Malicious code — usually injected into or hosted as a web front end — that induces a user to sign a transaction or approval transferring their assets to an attacker.
Why it matters
A drainer does not break cryptography. It obtains a genuine signature from the account owner by misrepresenting what is being signed. It is the mechanism behind front-end compromises such as the BadgerDAO incident and the Ledger Connect Kit compromise.
What you can check
A drainer earns nothing by breaking cryptography; it earns by getting a valid signature from the owner. That makes the decisive moment the prompt itself — what is being authorised, to which address, for how much — and the decisive question whether the interface asking and the device displaying agree.
Where it showed up
Records in the Incident Tracker that turn on this: BadgerDAO front-end injection, Ledger Connect Kit supply chain attack and Atomic Wallet user fund theft.
Not advice. Definitions are for understanding, not instruction. Nothing here is financial, legal, tax or security advice.