Airdrop scams are effective because they don't need to hack anything. They just need you to sign one transaction. No exploit, no breached server, no stolen password — you hand over access yourself, and the blockchain faithfully executes it.
Understanding the mechanism makes the warning signs much easier to see.
How a wallet drainer actually works
A drainer is a script hidden behind a "Claim" button. When you connect your wallet and click claim, it doesn't send you tokens. It asks you to sign one of two things:
- A malicious approval — permission for a contract to spend your tokens. Once granted, the attacker moves them out at their leisure.
- A disguised transfer — a transaction that looks like a claim but is actually sending your assets elsewhere.
Both require your signature. Which means your wallet is the last line of defense, and the only thing standing between you and an empty balance is whether you read what you're approving.
The 9 red flags
1. It arrived unsolicited in a DM
Treat unsolicited airdrop DMs as high-risk. If a stranger — or an account you don.t recognize — sends you a claim link, verify the opportunity independently through the project.s official channels before interacting with it.
2. The domain is almost right
Extra hyphens, a different TLD, a slightly misspelled word. Read the URL character by character. Better yet, don't use their link at all — navigate to the project yourself.
3. It asks for your seed phrase
This is never legitimate. Not for verification, not for "syncing," not for "unlocking," not for support. There is no exception.
4. It asks you to pay first
"Send 0.1 ETH to cover gas and receive 5,000 tokens." No. Real airdrops cost you nothing beyond the network fee of the claim transaction itself, which goes to the network — not to a person.
5. There's a countdown timer
Manufactured urgency is the oldest trick in the book. If a page is pressuring you to act in the next few minutes, that pressure exists to stop you from thinking.
6. You never interacted with the project
If you've never heard of the project and never used it, why would it reward you? Unsolicited "rewards" for a project you've never touched are almost always bait.
7. The wallet prompt asks for unlimited approval
Read the approval screen. If a claim requires unlimited spending permission over a token you actually value, stop and reconsider.
8. The token appeared in your wallet unannounced
Random tokens showing up in your wallet are a common lure. Interacting with them — trying to swap or "claim" them — often triggers the trap. Leave them alone.
9. Nobody official is talking about it
Cross-check. If a major airdrop were live, the project's official channels would say so. If the only source is the page itself, that's your answer.
Your pre-flight checklist
Before signing anything, run through this:
- Am I on a wallet that holds nothing valuable?
- Did I navigate here myself, from a source I trust?
- Does the contract address match the official documentation?
- Do I understand what this transaction does?
- Is the approval limited, or unlimited?
- Is anyone rushing me?
If any answer makes you uncomfortable, close the tab. There will be other airdrops. There will not be another portfolio.
Many serious wallet-draining attacks require an approval or signature, but other risks can also exist. Slow down whenever your wallet asks for authorization and review exactly what you.re approving.