Send a test amount to a new counterparty. Keep savings on hardware and working money in a hot wallet. Treat anybody who arrives offering help, urgently, as an attack, because that is what they almost always are.

Questions
Would a real wallet or exchange ever ask for my seed phrase?

No, and there is no exception. Not for support, not to verify, not to migrate, not to restore. Nothing on the internet has a legitimate reason to receive those twelve words, and nobody should ever see them on your screen either, including somebody helping you over a screen share.

How does address poisoning work?

An attacker generates an address whose first and last characters match one you have paid before, then sends you a dust transaction so it appears in your history. Later you copy an address from that history and pay them. It works because people compare the ends of an address rather than the middle, so comparing the middle defeats it.

Do I need a hardware wallet?

For savings, yes. It is the only way to keep a key off an internet-connected machine and to confirm a transaction on a screen an attacker cannot reach. Keep working money, the balance you invoice and pay with, in a hot wallet. Almost every large individual loss comes from one wallet doing both jobs.

Every account in one ledger.

Banks, cards, cash, exchanges and wallets, with the shared parts shared and the rest kept to yourself.

Get it on your phone
App StoreGoogle Play