Safety
Solana Wallet Security Checklist: Drainers and Delegates
A prioritised Solana wallet security checklist: how drainers work, how to check token delegates, hot vs cold wallets, and what to do after a compromise.
Key takeaways
- Most Solana wallet drains come from signing one malicious transaction or leaking a seed phrase, not from standing token approvals.
- A Solana token delegate is an address approved to move up to a set amount from one token account, and the account owner can remove it with a Revoke instruction.
- Revoking delegates does not help once a Solana seed phrase or private key is exposed; the only fix is moving assets to a wallet created from a new seed.
- Separating a Solana hot wallet for trading from a hardware-backed cold wallet limits the damage of any single bad signature.
- A Solana vanity address generated in a browser is suitable for hot wallets and branding, not for long-term storage.
The short answer#
Solana wallets are almost always drained in one of two ways: the owner signs a malicious transaction, or the seed phrase ends up somewhere other than paper. Standing token approvals, the classic Ethereum problem, are a much smaller risk on Solana, though they exist and take seconds to check. The checklist below is ordered by how much damage each item prevents, and the second half covers what to do if the worst has already happened.
How do Solana wallet drainers actually work?#
A Solana drainer is a site or script that turns one approval from you into a transfer of everything worth taking. There is no exploit of the chain involved. The wallet owner authorises the loss, usually without realising what the transaction contains. The common variants are these.
Malicious transaction signing#
A Solana transaction can hold many instructions, so a single signature can send SOL, move a dozen tokens and transfer NFTs together. Drainer sites scan the connected wallet, build a transaction that takes the most valuable assets, and present it as "claim", "mint" or "verify". Wallets such as Phantom and Solflare simulate the transaction and show expected balance changes, which is the main defence. Drainers respond by trying to make simulations fail or look harmless, which is why "simulation failed, sign anyway?" should be treated as a no.
Fake airdrop and claim sites#
Fake claim pages copy the branding of a real project and are promoted through replies on X, Discord DMs, search ads and lookalike domains. The real project never needs you to "claim" within ten minutes, and a claim never requires sending assets out. If a simulation of a claim shows tokens leaving the wallet, close the tab.
Spam NFTs and tokens with links#
Anyone can send an asset to any Solana address. Spam NFTs and tokens advertise a URL in their name or image, promising a reward for visiting. Holding the asset is harmless. Visiting the site and signing is where the loss happens. I cover the cleanup options in what to do with spam NFTs on Solana.
Seed-phrase phishing#
Seed-phrase phishing is any attempt to get the 12 or 24 words typed into something other than your wallet's own restore screen. It arrives as fake wallet-update pop-ups, fake support staff, "wallet validation" forms and counterfeit browser extensions. No legitimate site, tool or support agent needs a seed phrase. That includes SOLTidy: every tool on this site works through your wallet's signing prompt and never asks for a key.
Owner and authority reassignment#
Some drainers do not move assets at all; they take control of the accounts holding them. The SPL Token program lets a token account's owner be changed with a SetAuthority instruction, the System program's Assign instruction can hand a wallet account to another program, and a stake account's withdraw authority can be reassigned with an Authorize instruction. The balance appears untouched afterwards, but you can no longer move it. Any simulation or instruction list showing "set authority", "assign" or "authorize" on a site that has no reason to do so is a red flag.
Do Solana wallets have token approvals like Ethereum?#
Solana has token approvals, called delegates, but they are far less common than ERC-20 allowances. A delegate is an address that the owner of a token account has approved, with an Approve instruction, to move up to a fixed delegatedAmount from that one account. Most Solana programs do not need one, because the transfer happens inside the same transaction you sign, with your signature authorising it directly.
Delegates still show up in three situations: some staking, lending and listing programs use them by design; an old app may have left one behind; and a malicious transaction can include an Approve alongside something innocent. A delegate that covers your whole balance of a valuable token deserves attention.
To check, open the free Revoke Delegations tool and either connect or paste the wallet address for a read-only scan. It reads every SPL Token and Token-2022 account, lists those with an active delegate along with the delegated amount and your balance, and flags allowances covering the full balance. Revoking is a standard Revoke instruction signed by you; the tool charges nothing, and the network fee is about 0.000005 SOL per transaction. The Solana CLI does the same job with spl-token revoke <account> if you prefer the terminal.
Two limits are worth knowing. A Token-2022 permanent delegate is set on the mint by the issuer and cannot be revoked by holders at all; the only defence is not holding that token, which I explain in Token-2022 explained for traders. And a clean delegate scan says nothing about whether your key is exposed.
Which wallet setup limits the damage?#
Separating wallets by purpose limits the damage of any mistake to the wallet it was made in. A workable setup for an active trader has three tiers.
| Wallet | Key storage | Used for | What it holds |
|---|---|---|---|
| Cold wallet | Hardware device, seed on paper or steel | Receiving, occasional transfers, native staking | Savings and long-term positions |
| Hot wallet | Browser or mobile wallet, its own seed | Daily trading on known apps | Working capital only |
| Burner wallet | Separate seed or throwaway keypair | New mints, unknown sites, airdrop claims | Just enough SOL for the action |
The tiers only work if the seeds are different. Several accounts derived from one seed phrase all fall together if that phrase leaks. A hardware wallet such as a Ledger keeps the private key off the computer, so malware cannot copy it, but the device will still sign a malicious transaction if you confirm it. Its real value comes from being connected to very few sites.
Where a vanity address fits#
A vanity address is a normal Solana keypair whose address starts or ends with chosen characters. The free vanity address generator searches for one inside your browser and never uploads the key, but the secret key is still displayed on an internet-connected machine, where a rogue extension or clipboard malware could read it. Use a browser-generated vanity address for hot wallets, project wallets and branding. Keep savings on a key that was generated inside a hardware device and has never been shown on a screen.
How do you read a transaction simulation before signing?#
Reading a simulation means checking that the balance changes your wallet predicts match what you meant to do. It takes about ten seconds.
- Check the domain in the wallet prompt and compare it with the project's official link, character by character.
- Read the expected balance changes. A swap shows one asset out and one in. A claim shows assets in only. Anything else leaving is a reason to reject.
- Look for extra assets. A mint that also moves your USDC or an unrelated NFT is a drainer.
- Treat "simulation failed", "unable to simulate" or a blank preview as a rejection on any site you do not already trust.
- Reject prompts to sign several transactions at once from an unfamiliar site; the harmless one is often first.
- On a hardware wallet, avoid blind signing for anything beyond apps you know well.
If you signed something and are unsure what it did, paste the signature into the Transaction Decoder, which lists the balance changes per account and every instruction, including inner ones, in plain language. It is read-only and needs no wallet connection.
What should you do in the first minutes after a compromise?#
After a compromise, move assets to a wallet created from a new seed phrase before doing anything else. A leaked seed cannot be un-leaked. Changing a wallet password, revoking delegates or disconnecting sites does nothing when the attacker holds the key, because they can sign whatever you can. Automated sweeper bots often watch compromised wallets and take incoming SOL within seconds, so speed and order matter.
- On a device you trust, create a new wallet with a new seed phrase. Do not add an account under the old seed.
- Transfer the most valuable liquid assets first: SOL, stablecoins, then large token positions and NFTs.
- Do not send extra SOL to the old wallet "for fees" in advance; send small amounts only as needed, since a sweeper may take it.
- Check native stake. Use the Stake Accounts tool to list stake accounts the old key controls. Deactivating is free, withdrawals cost 0.002 SOL per account, and stake that is still active must wait for the epoch boundary, so start this early.
- If the old key is a mint, freeze or metadata update authority for a token you launched, transfer or revoke that authority from the old key.
- If only a single bad transaction was signed and the seed is safe, a delegate scan and revoke is the right response. If you cannot tell which case you are in, assume the seed is exposed.
- Retire the old wallet permanently and work out how the leak happened (cloud notes, screenshots, a fake extension) before it happens again.
The checklist, by priority#
The items below are ranked by how much loss each one prevents for a typical active trader.
| Priority | Action | Why it matters |
|---|---|---|
| Critical | Never type a seed phrase anywhere except your wallet's restore screen | A leaked seed loses everything and cannot be fixed |
| Critical | Store the seed offline; no photos, cloud notes or password-manager copies you would not trust with cash | Most seed leaks are from synced files |
| Critical | Reject transactions whose simulation fails or shows unexpected outflows | One signature is enough to drain a wallet |
| High | Keep savings in a hardware-backed cold wallet with its own seed | Limits any hot-wallet mistake |
| High | Use a burner wallet for new mints, claims and unknown sites | The most dangerous signing happens here |
| High | Reach apps from bookmarks, not search ads, replies or DMs | Lookalike domains are the main delivery route |
| Medium | Scan for token delegates every few months and after using unfamiliar apps | Cheap to check, occasionally serious |
| Medium | Never follow links in spam NFTs or tokens | The asset is harmless; the site is not |
| Medium | Install wallet extensions only from the wallet's official site | Counterfeit extensions steal seeds |
| Low | Use browser-generated vanity addresses for hot wallets only | The key has been on a networked screen |
Checking the token is a separate job from protecting the wallet; for that, see how to spot a Solana rug pull. If you want to know who builds these tools and why they never ask for a key, that is on the about page.
Bottom line#
Solana wallet security is mostly about two things: what you sign and where your seed phrase lives. Delegates are worth a periodic free scan, but they are not how most wallets are emptied. Split funds across a cold wallet, a hot wallet and a burner with different seeds, read every simulation, and treat a failed simulation as a refusal. If a key is ever exposed, skip the revoking and move everything to a new seed at once.
Questions & answers
How do Solana wallet drainers work?
A Solana drainer is a website or script that gets you to sign a transaction which transfers your assets or hands over control of them. The page usually poses as an airdrop claim, a mint or a wallet verification step. One signature can carry many instructions, so a single approval may move SOL, several tokens and NFTs at once. Other drainers skip transactions entirely and simply ask for the seed phrase in a fake wallet pop-up or support chat.
Can someone drain my Solana wallet just by sending me a token or NFT?
No. Receiving a token or NFT on Solana cannot move your funds, because nothing in your wallet is signed by you when someone sends you an asset. The danger is what the spam asset advertises: a link in its name, image or description that leads to a drainer site. Ignore the link, never connect to the site it names, and hide or burn the asset if it bothers you.
Do I need to revoke token approvals on Solana like on Ethereum?
Less often, but it is still worth a check. Solana programs normally take tokens inside the transaction you sign rather than relying on a standing allowance, so most wallets have no active delegates. Delegates do exist, though, and a malicious Approve can be hidden in a transaction. A read-only scan takes a few seconds and shows every token account with a delegate and the amount it may move.
What should I do first if my Solana wallet is compromised?
Create a new wallet from a new seed phrase on a clean device and move everything of value there immediately, starting with the largest balances. Do not reuse the old seed, and do not spend time revoking approvals first if the key itself is exposed, because the attacker can sign anything you can. Afterwards deal with stake accounts and token authorities the old key controls, then treat the old wallet as permanently burned.
Is a hardware wallet enough to keep Solana funds safe?
A hardware wallet keeps the private key off your computer, which defeats malware and seed-stealing extensions. It does not stop you from approving a malicious transaction, because the device signs whatever you confirm. It is strongest when used as a cold wallet that rarely connects to new sites, with a separate hot wallet for trading and mints, and with the seed phrase stored offline only.
Are browser-generated vanity addresses safe to use?
A vanity address generated locally in a browser is as mathematically sound as any other Solana keypair, but the secret key has been displayed on an internet-connected machine, where a malicious extension or clipboard malware could read it. That makes it fine for a hot wallet, a project wallet with working funds or a branded address, and a poor choice for savings. Use a hardware wallet for anything you cannot afford to lose.
Continue reading
How to spot a Solana rug pull: a trader's pre-buy checklist
Most Solana rug pulls use one of a handful of on-chain powers, and every one of them is publicly readable before you buy. This is the checklist I run on a new token, where to look for each item, and what it cannot tell you.
Token-2022 explained for traders: extensions that matter
Token-2022 lets a Solana token carry optional extensions, and a few of them give the issuer powers the classic token program never allowed. This is what each extension does, which ones should stop a trade, and how to check a mint.
Spam NFTs on Solana: what to do with them (hide or burn?)
A spam NFT in your Solana wallet cannot hurt you by sitting there; the claim site it advertises can. Hide compressed spam, burn regular Metaplex NFTs to get their rent back, and never open the link.