In the world of crypto assets (also known as virtual currencies), new projects often distribute tokens for free as a marketing tool to promote themselves and expand their user base — a practice known as an “airdrop.” While this is a legitimate marketing method in itself, scams that exploit the appeal of “getting something for free” to target users’ assets are on the rise.

This article focuses specifically on scams that pose as crypto airdrops, explaining how they work at a technical level, how to spot them, and what to do if you become a victim. Note that this is a separate topic from “AirDrop,” the file-sharing feature built into iPhone and Android devices. For the basic mechanics and real-world examples of legitimate airdrops themselves, see “What Is a Crypto Airdrop? A Beginner’s Guide to How It Works, Examples, and Risks.”

What this article covers

  • The seven most common types of airdrop scams and the technical mechanisms behind them.
  • What to check before signing or approving anything, so you can spot a scam early.
  • What to do if you’ve been victimized, including how to revoke approvals and where to seek help.

What Is an Airdrop Scam? An Overview of Crypto Scams Disguised as Free Token Giveaways

An airdrop scam is a general term for scams that pose as legitimate token distributions by real projects, tricking users into connecting their wallets or signing transactions in order to steal their assets. In recent years, as DeFi (decentralized finance), NFTs, and newer chains known as “layer 2” networks have grown more widespread, scammers have increasingly attached plausible-sounding justifications to their schemes — such as “eligible because you traded in the past” or “limited to early users only.”

Several psychological factors are said to make these scams effective. One is that the phrase “getting something for free” tends to lower a person’s guard. Another is language that emphasizes urgency — such as “claim now or it expires” — which pressures users into acting before they’ve fully reviewed what they’re doing. A defining feature of this scam type is that it doesn’t extract money directly; instead, it gets the user to perform the “claim” action themselves, which is what actually causes the loss.

The actual tactics used are not uniform — they range from schemes that redirect users to fake websites, to ones that abuse wallet functionality itself, to ones that “poison” transaction history to trigger misdirected transfers.

Common Airdrop Scam Tactics: 7 Types and How They Work

Even though airdrop scams all present themselves under the same banner of a “free distribution,” the underlying technical mechanisms differ from one tactic to the next. Understanding these mechanisms makes it easier to see through a scam even when the surface-level wording changes.

This section covers seven representative types. For each one, we’ll walk through exactly how assets get stolen and which action serves as the trigger.

1. Signature Phishing via Fake Airdrop Websites

One of the oldest tactics is directing users to a fake website that closely mimics a legitimate project. Search ads, social media posts, and direct messages are commonly used as entry points, leading victims to a claim page on a domain that is difficult to distinguish from the real one.

When a user connects their wallet on that page and is prompted to sign after clicking a “Claim Tokens” button, the signature they are actually giving may not be for receiving a distribution at all — it may instead authorize sending assets or granting the kind of approval described below.

Signature prompts are supposed to display exactly what they authorize, but a defining feature of these scams is that they exploit how hard that content is to parse, pushing users to approve without actually checking it.

2. Wallet Drainers That Abuse Wallet Approval Functions

Crypto wallets have an “approve” function that lets a user pre-authorize an app or service to handle their tokens. This mechanism is essential for using DeFi and similar services, but a tactic known as a “wallet drainer” abuses this approval function.

The signature requested on a fake claim page may in fact grant unlimited withdrawal rights over a specific token, or transfer rights over every NFT a user holds. Once that approval is granted, the attacker can move assets out of the wallet at any time of their choosing thereafter.

Because assets are not necessarily drained immediately after the claim action but sometimes after a delay, victims can find it difficult to notice they have been targeted.

3. Suspicious Tokens or NFTs Sent to Your Wallet, and Redirection to Token-Swap Sites

Tokens or NFTs a user never requested can suddenly show up in their wallet. This is generally reported to be less about targeting a specific individual and more about mass-sending to a large number of addresses at once.

These unsolicited tokens are sometimes given names designed to look valuable, or embedded with a URL for a site that encourages the user to cash them out. If a user follows those instructions, connects their wallet to that token-swap site, and signs, they risk losing assets through the same wallet-drainer flow described above.

The generally recommended approach for tokens of unknown origin is to leave them untouched and not attempt to cash them out.

4. Address Poisoning to Induce Misdirected Transfers

Address poisoning is a relatively new tactic that “poisons” a user’s transfer history to induce a misdirected payment. Crypto addresses are long strings of characters, and many people tend to check only the first and last few characters — a habit this tactic exploits.

An attacker prepares a fake address whose first and last characters closely resemble the address of someone the user regularly sends funds to, then slips it into the user’s transaction history — for example, via a tiny transfer. The next time the user sends funds and copies an address from their history, they may mistakenly select the fake, look-alike address instead of the real one, sending their funds to the attacker.

According to a report from a blockchain analytics firm, approximately 270 million such attacks were observed on Ethereum and BSC (BNB Smart Chain) between July 2022 and June 2024, with 6,633 successful attacks resulting in confirmed losses of roughly $83.8 million (source: Innovatopia, Japanese-language source).

5. Impersonation Solicitations on Social Media and Chat Apps

On platforms such as X (formerly Twitter), Discord, and Telegram, solicitations impersonating a legitimate project’s official account or team members are common. Typical forms include slipping a fake claim link into the replies under an official post, or sending direct messages announcing that the user has “won” a prize (source: National Police Agency special fraud countermeasures page, Japanese-language government resource).

Most of these ultimately function as an entry point steering users toward signing or connecting their wallet on a fake site. Even when an account claims to be official, it is important to check for anything unnatural about the account name, registration date, or follower composition, and to confirm that any linked destination matches the project’s actual official domain.

6. Demands for Upfront Payment of “Taxes” or “Gas Fees”

Some tactics involve claims such as “you must pay a fee, gas cost, or tax before you can claim your distributed tokens,” demanding a transfer or small payment. In reality, whatever amount is paid is simply stolen outright, and in some cases the payment process itself is also used to try to steal the victim’s wallet information.

Even legitimate airdrops can require a network fee (gas fee) at the time of claiming, but that fee is paid to the blockchain network itself — it is not the kind of upfront payment made to an individual operator or a specific account. If a claim requires sending funds to a third party as a condition, that should be treated with caution.

7. Requests to Enter Your Seed Phrase or Private Key

A wallet’s recovery phrase (seed phrase) or private key (signature key) is, in itself, the authority to control its assets. Sharing either of these with a third party is functionally equivalent to handing over full control of all of one’s assets.

Any page or message that asks a user to enter their recovery phrase or private key under the guise of claiming an airdrop or “verifying” a wallet can generally be regarded as a scam. Legitimate wallets and services never ask users to enter and submit this information. Regardless of the reason given, the rule is: never enter or send this information.

Airdrop Scam Warning-Sign Checklist

Looking across the mechanics of each tactic reveals a set of common points worth checking. Pausing before you act and reviewing the following checklist can help prevent you from becoming a victim.

What to check

Warning signs

The claim page’s domain

Does it exactly match the domain officially announced by the project? Is it a different, merely similar-looking domain?

The wording displayed

Does it use urgency-driven phrases like “claim now” or “expires soon” to rush you past a careful review?

What the signature actually says

Does it say “send” or “approve” rather than “claim” or “receive”?

The scope of the approval being granted

Is it broader than necessary — such as unlimited withdrawal rights or transfer rights over all your NFTs?

URLs attached to unfamiliar tokens

Are you about to access a link embedded in a token or NFT you do not recognize?

Conditions attached to the claim

Are you being asked to make an upfront payment to a third party, or to enter your seed phrase?

If even one of these applies, it is recommended that you stop and verify the facts through an official source. When you are unsure, choosing not to claim is often the choice that ends up protecting your assets.

What to Do After Falling Victim to an Airdrop Scam

Even with careful attention, a sufficiently sophisticated scam can still trick a user into signing or connecting their wallet. If you notice you have been victimized, or suspect you may have performed a risky action, taking steps to limit further damage becomes important.

Taking hasty additional actions can sometimes make the damage worse. Let’s calmly work through what to do, one step at a time.

First, Revoke Approvals and Move Remaining Assets to Safety

In wallet-drainer cases, as long as a dangerous approval remains active, there is a risk that additional assets will continue to be drained. For that reason, an action known as “revoke” — canceling an approval you have already granted — can be an effective countermeasure. Dedicated tools exist for checking and revoking approvals; for specific steps, see “How to Revoke a Crypto Approval,” and check whether any suspicious approvals remain active on your wallet.

Additionally, if any assets remain intact, moving them to a newly created, separate wallet — distinct from the compromised one — is also worth considering. However, transfers require a gas fee, and if a dangerous approval is still active, there is a risk assets could be drained before the transfer completes — so the order of operations matters.

When the situation is hard to assess, it is important not to force a decision on your own, but to proceed while consulting reliable sources of information.

Contacting Official Consultation Channels

If you have been victimized by an airdrop scam, or suspect one, you can consult official channels. The following are Japan-based resources: for financial losses, the police consultation hotline (#9110) or your nearest police station can help; for general consumer-related concerns, the Consumer Hotline (188) is the point of contact. The Financial Services Agency (FSA), Japan’s financial regulator, also accepts inquiries related to financial services through its Counseling Office for Financial Services Users. Readers outside Japan should check the equivalent fraud-reporting or consumer-protection body in their own country or region, as these specific hotlines are only accessible from within Japan.

Contact point

Contact details

Main role

Police consultation hotline

#9110

General consultation window for crime and victimization. Call 110 for emergencies.

Prefectural police cybercrime consultation desks

See each prefectural police website

Consultation on unauthorized access and online scam damage.

Consumer Hotline

188

Connects to a local Consumer Affairs Center for consultation on contracts and general damages.

FSA Counseling Office for Financial Services Users

0570-016811

Consultation on financial services, including crypto asset exchange businesses.

National Consumer Affairs Center of Japan

Directs you to the appropriate consultation desk

Core body for consumer affairs consultation; also issues warnings about scam tactics.

When consulting these channels, keeping records of your communications, the address you sent funds to, and your transaction history (transaction IDs) will make it easier to explain the situation.

Note that crypto assets move easily across borders, and once assets have been sent, recovering them is said to be difficult. Because of this, any operator claiming they can “guarantee a refund” should be treated with caution, as this carries a risk of secondary victimization. For specific procedures related to refunds or recovering losses, consulting a qualified professional such as an attorney is the most reliable path forward.

Security Habits That Help Prevent Airdrop Scams

Beyond addressing each individual tactic, everyday habits can lower your overall probability of falling victim to an airdrop scam. Below are basic measures that do not require any specialized knowledge.

Measure

Details

Separate wallets by purpose

Use a dedicated wallet holding only a small amount for claiming new airdrops or using unfamiliar services, keeping it separate from the wallet where you store your main assets.

Use a hardware wallet alongside your others

Managing long-term holdings in a hardware wallet, which keeps the private key (signature key) offline, makes them less vulnerable to signature phishing.

Periodically review your active approvals

Revoking any past approvals you no longer need reduces the risk of them being abused.

Always check what you are signing

Reviewing exactly what a signature authorizes every time, and refusing to sign anything you do not understand, is an effective habit.

Verify official information at the primary source

For airdrop announcements, do not click links from social media directly — instead, verify authenticity by navigating to the official site or a bookmark you have saved yourself.

These habits are useful for crypto asset security in general, not just for preventing airdrop scams.

Frequently Asked Questions (FAQ)

Below are answers to points people commonly find themselves unsure about, both before and after taking action related to an airdrop, as well as questions that tend to arise after realizing they have been victimized. The best response varies by individual situation, but use these as a starting point for the basic thinking involved.

What is the most common airdrop scam tactic?

The most representative type is reported to be one that gets a user to sign on a fake claim site and then abuses that wallet approval to drain assets. Because wallet connection and signing serve as the common entry point across tactics, checking exactly what you are signing is the basic foundation of prevention.

Is it safe to receive a token I never requested?

Simply having it appear in your wallet does not by itself cause any loss. However, accessing a site associated with that token, or signing in an attempt to cash it out, can lead to victimization. The safest approach for tokens of unknown origin is to leave them alone and not interact with them.

Can crypto assets sent to a scammer be refunded?

Crypto transactions are difficult to reverse, and recovering assets once they have been sent is said to be difficult. There are also reports of secondary victimization by operators claiming they can “guarantee recovery,” so it is recommended to consult professionals such as the police or an attorney regarding any refund process.

How can I tell a legitimate airdrop apart from a scam?

Whether the domain matches the official one, whether the wording tries to rush you, and whether the signature actually says “send” or “approve” rather than “claim” are all useful signals. For more detail, see the warning-sign checklist earlier in this article.

Summary

Airdrop scams share a common feature: they exploit the expectation of “getting something for free” to get users to sign or approve transactions themselves, which is what actually causes the loss. Tactics range widely, from fake-site phishing to wallet drainers to address poisoning, but in every case, connecting a wallet and signing is the trigger.

Pausing to check what you are signing before you sign it, separating your wallets by purpose, and leaving tokens of unknown origin untouched form the foundation of preventing this kind of loss. If the worst happens, consider revoking approvals and reaching out to an official consultation channel as early as possible.

Crypto scams take several other forms beyond airdrop scams. For more on how legitimate airdrops themselves work, see the basic explainer article; for other scam types, see our related articles as well.

This article is for informational purposes only and does not constitute financial or investment advice. Please consult a qualified professional before making investment decisions.