Solana Wallet Safety: Approvals, Fake Tokens, Address Poisoning and Drainers

Updated | 4 min read | QUANTUM (QNT) community

Where the risk actually is

Solana's network rules do not let a stranger move your tokens. Problems arise when you give permission, or when you are tricked into sending funds to the wrong place. This guide builds on how wallet signing works, seed phrases and private keys and storing QNT safely. It is general education, not financial advice, and no habit removes risk entirely.

Approvals: delegates on Solana

Solana's docs explain that a token account owner can authorize a delegate to transfer or burn a set amount of tokens from that account. Revoking uses the Revoke instruction, which clears the delegate and resets the delegated amount to zero. Under the standard Token Program the owner must sign the revocation. Note a difference from Ethereum style approvals: most Solana swaps do not leave a lasting delegate, but some programs can. One tool guide reports that Phantom lists revocable permissions under Trusted Apps in settings, and Solflare has a delegation check, but features change, so look in your own wallet. Revoking also costs a small network fee.

The habit: approve only what you understand, keep amounts small, and review delegates after using a new app.

Fake and airdropped tokens

Scammers send random tokens to many wallets. A token account appearing in your wallet is not itself dangerous, but the token's page often links to a site that asks you to connect and sign to sell or claim. Do not click it. Hide or ignore the token. More in airdrop scams explained. Also, fake versions of real tokens exist, so confirm contract addresses as shown in verifying a contract.

Address poisoning

This is a trick, not a hack. An attacker creates an address that matches the first and last characters of one you use, then sends a small transfer so it appears in your history. A Solscan article and other analysts report that the trap works when you later copy the address from history instead of a trusted source. One analysis reported a loss of about 2.91 million dollars in November 2024 from this method. Low transaction fees make sending these decoys cheap, which is why it is common.

Drainers

A wallet drainer is a fake site, popup or message that asks you to connect and sign. The signed transaction can transfer tokens, move SOL, or set a delegate. Common bait is a fake mint, a fake airdrop claim, a support chat, or a link in a replied post. Habits that help:

  1. Type or bookmark official addresses. Do not follow links from replies or direct messages.
  2. Read the wallet's transaction preview. If it shows tokens leaving or an approval you did not expect, reject it.
  3. Be suspicious of urgency: claims that you must act now are a standard pressure tactic.
  4. Never type your seed phrase into any site, and no real support person will ask for it.
  5. Use a separate wallet with a small balance for new apps and mints.

Hardware wallets

A hardware wallet keeps your private key on a separate device and requires a physical confirmation for each signature. That protects against malware that reads your computer, but not against you approving a harmful transaction, so you still must read what the device shows. They are most useful for savings you do not trade often. Buy only from the maker, and write the recovery phrase on paper stored offline.

Also watch for bots and impersonators

Telegram and trading bots hold or request keys, and fake support accounts target people who post questions. See bot risks and memecoin scams. A reminder: the QNT memecoin is independent of Quantinuum Ltd, and anyone claiming company backing to get you to send funds should be treated with suspicion.

If you think you signed something bad

Move remaining assets to a new wallet created on a clean device, then revoke delegates from the old one if you can. Do not send funds to anyone who offers to recover them for a fee, as these are frequently follow up scams.

Sources and further reading

Reported as of 2026-10-09. Platform fees and rules change often, so check the primary pages before relying on any number. This is education, not financial advice. The QNT memecoin is independent of Quantinuum Ltd, the real company.

Frequently asked questions

What is address poisoning?

A scam where an attacker plants a lookalike address in your history, hoping you copy it by mistake. Copy addresses from a saved contact and compare the full string.

Is a token I did not buy dangerous?

The token account itself is not usually harmful, but links attached to it often lead to drainer sites. Ignore or hide it.

How do I remove a token delegate?

Use your wallet's permissions or approvals page or a revoke tool. The Revoke instruction clears the delegate, and under the standard Token Program the owner signs it.

Does a hardware wallet make me safe?

It protects the key from computer malware, but you can still approve a harmful transaction, so read each prompt.

Share on X

Keep reading

All How to buy and stay safe guides | Back to top | Search the site

Main pages: What is QNT? | Token information | How to buy | FAQ

QUANTUM (QNT) is the quantum sector memecoin on Solana. See the live chart, buys and burnt supply or read the token facts. Questions? Join the Telegram.