Malicious code — usually injected into or hosted as a web front end — that induces a user to sign a transaction or approval transferring their assets to an attacker.
Why it matters
A drainer does not break cryptography. It obtains a genuine signature from the account owner by misrepresenting what is being signed. It is the mechanism behind front-end compromises such as the BadgerDAO incident and the Ledger Connect Kit compromise.
Not advice. Definitions are for understanding, not instruction. Nothing here is financial, legal, tax or security advice.