Drainers rarely steal keys. They get you to sign something: an approval, a permit signature, or a transfer disguised as a claim. Delivery is through phishing links, fake support in chat apps, compromised project accounts, and sponsored search results.
The tell is almost always urgency plus a signature request. Real airdrops do not need your seed-phrase, and a "verification" or "sync" request from any wallet or support agent is fraud, without exception.
Defences that work: bookmark the real URLs and never use search results for wallet apps, read what a hardware wallet actually displays before confirming, keep a burner-wallet for claims, and stop the moment anything is rushing you.
Related: token-approval, seed-phrase, burner-wallet, address-poisoning