All articles
BeginnerScams

Fake Airdrop Scams and How to Spot Them

A fake airdrop dangles free tokens to get you onto a site that drains your wallet — through a malicious approval, an upfront fee, or a poisoned scam token already sitting in your address. Here is how each variant works and how to stay clean.

July 31, 2026
6 min read

Dive Deeper with AI

Click → prompt copied → paste in AI chat

A fake airdrop offers you "free tokens" to lure you onto a site that either asks you to connect and sign a malicious approval — which drains your wallet — or asks you to pay a "gas" or "claim" fee you never get back. Sometimes the scam tokens simply appear in your wallet unsolicited, and the drain triggers the moment you try to interact with them. Real airdrops never need your seed phrase and never require an upfront payment.

That is the short answer. The rest of this page breaks down each variant, because they do not all work the same way, and the defense is different for each.


Why the free-token bait works

Legitimate airdrops are real. Projects genuinely distribute tokens to early users, testnet participants, and governance voters. That is exactly why the scam is effective: "you qualified for an airdrop" is a plausible message, not an obvious lie. The attacker borrows the credibility of a real mechanism and points it at a malicious endpoint.

So the discipline is not "ignore all airdrops." It is verifying the source and never signing something you do not understand.


The four main variants

1. Phishing claim sites. You get a link — in a reply, a DM, a fake ad, or a spoofed email — to a "claim portal" that looks like the real project. It may ask for your seed phrase outright (game over if you type it), or it may just harvest a wallet connection to set up the next step.

2. Malicious signature or approval. The site asks you to "sign to claim." The signature is not a claim at all — it is a token approval (or a permit / setApprovalForAll) that authorizes the attacker's contract to move your tokens. Once signed, they drain the approved assets at their leisure, often minutes or days later.

3. Dust and scam tokens sent to your address. The attacker sends unsolicited tokens or NFTs to your wallet. The token's name or an embedded link points to a phishing site ("claim rewards at example‑site.com"). Interacting with the token — trying to sell, swap, or approve it — routes you through a malicious contract that triggers the drain.

4. Advance-fee ("send X to receive Y"). You are told you must send a small amount of crypto — a "gas fee," "unlock fee," or "verification deposit" — to receive a larger airdrop. You send it; nothing comes back. This is a classic advance-fee fraud wearing airdrop clothing.


How each tactic drains you, and the defense

Fake-airdrop tacticHow it drains youDefense
Phishing claim site asking for seed phraseYou type the phrase; attacker imports your walletNever enter a seed phrase on any website — ever
"Sign to claim" malicious approvalSignature authorizes a contract to move your tokens laterRead what you sign; reject unlimited approvals from unknown sites
Unsolicited scam tokens with poisoned nameInteracting routes you through a drainer contractDo not touch unexpected tokens; hide, do not sell
Advance-fee "send X to get Y"You pay a fee for tokens that never arriveReal airdrops never require an upfront payment
Fake claim ad or DM linkSends you to any of the above under a trusted logoOnly use links from the project's verified official channels

How to stay safe in practice

  • Do not interact with tokens you did not expect. If random tokens or NFTs appear, treat them as radioactive. Hide them in your wallet interface. Do not sell, swap, or approve them.
  • Never sign to "claim" from an unverified site. A real claim rarely needs more than a standard transaction, and never needs a blanket approval. If a signature request is vague or asks for approval over your assets, reject it.
  • Verify through official channels. Go to the project's website by typing the address yourself, and cross-check the airdrop announcement on its verified social accounts and docs. Ignore the link that was pushed to you.
  • Use a burner wallet for claims. Keep a separate wallet with minimal funds for interacting with new or unverified sites. If it gets drained, you lose nothing meaningful.
  • Revoke stale approvals. Periodically check and revoke token approvals using a reputable revocation tool, so an old or malicious approval cannot be used against you.
  • Assume urgency is a red flag. "Claim in the next hour or lose it" exists to stop you from checking. Real distributions give you time.

The honest part

Airdrops are not inherently scams, and pretending they are would leave you unable to claim legitimate ones. The problem is that the real mechanism gives cover to the fake one. You cannot tell a good airdrop from a bad one by the promise of free tokens — both promise that. You tell them apart by where the link came from and by what the site asks you to sign. Verify the source, and never sign blind.


FAQ

Are all airdrops scams? No. Legitimate projects do distribute tokens to real users, which is precisely why the scam works. The message "you got an airdrop" is believable. Judge each one by the source of the link and the nature of the transaction it asks for, not by the offer itself.

Random tokens appeared in my wallet — is that dangerous? Receiving them is harmless; interacting with them is not. Many are bait whose name or embedded link points to a drainer site, and trying to sell or approve them can trigger the attack. Leave them alone and hide them.

Do I have to pay a fee to claim an airdrop? A genuine claim may cost a normal network gas fee that you pay to the blockchain, not to the project. Any request to send crypto to an address to "unlock," "verify," or "receive" your airdrop is advance-fee fraud. Real airdrops never require an upfront payment to a person.

How do I claim an airdrop safely? Confirm the announcement through the project's official website and verified channels, navigate there yourself rather than via a pushed link, use a burner wallet, and read every signature request before approving it. If anything asks for your seed phrase or a blanket approval, stop.


Fake airdrops overlap heavily with approval phishing, where a single signature hands over your tokens. If you also farm real airdrops, learn to separate the genuine campaigns from the traps in our guide to airdrop farming, and keep the broader crypto scam red flags in mind for everything else.

Read also

Liked this article? Follow me!

@t0tty3
#fake-airdrops#scams#approval-phishing#wallet-drainer#dust-attack

Dive Deeper with AI

Click → prompt copied → paste in AI chat