Wallet drained after connecting to a 'new DEX' that promised crazy APY, is my ETH gone?

asked 21d ago12 views31 answers
0

Feeling pretty stupid right now. I saw this ad on X (Twitter) for a new Decentralized Exchange (DEX) that was offering like, 500% APY on ETH staking. I know, I know, red flag city. But I was just looking at my portfolio and feeling a bit down, thought maybe a quick win could help. It looked pretty professional, had a decent UI, lots of excited comments on their social posts. So I connected my MetaMask wallet. Didn't even think twice. Approved a transaction, thinking it was just for staking. Next thing I know, my entire ETH balance is gone. Like, completely wiped out. I immediately disconnected my wallet, revoked permissions, everything. But it was too late. I've heard about wallet drainers but always thought I was too careful for this. My partner is furious. Is there literally *any* chance of getting it back? I traced the transaction on Etherscan, and it went to a completely different wallet address. It's about $4,000 worth of ETH. Any advice beyond "you're an idiot" would be really appreciated.

Mentioned in this discussion
MetaMask· neutral

31 Answers

38

Been there, done that, got the empty wallet. Not exactly a DEX but a fake liquidity mining pool that promised mad returns. Similar setup – connected my Trust Wallet, approved what looked like a benign transaction, poof, gone. It was like 0.8 BNB but still stung like hell. This was about 6 months ago. I reported it to the local police here in Bristol and also to a few crypto scam reporting sites, gave them all the TX IDs and everything. Never heard a peep back. Ended up just chalking it up to experience. It's a brutal lesson, but it really hammered home the 'do your own research' and 'if it's too good to be true' lessons. For anything that requires connecting your wallet, I now literally check *everything* – contract address, reviews, social media age, everything.

Jack Evans · Bristol, United Kingdomanswered 21d ago
45

Ah, Jonathan, I'm really sorry to hear this happened to you. Wallet drainers are absolutely brutal, and they prey on exactly that moment of wanting a quick win. It's not about being an idiot, it's about sophisticated social engineering and often very convincing fake platforms.

So, about recovery. The harsh truth is, once a transaction is on-chain and confirmed, especially to a scammer's address, it's incredibly difficult to reverse. The decentralized nature of crypto is a double-edged sword here – great for freedom, terrible for fraud reversal. When you 'approved a transaction' you likely signed a malicious smart contract allowing them to transfer your ETH. That's how drainers work.

However, 'incredibly difficult' isn't 'impossible'. Your best bet is to report this *immediately*. File a report with the Singapore Police Force, specifically their Anti-Scam Centre. They often have contacts with global law enforcement agencies. Also, file a report with your local equivalent of the FBI IC3 or FTC, even though you're in Singapore, as crypto scams are cross-border. Provide them with everything: transaction hashes, the scam DEX URL, screenshots of the X ad, everything.

While law enforcement might not get *your* funds back directly, tracing firms like Chainalysis or TRM Labs work with these agencies to track illicit funds. If the scammer moves funds to a centralized exchange (like Binance or Coinbase), there's a slim chance those exchanges, when presented with a police report, might freeze the assets. It's a long shot, but it's the only legitimate path.

Beware of anyone contacting you now, promising recovery if you pay an upfront fee. Those are almost always recovery scams, preying on victims twice.

Saoirse Lynch · Belfast, Irelandanswered 21d ago
22

Oh Jonathan, I'm so sorry this happened to you. Please don't beat yourself up too much. These scammers are incredibly sophisticated and they know how to exploit emotions and hopes. It could happen to anyone, especially when they're feeling a bit vulnerable. It's a horrible situation to be in, and the feeling of betrayal is just awful. Just focus on what you can do now, okay? Saoirse gave really good advice about reporting it. Take a deep breath. We're all here for you.

Niamh Burke · Waterford, Irelandanswered 21d ago
11

Yeah, look, 500% APY should scream 'scam' from a mile away. It's rough, mate, but that money's probably gone. Once it's off your wallet and on the blockchain, it's like cash through a shredder. These 'wallet drainers' are just smart contracts you unknowingly approve to give away your funds. Tracing it just means you can see it's gone. Police are unlikely to get involved for $4k, tbh, it's a small amount in the grand scheme of crypto crime and they're so under-resourced for this stuff. Best to consider it a very expensive lesson and harden up your security practices for next time.

Thomas Walker · Newcastle, Australiaanswered 21d ago
29

Man, I feel your pain so much. I fell for something similar, not a DEX but a fake investment platform that promised crazy returns. Lost about 3 ETH myself, which was a huge chunk of my savings. I remember that sinking feeling, checking Etherscan over and over hoping I'd made a mistake, but no, just gone. My wife was absolutely livid. I reported it to the police here in Edinburgh, but they basically said it's a global problem and hard to trace. Never heard anything back. It's been over a year now, and I've pretty much accepted it's a goner. It sucks. Really, really sucks.

George Wright · Edinburgh, United Kingdomanswered 21d ago
18

Sending you so much positive energy, Jonathan. It's easy to look back and say 'red flag', but in the moment, with clever marketing and the promise of a solution, it's completely understandable how you could fall for this. Don't let anyone make you feel bad. What's important now is to protect yourself from further harm. Change any passwords that might be linked, revoke *all* permissions from any dApp on your MetaMask (not just the scam one), and be super vigilant about anyone contacting you about recovery services. As others said, only legitimate police and specialized firms have even a tiny chance, and they won't ask for upfront fees. Stay strong.

Grace Johnson · Perth, Australiaanswered 21d ago
33

Jonathan, this is a classic wallet drainer technique. When you connect your MetaMask and 'approve a transaction' for staking on a malicious site, you're not just giving permission to stake. You're actually signing a transaction that grants the scammer's contract the ability to transfer *all* of your ETH (or whatever token) out of your wallet without any further interaction from you. This is known as giving an 'unlimited approval' or 'token allowance' to a malicious contract.

To prevent this in the future, always be extremely cautious with dApp connections. After you're done interacting with a dApp, it's good practice to revoke any approvals or allowances you've granted, especially for tokens. You can do this through sites like Etherscan's Token Approvals page (for ERC-20 tokens) or specific revoke tools for other chains. This limits the damage if a site you've interacted with later turns out to be compromised or malicious. For now, as others have said, reporting to local authorities is your only official recourse.

Laura Meyer · Berlin, Germanyanswered 21d ago
16

Ugh, this sucks, Jonathan. I'm in Singapore too and got caught out by a similar thing last year, but with a fake NFT mint site. The FOMO was real, and it looked so legitimate. My 0.5 ETH was gone in a flash. I was so embarrassed I almost didn't tell anyone. But I did report it to the Singapore police (CAD) and gave them all the transaction details. They were quite professional, but also very clear that crypto recovery is incredibly difficult. They said they'd investigate, but I never got my money back. It's a hard pill to swallow, but sometimes you just have to learn from it and move on. Don't fall for the recovery scams now, those are everywhere.

Hannah Tan · Singapore, Singaporeanswered 21d ago
9

Oh god, Jonathan, I just want to give you a virtual hug. It's such a horrible, gut-wrenching feeling. I had my Trust Wallet drained by a very similar scam – saw it on Insta, 300% APY, connected, approved, gone. All my SOL, gone. It was less than you, about 800 quid, but it felt like the end of the world. My partner was worried sick. I followed all the advice – reported to police, told my bank, all that. Nothing. Not a single penny back. It's a bitter pill. But you're not alone, loads of us have been caught by these sophisticated scams. Just try to see it as a lesson learned, albeit a very, very expensive one.

Aoife Byrne · Belfast, Irelandanswered 21d ago
36

To build on what Laura mentioned about revoking permissions, this is a crucial preventative step for *everyone* who interacts with dApps. When you approve a token allowance, you're essentially giving a contract permission to spend your tokens up to a certain amount, or sometimes an unlimited amount. Malicious actors leverage this. Always check the approval amount before confirming a transaction. If it says 'unlimited', be extremely wary unless you fully trust the protocol.

After interacting with any dApp, especially new or unfamiliar ones, make it a habit to visit a token approval checker like revoke.cash or etherscan.io/tokenapprovalchecker for Ethereum (similar tools exist for other chains). These tools let you see all the allowances you've granted from your connected wallet and revoke any that are unnecessary or suspicious. This won't get your already-drained ETH back, but it's a vital security measure to prevent future wallet drains if you accidentally approve something malicious again.

Grace Brown · Cardiff, United Kingdomanswered 21d ago
5

Oof, mate. That's a rough one. 500% APY is definitely a massive red flag, especially from an unknown DEX. Scammers prey on that FOMO. Connecting your wallet and approving a transaction without fully understanding what it does is how they get ya. Once that token approval is granted, they can drain whatever they want, not just ETH. What you need to do now is report it to the FBI's Internet Crime Complaint Center (IC3). They collect these reports and can sometimes track patterns, even if recovery is unlikely for your specific case. Just file a detailed report there, it's the official channel.

Liam de Jong · Nijmegen, Netherlandsanswered 21d ago
4

Hey, don't beat yourself up too much. It happens to the best of us, even people who think they're super careful. That rush of seeing high APY and thinking 'what if?' is a powerful thing. Your partner will probably calm down once the shock wears off. The ETH is likely gone, unfortunately. These drainers are sophisticated. The best thing you can do now is learn from it, and honestly, just try to move on. Don't let it stop you from engaging with crypto, but be way more cautious moving forward. Maybe stick to well-established platforms for a while.

James O'Connor · Dublin, Irelandanswered 21d ago
3

This is precisely the kind of trap they set. "New DEX", "Crazy APY" – these are textbook scam phrases. X is unfortunately riddled with these bots and fake projects. Even if the UI looked good, that's part of the illusion. They'll make it look legitimate to trick you into signing permissions. If you ever connect your wallet to a site and later suspect it, revoke all permissions IMMEDIATELY using a tool like Revoke.cash. It's not foolproof if they already took the funds, but it stops further access. Report it to the FTC as well; collective reports help them identify trends.

Mia Meyer · Cologne, Germanyanswered 21d ago
5

The scenario you've described is a classic malicious smart contract interaction, often facilitated by a fake front-end that mimics a legitimate DEX. The key is the approval transaction. When you approved a token, you essentially gave that contract permission to move your assets. The UI on X often has fake engagement, making it look popular. For future reference, always check the contract address *before* interacting, and use a hardware wallet for any significant amounts. Hardware wallets require physical confirmation for every transaction, making this kind of remote draining impossible.

James O'Brien · Belfast, Irelandanswered 21d ago
4

Oh man, that sounds absolutely devastating. I can only imagine how you're feeling right now. $4k is a lot of money, and to lose it like that would be gutting. Don't let your partner's anger get to you too much; focus on what you can do now, which is mainly just reporting it. You did the right thing by disconnecting and revoking permissions afterwards, even if it was too late. It shows you're trying to mitigate further damage. Keep your head up, these scams are rampant.

Charlotte Harris · Melbourne, Australiaanswered 21d ago
5

Right, so the issue is the setApprovalForAll or a similar allowance function that was likely hidden within the 'staking' transaction. The scammer's front-end calls this to grant their contract infinite or near-infinite access to your ETH on the ERC-20 standard (or WETH if that's what you were staking). Once approved, their bot monitors your wallet and instantly sweeps any ETH that appears. You can't get it back once it's in their control, as they'll have already moved it through multiple mixers or liquidity pools. Best practice: use a separate 'burner' wallet for any new, unverified DeFi protocol. Never connect your main wallet with significant funds to unknown sites.

Charlotte Jones · Brisbane, Australiaanswered 21d ago
3

Wait, you connected MetaMask to a random DEX from an X ad? And approved a transaction? Lol. Dude, you basically handed them the keys. 'Crazy APY' is code for 'scam'. No legitimate platform offers that kind of return. You're lucky it was only $4k and not your entire life savings. What can you do? Nothing, really. The ETH is gone. Learn your lesson. Stop clicking on ads and stop falling for get-rich-quick schemes. If it sounds too good to be true, it is. Ffs.

Aaron Yeo · Singapore, Singaporeanswered 21d ago
6

The exploit here is a classic bait-and-switch using a malicious smart contract. The front-end you interacted with was designed to trick you into authorizing a token spend for the scammer's contract. The 'staking' transaction was likely the approval, allowing them to transfer your ETH. The fake comments on X are social engineering. To prevent this in the future, always verify the contract address of any DEX or protocol you're using through a reputable source like CoinGecko or CoinMarketCap, and cross-reference it with their official social media. Never trust a link directly from an ad or unverified post.

Yi Tay · Singapore, Singaporeanswered 21d ago
5

I'm so sorry this happened to you. I lost about $2k last year to a similar phishing scam, though mine was an email pretending to be from Coinbase. I know how it feels, that sinking feeling in your stomach, and the embarrassment. My wife was mad too. I reported it to IC3, but like you, never heard anything back. It's a tough lesson. I've since set up a hardware wallet and I'm super paranoid about every single transaction now. Just be extra careful out there, man.

Jack Wright · London, United Kingdomanswered 21d ago
4

This is why I tell everyone: never trust a DEX advertised on social media with promises of insane returns. It's a trap. These ads are paid for by scammers, and the fake comments are bots. They use professional-looking UIs to lure you in. The moment you connect your wallet and approve *any* transaction, you're at risk. The ETH is gone. Your best bet is to file a report with the FTC. While they might not recover your funds, reporting helps them build cases against these types of operations. Don't connect your primary wallet to anything you haven't thoroughly vetted.

Charlotte Cote · Winnipeg, Canadaanswered 21d ago
3

Man, that's a brutal lesson. The high APY bait is so common. You clicked on an ad on X, which is already a huge red flag – they're full of crypto scams. The "professional UI" is just to make it look legit. Once you connect your wallet and approve a transaction, you're giving them permission to drain it. The ETH is definitely gone. Don't beat yourself up too much, it's a harsh reality of the crypto space. Maybe consider using a hardware wallet for your main holdings and a separate, smaller wallet for interacting with new dApps.

James O'Neill · Galway, Irelandanswered 21d ago
5

Okay, let's break this down. The 'new DEX' was a front-end for a malicious contract. When you connected MetaMask, you gave it access. The 'staking' transaction was likely an approval function that granted the scammer's contract permission to transfer your ETH. They have bots that monitor for these approvals and immediately sweep funds. Reporting is essential. File a complaint with the FBI's IC3. Also, for future safety, use a tool like 'Debank' or 'Zapper' to review your wallet's token approvals. You can revoke them directly from those dashboards. This is crucial for preventing further drainages if you ever accidentally interact with a bad contract again.

Joshua Koh · Singapore, Singaporeanswered 21d ago
3

Yeah, the whole "crazy APY" thing is the oldest trick in the book for crypto scams. If it sounds too good to be true, it absolutely is. These DEX ads on X are notorious for being scams. The UI might look good, but the backend is pure theft. Once you connect your wallet and approve a transaction, they have control. The ETH is gone, sorry to say. Reporting it to IC3 is the official route, but don't expect miracles. My advice? Stick to well-established DEXs like Uniswap or Curve for now, and always, always do your own research.

Tyler Jones · San Diego, USAanswered 21d ago
4

That sucks, dude. Seriously. The allure of high APY can blind anyone, especially when you're feeling a bit down. The crypto ad space on X is a minefield. They make these fake UIs look so convincing. Once you authorize a transaction, even one you think is for staking, it can be a permission grab. The ETH is gone. The one thing you can do is report it to the FTC. They collect these kinds of complaints and use them to track down fraudulent operations. It's unlikely you'll get your money back, but reporting helps others avoid the same fate.

Amelia Anderson · Perth, Australiaanswered 21d ago
5

Classic honeypot, mate. The 'new DEX' with insane APYs is a dead giveaway. They're essentially paying for ad space on X to attract victims. The UI is a smokescreen. When you connected your wallet and approved the transaction, you likely granted the scammer's contract permission to move your ETH. It's gone. There's no getting it back. The key takeaway here is to *never* trust a link or an offer from an ad on social media for DeFi. Always go directly to the official website of a known DEX, or use a DeFi aggregator that verifies contracts.

Mia Gauthier · Halifax, Canadaanswered 21d ago
3

Oh no, that's awful. I've heard stories like this so many times. The high APY promise is such a common scam tactic. Honestly, the ETH is probably lost for good. These drainer bots are super fast. What you *should* do, though, is report it to the FBI's IC3. It's important to get these incidents on record. Even if your money isn't recovered, these reports help law enforcement track the scammers. Next time, be super careful with wallet connections – maybe use a hardware wallet or a dedicated burner wallet for new DeFi protocols.

Aaron Ng · Singapore, Singaporeanswered 21d ago
5

This is a harsh but common lesson in DeFi. Those 500% APY offers from unknown DEXs advertised on X are almost universally scams. The UI and fake comments are designed to build trust. Connecting your wallet and approving a transaction, especially one that grants token allowances, is how they drain funds. The ETH is gone. However, for future reference, you can use tools like Etherscan's 'Token Approval Checker' or third-party sites like Revoke.cash to view and revoke any existing approvals on your wallet. Do this regularly, especially after interacting with new protocols.

Lily van der Merwe · East London, South Africaanswered 21d ago
4

Ah, the classic 'high APY scam'. Brutal. You saw an ad on X, which is like the Wild West for crypto scams right now. The professional-looking UI and fake comments are designed to fool you. When you connected your wallet and approved a transaction, you gave permission for them to take your ETH. It's gone. The best thing you can do now is report it to the FTC. They gather this data. And for the future? Always use a hardware wallet for significant amounts. They require physical confirmation, stopping remote drains like this.

Henry Brown · Brisbane, Australiaanswered 21d ago
3

Wow, that's a tough break. 500% APY is a huge red flag, especially from an unknown DEX advertised on X. You connected your wallet and approved a transaction – that's the critical step where they gain access. The ETH is gone. I know it's hard, but try not to dwell on it. You did the right thing by disconnecting and revoking permissions afterwards. For future reference, consider using a dedicated 'burner' wallet for any new or untrusted DeFi interactions. Keep your main wallet with significant funds completely separate and only connect it to audited, reputable platforms.

Lina Bauer · Leipzig, Germanyanswered 21d ago
5

That's a textbook scam. The high APY bait, the X ad, the professional-looking UI – it's all designed to trick people. When you connect your wallet and approve a transaction, you're giving them the keys. The ETH is gone. There's almost no chance of recovery. You should report it to the FBI IC3. They collect these complaints. For future safety, always use a hardware wallet like a Ledger or Trezor. They require physical confirmation for every transaction, making this type of drain impossible. It's a small investment for peace of mind.

Michael Pretorius · Bloemfontein, South Africaanswered 21d ago
3

Damn, that's rough, mate. $4k is a chunk of change. It's super easy to get sucked into those "too good to be true" APYs, especially when you're feeling a bit low. The social proof with fake comments and slick UI is a classic tactic. Unfortunately, once that ETH is out of your wallet and into theirs, the chances of recovery are slim to none. The scammers are usually long gone before you even realize what's happened. Best bet is to report it, even if it feels futile. You can file a report with the FBI's Internet Crime Complaint Center (IC3). They collect this data and sometimes patterns emerge that help them track these operations. Also, make sure you haven't interacted with *any* other suspicious links or dApps recently. Stay vigilant with revoking permissions on sites you no longer use.

Henry Martin · Gold Coast, Australiaanswered 20d ago

Your answer

You'll be asked to sign in to post.