TrustDex › Guides › Airdrop scams
Airdrop scams, decoded: dusting, drainer links and fake claims
Tokens you never asked for showing up in your wallet is not luck — it's a fishing lure cast at scale. The dust itself is harmless. What it invites you to do next is the attack.
Open almost any active wallet and you'll find them: tokens you never bought, NFTs you never minted, names like "5000USDT-voucher" or a famous project's ticker with a website baked into it. Sending them costs the scammer almost nothing, because on most chains a single transaction can spray a worthless token to thousands of addresses at once. The economics only work because a tiny fraction of recipients does the one thing the token exists to provoke — and that action, not the airdrop, is what empties wallets.
This guide separates the three layers of the scheme — the dust, the destination, and the signature — so the next unexpected "reward" in your wallet reads as what it is: unsolicited advertising for a trap.
Found a mystery token in your wallet?
Paste its mint address before touching it — mass-dusted scam tokens tend to light up a scan immediately.
Why anyone would send you free tokens
Legitimate projects airdrop for a reason you can articulate: rewarding past users, decentralizing governance, bootstrapping a network. Scammers airdrop for a different reason — an unsolicited token is the cheapest way to place a clickable message inside your wallet UI, past every spam filter that guards your inbox. The token's name is the ad ("Claim at ..."), its metadata carries the link, and your own curiosity does the delivery. Some campaigns add a pricing trick: the scam token trades against itself on a pool the scammer controls, so your wallet may display the dust as "worth" hundreds of dollars. That number exists to make ignoring it feel expensive.
The dust layer: tokens, NFTs, and memo spam
The bait takes a few forms depending on the chain. Fungible dust — a few thousand units of a token named after a real protocol or a fake voucher. NFT spam — an image whose entire artwork is a URL and an instruction. Memo or metadata spam — transfer notes attached to tiny native-coin deposits, common on chains with cheap memo fields. All three share one property that matters more than anything else in this guide: receiving them changes nothing about your security. Tokens cannot execute code on arrival. No balance sitting in your wallet can move your other assets. The dust is inert until you interact with it or with the address it advertises.
The trap is participation, not possession. Every airdrop drain in the wild requires a step you take: visiting the printed URL, connecting a wallet, and approving something. Refuse that step and the entire kill chain dies in your token list, worth exactly nothing and threatening exactly nothing.
The destination: anatomy of a fake claim site
Follow the printed link (don't) and you land on a site built to feel official — cloned branding from a real project, a countdown, an eligibility checker that congratulates every address it's shown. The eligibility theater matters: being told your specific wallet "qualifies for 2,400 tokens" converts a stranger's website into your pending payout, and people protect payouts. The connect-wallet button works normally, because connecting is harmless and builds trust. The harm is queued behind the button labeled Claim, which does not claim anything — it asks your wallet for a signature or transaction whose true effect is written in the fine print your excitement is designed to skip.
What the "claim" actually asks you to sign
Drainer kits are modular, and the request they serve depends on what your wallet holds. The table below is the field guide — the left column is what the site says, the middle is what the wallet prompt really does.
| Pitched as | Actually is | Effect if signed |
|---|---|---|
| "Claim your airdrop" | Token approval / permit for your valuable tokens | Drainer can transfer those tokens anytime, now or weeks later |
| "Verify wallet ownership" | Off-chain order/listing signature (marketplace or intent format) | Your NFTs or tokens "sold" to the attacker for ~zero |
| "Small network fee" | Direct native-coin transfer, or a contract call that sweeps balances | Immediate loss of the fee — or the wallet |
| "Sync / migrate your assets" | Blanket collection approval (all-assets variant) | Entire NFT collections or token classes movable by the attacker |
| "Upgrade to smart account" | Account-delegation signature on chains that support it | Attacker code rides your account's future activity |
Two properties make these requests nastier than ordinary bad transactions. First, several are gasless signatures — nothing leaves your wallet at signing time, so the theft can execute hours later, disconnected from anything you remember doing. Second, an approval is durable: it survives until revoked, so a single careless click can sit dormant in your account like an unlocked door.
Safe handling: what to do with dust
The correct response is deliberately boring. Hide the token using your wallet's spam controls, or simply leave it — it cannot hurt you by existing. Never open the URL in its name or metadata, never Google the token looking for a claim page (search ads are a major drainer distribution channel), and never try to sell or swap the dust: interacting with a scam token's own contract is precisely the engagement its designer wants, and some are built so any interaction reverts, wastes fees, or fires an approval request. Burning is likewise unnecessary — you'd be spending gas to tidy a threat that isn't one. If you did sign something on a claim site, treat it as an active incident: revoke the approval from a trusted revocation tool and move remaining assets to a clean wallet, in that order of urgency.
How real airdrops behave differently
Legitimate distributions have a shape you can recognize. Eligibility is determined by a snapshot of past activity, announced through the project's long-established channels — never by a token materializing in your wallet with instructions. Genuine claim flows are hosted on the project's primary domain, linked consistently from every official surface, and the claim transaction interacts with a published, verifiable distributor contract; many teams simply send tokens directly with no claim step at all. And no honest airdrop, anywhere, asks for your seed phrase, an upfront "release fee," or an approval over unrelated assets. When an airdrop is real, you generally learn about it from the project. When the "airdrop" is how you learned the project exists, you already have your answer.
One more habit closes the loop: treat claim deadlines as a pressure gauge. Fraudulent flows lean hard on urgency — hours-long countdowns, "unclaimed allocations redistributed tonight" — because reflection is fatal to them. Established projects run claim windows measured in weeks or months precisely so nobody has to rush a signature. The more a flow insists you act immediately, the more certain you can be that waiting costs you nothing and protects everything.
Check before you touch anything
A scan of the dropped token's address costs nothing and takes seconds — the opposite of a drained wallet.
Airdrop questions, answered
Can a scam token steal from my wallet just by sitting there?
No. Tokens are passive entries in a ledger; receiving one grants its creator no power over your other assets. Every real-world drain tied to airdrop scams required the victim to act — visit a link, connect, and sign something. The dust is the lure, and a lure in your tackle box catches nothing.
Should I sell or burn unsolicited tokens to get rid of them?
Neither. Selling means interacting with a contract written by a scammer, which can revert, waste gas, or prompt you for approvals; burning spends fees to remove something that poses no threat. Hide the token with your wallet's spam filter and move on.
How do I verify an airdrop announcement is genuine?
Go to the project through a channel you already trusted before the announcement — its long-standing domain, its documented social accounts — and confirm the airdrop is described there with a claim flow on that same domain. Skip search results and ads entirely, and treat any flow demanding fees, seed phrases, or broad approvals as fake regardless of branding.
I signed something on a claim site — what now?
Assume an approval or standing signature now exists against your account. Immediately revoke recent approvals with a reputable revocation tool, then transfer remaining assets to a freshly created wallet, prioritizing whatever the signature touched. Speed matters more than certainty; some drainers cash out in minutes, others wait for a bigger balance.
Why does the spam token show a large dollar value in my wallet?
Because wallet UIs often price tokens from whatever pool exists, and the scammer created a pool that quotes their own token at a fantasy price. The displayed value is self-reported by the attacker and cannot be realized — attempting to is the engagement the whole scheme is built around.