A fake airdrop promises free tokens from a protocol, NFT project, L2, or exchange if you “claim” on a website. The site asks you to Connect Wallet (MetaMask, Phantom, Coinbase Wallet, WalletConnect) and approve a transaction, or to paste a seed phrase “for eligibility.” Real airdrops never need your seed. Many claim pages are pure phishing that drain approvals the moment you sign.
This is different from fake cryptocurrency giveaway scams that tell you to send coins to get more back. Airdrop drains often take coins without a voluntary send, via malicious approvals. Telegram and DM cousins: Fake Telegram wallet drain scams. Broader map: Credit and debt scams.
Airdrop claim vs wallet drain
| What you see | What is happening |
|---|---|
| “Claim $ARB / $OP / $JUP / meme coin now” link in Discord, X, or Telegram | Look-alike domain; connect + sign = asset or approval theft |
| “Verify wallet for eligibility” that asks for 12/24 words | Seed phishing; wallet is emptied |
| Unlimited token approval popup you do not understand | Spender contract can empty that token later |
| “Gas fee” or “claim tax” payable in ETH/USDT first | Advance-fee layer on top of the drain |
| QR code to “official airdrop portal” from a stranger | Often a draining dApp, not the project’s site |
Login-style phishing for exchange passwords sits next door: Phishing and account takeover. Discord gift wrappers that lead to the same drain: Fake Discord Nitro scams.
How the script usually runs
- A real project announces or rumors an airdrop.
- Scammers clone the brand within hours: similar domain, fake support bots, pinned “claim” replies under the real announcement.
- You connect a hot wallet that also holds long-term savings.
- The site requests a signature or unlimited approval; a bot sweeps tokens and NFTs.
- Follow-on DMs offer “recovery” for a fee (a second scam).
Named wallets and chains do not make a link safe. MetaMask, Phantom, Ledger, Trezor, Uniswap, OpenSea, and major L2 brands are routinely impersonated.
Worked example: “claim portal” + unlimited approval
Devon sees a reply under a Coinbase or Uniswap post: “Official claim: airdrop-claim-secure.io.” He connects MetaMask from his phone, taps Approve on an unlimited USDC allowance, and signs a second “claim” message. Minutes later his USDC balance is zero; Etherscan shows a spender contract moving funds. Healthy version: Devon ignores reply-guy links, opens only URLs from the project’s bookmarked site or verified account bio he already trusts, and keeps large balances on a hardware wallet that never connects to random claim sites. He never types a seed into a webpage.
If payment cards or prepaid rails were also requested, treat that like any prepaid extract: Gift cards and prepaid debit risks.
Hard rules that prevent most drains
- Never enter a seed phrase or private key to “claim,” “sync,” or “validate” an airdrop.
- Treat unsolicited claim links in Discord, Telegram, SMS, and X replies as hostile until proven on a bookmarked official domain.
- Read every wallet popup: reject unlimited approvals you did not intend; revoke stale approvals on reputable revoke tools when you know what you are doing.
- Use a burner wallet with tiny balances for any experimental mint or claim; keep savings offline or on hardware.
- Real support will not DM you a claim portal. Impersonators will.
Checklist
- Ignore cold claim links; start from a bookmark or typed official URL.
- Never paste a seed phrase into a website or “support” chat.
- Reject surprise unlimited token approvals.
- Separate a claim/burner wallet from long-term holdings.
- Assume reply-guy and QR airdrops are drains until independently verified.
- If drained, move remaining assets from any still-connected wallet, document tx hashes, and report to FTC / IC3 as appropriate; ignore paid “recovery” DMs.
Educational only. Not legal, tax, or investment advice. Blockchain transfers are usually irreversible; verify URLs and signatures before you approve anything.