Start your 3-day free trial
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.


A fake crypto airdrop tries to turn a promised reward into permission to access your wallet, approve a token, sign a message, or reveal a recovery phrase. Do not connect because a token appeared in your wallet or because a countdown says the claim will expire. Verify the project, exact website, contract, network, and requested action through independent channels first.
Key Takeaways
- An unsolicited token or NFT is not proof that its claim website is legitimate.
- Open the project's known official channel yourself instead of following the message, token description, search ad, or direct-message link.
- A normal wallet connection still reveals an address to the site; later signature or approval requests can carry much greater risk.
- No legitimate airdrop needs your seed phrase or private key.
- If the story, domain, contract, network, and requested action do not agree, stop rather than trying one more prompt.
Public blockchains let another address send tokens or NFTs to your address without asking you first. That fact proves only that a transaction involving your address was recorded. It does not prove that the sender represents a real project, that the asset has value, or that a URL embedded in its name or description is safe.
Scammers exploit this gap. A token may display a tempting name, a claim deadline, or a website. The FBI has described malicious NFT airdrops that directed recipients to spoofed sites, requested wallet connections, and then attempted to steal credentials or assets.[1] Treat the object in your wallet as untrusted input, not as an invitation you must process.
This is different from Apple's AirDrop file-sharing feature. Here, “airdrop” means a blockchain distribution or a claim campaign, not a nearby-device transfer.
Start with the event, not the link. Ask whether you had a documented reason to be eligible: a project snapshot, an activity you actually completed, or an announcement you can find independently. An unexpected asset can be real, spam, worthless, or malicious; its presence alone does not answer that question.
Use this sequence:
The goal is agreement between several independently reached facts. One matching logo, social post, or search result is too weak because accounts, ads, and websites can all be impersonated.
Look for the domain from a channel you already trust. If you have never used the project, compare multiple first-party references, such as its documentation and verified public account, while remembering that a social account can also be compromised. Do not let a direct message define which account is “official.”
Read the hostname from right to left. A name such as project.example.com belongs to example.com, while project-example.com is a separate registration. Extra words such as “claim,” “bonus,” or “support” do not make a domain official. URL shorteners and QR codes hide this comparison and should not be the starting point.
MetaMask advises checking whether a campaign is listed through official channels and avoiding sites that ask for a Secret Recovery Phrase.[2] Bookmarking a verified project page before a campaign can reduce last-minute search and advertising risk, but a bookmark cannot protect you if the project itself is compromised. You still need to read current warnings.
The same token name can exist on several networks, and anyone may create a lookalike token. Compare the network identifier and full contract address with an official announcement. Do not rely only on a ticker, icon, price display, or wallet label.
A block explorer can show when the contract was created, how holders received the asset, and whether the address matches the published contract. It cannot certify that the project is honest. Explorer verification labels and source-code publication are useful context, not a guarantee that a claim is safe or economically worthwhile.
Be especially cautious when the token's only apparent liquidity comes from an unknown venue, when selling requires visiting one specified website, or when a small “unlock” payment is demanded. Do not send gas, taxes, verification deposits, or return payments merely because the sender promises a larger reward.
Connecting commonly lets a site see the selected public address and request actions. It does not normally give the site your seed phrase. The important question is what happens next: the site may request a login-style signature, a token approval, a permit, a transaction, or a network switch.
Read every wallet prompt on the wallet or hardware device, not only the page behind it. Check the origin, account, network, asset, spender, amount, destination, and whether the request is a message or a transaction. If the wallet cannot explain the request clearly, cancel. A friendly page cannot make an opaque prompt safe.
Ethereum.org warns that malicious approvals and signatures can give an attacker authority over assets even when the user believes they are only claiming a reward.[3] An unlimited token approval is not a harmless connection step. A message can also carry authentication or authorization meaning, depending on its structure.
Stop if any page, person, extension, or “support agent” asks for:
Do not test a suspicious page with your main wallet. A separate empty wallet reduces the assets immediately exposed, but it does not make malware, tracking, deceptive signatures, or later funding safe. Isolation is a risk-reduction measure, not proof of legitimacy.
Real campaigns still require judgment. Confirm eligibility and deadlines, read the project's own claim instructions, understand fees and tax or reporting consequences in your jurisdiction, and decide whether the value justifies exposing an address to another site. Do not assume that a verified project account makes every reply or promoted result authentic.
Before signing, capture the announcement and terms you relied on. This creates a record if the project changes a domain, pauses a claim, or reports a compromise. It also slows down the urgency that social engineering depends on.
If a claim uses a smart contract, the project should explain the network, official contract, expected prompt, and whether an approval is needed. Differences are a reason to stop and seek clarification through a channel reached independently.
First identify what happened. Merely viewing a page is different from connecting an address, signing a message, granting an approval, sending a transaction, installing software, or exposing a seed phrase. Preserve the URL, transaction hash, wallet prompt, time, and messages without continuing the conversation.
Disconnecting a site in the wallet may end a local session, but it does not necessarily revoke on-chain approvals. Use the wallet or network's documented tools to inspect permissions. If you revealed a recovery phrase or private key, treat the secret as compromised and follow the seed phrase exposure response; changing a wallet-app password is not enough.
For broader phishing containment, use the phishing protection guide. The crypto hacks overview explains why device, identity, permission, and custody failures need different responses.
Before connecting, you should be able to answer yes to all of these:
If one answer is no, wait. Missing a reward is less damaging than granting control you did not understand.
Usually the risk begins when you follow its instructions, visit a malicious site, install software, or authorize an action. Do not interact merely to hide, sell, or “unlock” it; follow your wallet's documented spam-handling method.
No. A connection commonly shares an address and enables requests, while an on-chain approval grants a spender defined authority. A deceptive flow may present them close together, so inspect every separate prompt.
No. Verified or established accounts can be impersonated or compromised. Confirm the same details through independently reached documentation and compare the exact claim destination.
No. An empty wallet can limit immediate asset exposure, but it does not validate the site, software, signature, tracking, or future behavior. Never import a valuable seed into that environment.
The token makes the story visible inside a wallet and can carry a name or URL that pushes the recipient toward a malicious claim. The transfer is marketing for the trap, not evidence of legitimacy.
No. A seed phrase reconstructs wallet keys. It is not an eligibility credential, support code, tax record, or claim password.
No. Network encryption does not authenticate a project's identity, interpret a wallet signature, or validate contract intent. Those checks require independent project, domain, contract, and prompt verification.
Disclaimer: This article provides general security information, not financial, investment, legal, tax, forensic, or project-specific advice. Blockchain actions may be irreversible, and procedures vary by wallet and network.
[1]FBI, Cybercriminals Defraud Hedera Hashgraph Network Non-Custodial Wallet Users Through Nonfungible Token Airdrops Disguised as Free Rewards: https://www.fbi.gov/investigate/cyber/alerts/2025/cybercriminals-defraud-hedera-hashgraph-network-non-custodial-wallet-users-through-nonfungible-token-airdrops-disguised-as-free-rewards
[2]MetaMask Help Center, How to tell the difference between a regular airdrop and airdrop phishing scams: https://support.metamask.io/stay-safe/protect-yourself/tokens-and-transactions/how-to-tell-the-difference-between-a-regular-airdrop-and-airdrop-phishing-scams
[3]Ethereum.org, Ethereum security and scam prevention: https://ethereum.org/security/
Sources checked 10 September 2026.
Related articles:
Sign up to experience all premium features at no cost.
*Available only to new users. Each user is limited to one trial.





