Home Blog Blog EVM Wallet Drainer: Technical Analysis 2026

EVM Drainer Internals: How Permit2, Multicalls & Simulation Bypasses Wipe Wallets

1. How EVM Drainers Exploit User Signatures

An EVM wallet drainer is an automated Web3 script that uses off-chain EIP-712 signatures, Permit2 approvals, and multicall smart contracts to extract ETH, ERC-20 tokens, and NFTs across Ethereum, BSC, Arbitrum, Base, and Polygon without needing a user's private key or seed phrase.

Instead of relying on malicious executables, EVM drainers prompt standard wallet interactions (like "Claim Rewards" or "Connect Wallet") that encode broad spender allowances inside signed messages.

2. Permit2 EIP-712 Off-Chain Signature Breakdown

Uniswap's canonical Permit2 contract (0x000000000022D473030F116dDEE9F6B43aC78BA3) allows dApps to share token approval state without requiring repeated on-chain approve() transactions. Drainers abuse Permit2 by requesting off-chain PermitSingle or PermitBatch signatures:

{
  "details": {
    "token": "0xdAC17F958D2ee523a2206206994597C13D831ec7", // USDT
    "amount": "115792089237316195423570985008687907853269984665640564039457584007913129639935",
    "expiration": "1772000000",
    "nonce": "0"
  },
  "spender": "0xAttackerContractRelay...",
  "sigDeadline": "1772000000"
}

Because the victim signs an off-chain message, zero gas is consumed during signing. The attacker contract executes permitTransferFrom() subsequently to withdraw tokens.

3. eth_signTypedData_v4 Obfuscation Vectors

Standard wallet extensions (MetaMask, Rabby, Coinbase Wallet) use eth_signTypedData_v4 to present structured JSON data to users. Attackers obfuscate domain hashes (presenting recognized names like "Uniswap" or "Seaport" while changing the verifying contract or chainId parameters) to prevent manual detection during signing.

4. How Relayers Bypass Blockaid & Blowfish Simulations

Security simulation tools evaluate the balance change of the immediate transaction payload. EVM drainers bypass static and sandbox simulation via:

  • Asynchronous Sweeping: The initial signature only creates an off-chain allowance; the withdrawal transaction occurs hours later, leaving the initial simulation balance delta at +$0.00.
  • Dynamic Calldata Obfuscation: Calldata is assembled dynamically inside proxy contracts via variable salt and internal delegatecalls, evading static regex/AST scanners.
  • Sandbox Honeypot Evasion: Relayers check gas parameters, origin balances, and execution traces to abort if simulated by security crawler addresses.

5. EVM Exploit Comparison Matrix

Exploit Method Target Assets Signing Protocol Simulation Warning Evasion
Permit2 Batch Approval ERC-20, Stablecoins EIP-712 Off-Chain Bypasses on-chain approval warnings; shows $0 balance delta
Seaport / Blur Listings ERC-721, ERC-1155 NFTs Order Fulfillment Hash Masked as private 0 ETH listing or marketplace gasless order
Session Key Delegation Smart Accounts, Multi-Asset ERC-5792 / ERC-4337 Delayed execution hours after session disconnect
Multicall Batch Sweep DEX LPs, Staked Collateral Direct Relayer Interaction Atomic liquidation across Uniswap, Aerodrome, Camelot

3. Going Deeper: Not Just Tokens Anymore

Modern drainers don’t stop at your token balances. They’ve started targeting all kinds of DeFi positions - liquidity pools, lending collateral, restaked assets - the works.

3.1. DEX & Liquidity Pool Draining

The new breed of drainers taps directly into DEX protocols to liquidate your LP positions on the spot. When you connect, their script scans for:

  • Uniswap V2/V3 (any chain)
  • PancakeSwap V2/V3 (BSC, Base, Ethereum)
  • SushiSwap V2 LPs
  • QuickSwap (Polygon)
  • Camelot V2 (Arbitrum)
  • Trader Joe ERC1155 LPs
  • Velodrome and Aerodrome (Optimism, Base)
  • Curve.fi LP tokens and gauges
  • Convex Finance (cvxCRV, staked positions)
  • Stargate Finance (LPs and staked STG)
  • Frax Finance V2

Once found, they swap your LP tokens to stablecoins or ETH, then forward everything out - pulling max value and dodging price swings.

3.2. Exploiting Lending & Restaking Protocols

Staked or locked assets aren’t safe anymore. Today’s drainers interact straight with lending and restaking protocols to:

  • Pull collateral from AAVE V2/V3 (any chain)
  • Liquidate Venus positions (BSC)
  • Claim Spark Protocol rewards (Gnosis)
  • Drain Radiant Capital vaults
  • Grab Prisma Finance assets (mkUSD, eBTC)
  • Unwind EigenLayer restaked ETH and eTokens
  • Close out MakerDAO vaults
  • Harvest ApeStake rewards (APE, NFT staking)

Modern sweeper bots don't just dump liquid wallet tokens - they liquidate collateral, harvest yield rewards, and unwind complex LP positions in a single transaction.

3.3. NFT & Marketplace Draining

NFTs are hot targets - attackers go after them aggressively. Drainers already support:

  • Seaport 1.1 / 1.4 (OpenSea, Blur, LooksRare)
  • Blur Points Pools, even non-transferable reward tokens
  • ERC404 hybrid tokens like $DEGEN
  • Basic fallback coverage for NFTX, Sudoswap, and X2Y2 (through Seaport compatibility)

So, a single transaction can swipe both fungible and non-fungible assets. Quick, efficient, ruthless.

4. Full EVM Chain Coverage (2026)

This isn’t just about Ethereum mainnet anymore. By early 2026, drainers reach over 40 EVM-compatible chains:

Core Networks:

  • Ethereum
  • BNB Smart Chain (BSC)
  • Polygon (PoS)
  • Arbitrum One
  • Optimism
  • Base
  • Avalanche C-Chain (Avax)
  • Fantom
  • Cronos
  • Gnosis
  • Celo
  • PulseChain
  • Blast
  • Linea
  • Scroll
  • Mode
  • Manta Pacific
  • Fraxtal
  • Aurora
  • Moonbeam / Moonriver
  • Fuse

Extended Support (20+ more):

  • Mantle, Metis, Kava EVM, Telos, Boba, WEMIX, PGN, Beam, Heco, Shibarium, OKX Chain, Klaytn, and plenty of others

Universal Capabilities

On every chain, attackers can:

  • Pull out native coins (ETH, BNB, MATIC, AVAX, etc.)
  • Sweep ERC20 tokens
  • Drain ERC721/ERC1155 NFTs
  • Liquidate LP positions straight through built-in DEX routers

This cross-chain reach preys on people using new L2s and obscure chains - places packed with liquidity, but where users just don’t know how to spot phishing.

5. Advanced Signing Exploits: Bypassing Modern Defenses

Attackers keep getting smarter. Gone are the days when simple token approvals were enough to catch victims. Now, drainers slip right past people who:

  • Regularly use Revoke.cash to pull approvals
  • Actually check what they’re signing

How? A few dirty tricks:

  • Permit2 Phishing: Fake “gasless approval” pop-ups that look just like Uniswap or Blur. The spender address is buried deep in the EIP-712 payload - easy to miss.
  • Session Key Abuse: Sneakily ask for temporary full wallet access through ERC-5792. The drain happens later, long after the victim leaves the site.
  • Single-Signature Full Drain: Everything - native coins, ERC-20s, NFTs, LP tokens - bundled into one signature. Dead simple for the attacker, barely any interaction for the victim.

These moves dodge Blockaid, slip past MetaMask phishing alerts, and ignore wallet guardrails. Delayed execution makes them even harder to spot.

6. Real-World Case Study: The “BaseApe” Phishing Campaign (Q1 2026)

In January 2026, attackers ran a slick phishing campaign called “BaseApe” right when memecoins were booming on Base. They spun up fake airdrop sites that looked like official Bored Ape Yuga Labs pages, promising “free $BASEAPE tokens” to anyone who connected their wallet.

Here’s how it played out:

  • The landing page was a near-perfect BAYC clone, fresh domain, HTTPS, Cloudflare - looked legit.
  • Users got prompted to connect MetaMask or Coinbase Wallet.
  • Instead of a normal token approval, the site triggered a Permit2 universal allowance for all ERC-20s on Base.
  • The draining logic waited 18 hours - so victims thought they were safe.
  • The script then:
    • Drained ETH, USDC, DAI
    • Swapped illiquid memecoins ($TOSHI, $DEGEN) to USDC on Aerodrome
    • Liquidated LP positions in the $DEGEN/USDC pool
    • Routed everything through a privacy pool before consolidating the loot

The aftermath:

  • Around 840 wallets emptied in just 72 hours
  • Total losses hit about $2.1 million (mostly ETH and USDC)
  • Blockaid caught less than 9% of the attacks as they happened
  • Main weak point: users signed Permit2 approvals without checking the spender address

6. Frequently Asked EVM Drainer & Error Queries

Why did my wallet sign an approval without paying any gas?
You signed an EIP-712 off-chain typed message (like Permit2). Signing messages off-chain is free for the user; the attacker pays the gas fee when executing permitTransferFrom on-chain.

Can Revoke.cash remove Permit2 permissions?
Standard token allowance checkers only check ERC-20 allowance() mappings. To revoke Permit2 approvals, you must interact specifically with the canonical Permit2 contract functions (permit() or lockdown()) or set Permit2 allowance to 0.

Why didn't Blockaid or MetaMask alert me before signing?
Attackers use delayed execution (asynchronous relayer sweeps hours later) and dynamic proxy contracts. Because 0 tokens move during the initial signature verification, simulation tools display a neutral balance preview.

For a broader breakdown of multi-chain setups, check our what is a crypto drainer guide.

Explore more technical breakdowns on our blog.

If you’ve read this far, you understand how Permit2 multicalls dominate the EVM mempool