Airdrop Scams and Fake Claim Sites: How to Spot Them Before You Sign
The cruelest part of airdrop farming is that the scams target exactly the people doing everything else right. You do the genuine activity, you keep your wallets clean, you wait for months, and then a message says your tokens are ready to claim, and in one hurried click it all goes to someone else. The drains that empty wallets are rarely sophisticated exploits. They’re ordinary manipulation aimed at a moment of excitement. This is a plain guide to how airdrop scams actually work, the specific patterns to recognize, and the handful of habits that stop nearly all of them before you ever connect a wallet or sign a thing.
Why airdrops attract scammers
Airdrops are perfect bait because they combine free money, urgency, and a genuine expectation. People are actually waiting for tokens, so a message saying yours are ready doesn’t feel absurd. It feels expected. Scammers exploit that primed anticipation, dressing a drain up as the very thing you were hoping for. The emotional setup does most of the work, because someone excited about a long awaited claim is far less careful than someone approached out of nowhere. Understanding that the scam runs on your own genuine expectation is the first defense, because it tells you to be most careful precisely when something feels most like good news.
The fake claim site
The classic scam is the fake claim site, a page that looks like an official token claim, reached through a link from a fake announcement, an ad, a reply, or a direct message. It mirrors the real branding closely enough to pass a glance. You connect your wallet to claim, and the site presents a transaction or signature that, instead of claiming anything, grants the attacker permission to move your funds or drains them directly. The whole thing hinges on you being on the wrong site while believing it’s the right one, which is why verifying where you actually are is the single most important check you can make.
Malicious approvals
Many drains work through the token approval mechanism. The fake site asks you to approve a token, framed as a necessary step to claim. What you’re actually granting is permission for the attacker’s contract to move that token from your wallet, often without limit. It looks like a routine approval because approvals are routine, which is exactly what makes it effective. Once granted, the attacker moves the tokens at their leisure. This is why understanding what an approval really does, and why a claim would rarely need broad permission over your existing tokens, is such a powerful shield against this whole category.
Malicious signatures
More subtle than approvals are malicious signature requests, off-chain messages that don’t look like transactions at all. Some signatures authorize token transfers or grant permissions through mechanisms that need no gas and produce no obvious on-chain warning. A request to sign a message to “verify your wallet” or “claim” can, in the wrong context, be an authorization to move your assets. Because it doesn’t look like spending, people sign these far too readily. Treating every signature request with the same seriousness as a transaction, and refusing to sign anything you don’t fully understand, closes a door that opaque signatures otherwise leave wide open.
The mystery token in your wallet
A common passive scam is the token that simply appears in your wallet unrequested, often named to look like a reward or to lure you to a site to claim its value. Interacting with it, trying to sell or claim it, sends you into the trap: a site or contract designed to drain you. The defense is simple. Don’t interact with tokens you didn’t expect. An unrequested token appearing is not a gift, it’s bait, and the correct response is to ignore it entirely. Curiosity about what it might be worth is exactly the impulse the scam is built to exploit, so leave it sitting there and touch nothing.
Impersonation and fake support
A whole category is human rather than technical: impersonation. Fake official accounts, fake support staff, fake team members reaching out to “help” you claim or resolve a problem. Real support essentially never messages you first asking you to connect a wallet or share anything sensitive. Anyone who does is a scammer, without exception. The urgency and authority are manufactured to rush you past your judgment. The rule is absolute and worth memorizing: unsolicited contact offering help with a claim is a scam. Real teams don’t direct message you to walk you through connecting your wallet, and no legitimate process ever needs your seed phrase.
Urgency is the tell
Almost every scam shares one ingredient: manufactured urgency. Claim now before it expires, limited window, act fast or lose your allocation. That pressure is deliberate, because haste is the enemy of the checks that would expose the scam. A genuine distribution doesn’t evaporate in the next 5 minutes, and a real claim window isn’t a countdown designed to make you skip verification. So treat urgency itself as a red flag, independent of anything else. The more a message pushes you to hurry, the more certain you should be that slowing down is exactly what it doesn’t want you to do, and exactly what you should do.
Verify the source, always
The master defense behind all of this is verifying where information and links actually come from. Use official sources you reached independently, bookmarks you saved, the project’s verified channels, not links from replies, ads, direct messages, or search results, all of which scammers buy and rank. When a claim is announced, go to the project’s real site the way you always reach it, not through the exciting link someone handed you. This one habit, never trust the link that came to you, always navigate yourself, defeats the large majority of these scams, because nearly all of them depend on getting you onto a site you didn’t reach on your own.
Simulation catches drains
Wallet features that simulate transactions are your technical safety net here. A wallet that simulates a transaction shows you, before you sign, that a “claim” is actually draining your tokens or granting sweeping approval. A security scanning wallet flags a known malicious contract. These tools turn an invisible trap into a visible warning at the decisive moment. This is the concrete payoff of choosing a protective wallet: it can catch the drain that your excitement missed. Reading what the simulation tells you, and stopping when it says something is wrong, is often the last line that saves a wallet after every earlier check was skipped in the rush.
Revoke and hardware wallets
Two more habits blunt the damage even if something slips through. Keeping approvals limited and running periodic revoke sessions means a malicious approval you granted has less to take and a shorter life. Keeping real value behind a hardware wallet means a browser-side trick can’t move funds without the physical device confirming, giving you one more deliberate checkpoint to notice something is wrong. And isolating exploration in a low value wallet means the wallet most likely to touch a scam site is the one with the least to lose. These are the same defenses that matter for approval hygiene generally, and they’re exactly what contains a scam that gets past the first checks.
Check it in a block explorer
When you’re unsure whether a token or contract is legitimate, a block explorer lets you look before you leap. You can see a token’s history, whether a contract is verified, how it has behaved, and whether it matches what an official source says. This takes a few minutes, and it’s a few minutes well spent when real value is at stake. It won’t catch everything, but it turns a blind leap into an informed one, and it’s another habit that costs almost nothing and occasionally saves everything. The willingness to stop and check, rather than click and hope, is the through line of every real defense here.
If you think you were hit
If you fear you interacted with a scam, speed matters. Immediately revoke any approvals you may have granted using a revocation tool, from a safe device. Move remaining assets from an affected wallet to a secure one if it’s safe to do so, being careful not to compound the mistake in a panic. And understand that most on-chain theft is irreversible, which is precisely why prevention carries all the weight. There’s no support line that reverses it, and, painfully, anyone who appears offering to recover your stolen funds is almost always a second scam targeting the freshly desperate. The only reliable protection is the one applied beforehand.
Building the reflexes
All of this reduces to a few reflexes worth making automatic. Slow down when something feels like good news. Never trust a link that came to you, navigate to sources yourself. Treat every signature and approval as serious, and read what your wallet simulates. Ignore unrequested tokens and unsolicited help. Keep value on hardware and exploration on a throwaway wallet. And remember that urgency is manufactured to make you skip these very steps. Once these become habits rather than decisions, nearly every scam in this space simply bounces off, because it depended on a hurried lapse you no longer provide.
Upfront fee and deposit scams
One blunt variant deserves naming: the scam that asks for money upfront. A claim that requires you to first send a gas fee, a deposit, or a small payment to “unlock” your tokens is a scam, plainly. Real distributions don’t require you to pay to receive them, beyond the ordinary network gas of a legitimate claim transaction you initiate yourself. Any site or message demanding an advance payment to release a reward is taking your payment and giving nothing back. The moment a claim asks you to send funds first rather than simply signing a genuine claim, stop, because that request has no honest version anywhere.
Seed phrase requests are always fatal
The brightest line of all, and it’s worth ending on, is the seed phrase. Nothing legitimate ever asks for it. Not a claim site, not support, not a wallet verification, not a connection step, not ever. A seed phrase request isn’t a risk to weigh, it’s a guaranteed theft, because whoever has it owns the wallet completely and permanently. No genuine process needs it, and no explanation for why they need it is real. If anything, anywhere, for any reason, asks you to enter or share your seed phrase, it’s a scam with total certainty, and the only correct action is to close it and walk away.
The honest takeaway
The scams that empty wallets aren’t clever code. They’re ordinary manipulation aimed at your genuine excitement, and they’re beaten by ordinary, boring discipline. Verify every source and navigate yourself. Treat urgency as a warning, not a reason to rush. Understand what approvals and signatures actually do, and let a protective wallet show you. Isolate value, revoke regularly, and never touch unrequested tokens or trust unsolicited help. Do those consistently and you keep what all the genuine work was for, because the cruelest way to lose an airdrop is to do everything right and then hand it away in a single hurried click.
For the fuller writeup of how these scams work and how to shut them down, head back to the homepage.
Get new guides and videos first — join the Telegram channel.