HostDeFi › Guides › Fake airdrop sites
Fake airdrop claim sites: anatomy of the trap
Airdrops trained a whole market to expect free money for connecting a wallet. Scammers industrialized that reflex. Here's the trap stage by stage — and the tells that separate real claims from bait.
Genuine airdrops are real — major protocols have distributed enormous value to early users, and chasing them is a legitimate pastime. That legitimacy is the scam's raw material: because free-money-for-connecting is a thing that actually happens, a fake claim page doesn't have to overcome your skepticism, only borrow a real pattern. The result is the most industrialized fraud flow in crypto, run from kits, at scale, against everyone at once.
Stage one: the bait finds you
Seeded tokens. Unexplained tokens appear in your wallet — often named as instructions (“claim at …site”), sometimes carrying an eye-watering paper value. Sending tokens to any address costs a scammer almost nothing; wallet UIs display them like property you own. The token is an advertisement, and interacting with the site it names is the payload.
Impersonated announcements. Hacked or lookalike project accounts announce a surprise drop with a claim link. The countdown ("claim closes in 24 hours") is load-bearing — urgency suppresses verification.
Anticipated-airdrop parasitism. When a real project is rumored to drop, fake "checker" and "pre-claim" sites bloom ahead of the announcement, harvesting the crowd that's actively searching. The scam arrives before the real thing, wearing its name.
Stage two: the page
The claim site clones the project's design, shows your "allocation" (a random large number — the kit invents it), and asks you to connect and claim. Everything visible is set dressing for one moment: the signature request. Per the drainer playbook, that request is a transfer, an approval, or a permit — whatever the kit judges will extract the most from what your wallet holds. There is no allocation. There never was a check. The site's entire function was to route you to that prompt with your guard down.
Got a mystery token? Read it, don't visit it
Paste the mint of anything that appeared uninvited — the scan reads what it is without touching its website.
What real airdrops look like, by contrast
Real distributions announce through the project's long-established channels, and the claim lives on the project's own domain — the one that existed before the airdrop. Eligibility comes from your past on-chain activity, not from a page that "checks" after you connect. A legitimate claim transaction gives you tokens and asks for nothing standing in return — no token approvals, no spending permissions, no “verification” signatures. And real projects don't require urgency: claims stay open for weeks or months. Every one of these properties inverts in the fake flow, which makes the comparison itself the checklist.
The seeded-token rule: tokens that arrive uninvited are handled like unsolicited email attachments. Don't visit the site in the name, don't try to sell them (interaction is sometimes the trap — and “selling” one can route through the scam's own contract), don't sweep them to another wallet. Hide them in your wallet UI and move on. They cannot hurt you by existing; only your signatures can.
The habits that make the whole class miss
Verify announcements on a second surface — a drop announced only in one place isn't announced. Reach claim pages by navigation you initiate, never links that found you. Use a dedicated low-value wallet for any claiming at all, so even a mistake is scoped. And read the signature request as the final arbiter: a "claim" that wants an approval or asks you to authorize token spending is a drain wearing a gift bow. Ten seconds at the prompt beats every pixel of the page above it.
Check any claim token before you believe its number
The paper value in your wallet is the lure — a scan shows whether anything real stands behind it.
Frequently asked
Why did unknown tokens appear in my wallet?
Anyone can send tokens to any address for near-zero cost. Uninvited tokens are advertisements — usually naming a “claim” site that leads to a drainer. They can't hurt you by sitting there; interacting with them or their site is the trap.
How do I check if an airdrop is real?
Real drops announce on the project's long-standing channels, claim on the project's own pre-existing domain, base eligibility on your past activity, and stay open for weeks. A surprise drop with a countdown, announced by link, is the fake profile.
Can claiming a fake airdrop drain my wallet?
Yes — the “claim” signature is the payload: a transfer, approval or permit that hands the operator your real assets. The displayed allocation exists only to get you to that prompt.
Should I sell or transfer scam tokens out of my wallet?
No. Attempting to sell can route through the scammer's own contract, and transfers just spread the bait. Hide them in your wallet interface and ignore them.