HostDeFi › Guides › Romance & token-gifting scams
Romance & token-gifting scams
Someone you like sends you a token 'worth thousands.' It's not a gift — it's a hook with a handle, and the moment you try to sell it you've swum to exactly where the fisher wanted you.
The setup needs two props: a token that looks valuable, and a reason you'd try to sell it. The scammer supplies both. You wake to find an unknown token in your wallet worth — according to the explorer — a surprising amount, or someone you've grown to trust (a match, a "mentor," a new friend in a trading group) sends it to you as a generous gesture. Either way, the gift only pays out if you do one thing: try to sell it. And that's the whole design — the gift is bait, and the sale is the trap.
The three gift traps
"Sell it on our swap site"
The gifted token isn't listed anywhere normal — the gifter (or the token's own materials) points you to a bespoke swap site, "the only place it trades." Connecting there and signing the sell is the payload: the site's approval request is a drainer that takes your real assets, not their fake gift. The token was never sellable — the site was always the product. The claim-site anatomy this borrows →
Valuable on paper, unsellable in fact
The token is real and shows a real explorer value — but it's a honeypot: the contract lets you buy or receive and refuses to sell. Your "gift" is theater, and the attempt to dump it teaches the operator your wallet is active and worth follow-up attention — plus you just spent gas discovering it. How the sell-block works →
Dust as a probe
Sometimes the gift is just dust — a near-worthless spray across thousands of addresses. Interacting with it (trying to sell, swap, or even transfer) marks your wallet as active and attended: you've just told the operator "this address has a live human who touches unknown tokens" — the targeting signal for the real pitch that follows.
The romance angle — trust as the delivery mechanism
The token-gift variant that costs people most rides the pig-butchering playbook's lighter version: a weeks-long relationship — dating app, trading Discord, language exchange — where the "gift" arrives as affection or mentorship. "I made good money on this, sending you some." Now the token carries emotional weight: selling it feels rude, questioning it feels paranoid, and the gifter is right there to "help" when the sale needs a special site. The manipulation is the relationship itself — the scammer spent weeks buying the credibility that makes you click the link.
The tell that ends it: a gift you can only sell through one specific website is not a gift — it's a toll booth. Real tokens trade on real DEXes, discoverable on real aggregators. When the gifter is also the only liquidity source and the only off-ramp, you're not holding an asset; you're holding a lure.
The protocol for unsolicited tokens
Touch nothing. The single correct move for an unsolicited token is non-interaction: don't sell it, don't transfer it, don't "test" it, don't connect to the site someone helpfully provides. Wallets and explorers let you hide or flag it — do that and move on. It cannot hurt you sitting ignored.
Evaluate the relationship, not the gift. When the sender is a person — the romance case — the gift is a test of their character, not the token's. A real friend gives something you can verify and sell anywhere; a lure comes with instructions and a special site. How they respond to "I'll just sell it on a normal DEX" tells you everything.
Never let gratitude override verification. The token scans like any other: contract, authorities, liquidity, sell-side posture. If the "gift" is real it survives the check; if it's bait, the check is how you find out before the signature. Reading the scan's verdict →
Gift or lure — the contract knows
Paste the token someone sent you: does it trade on real venues, or does its whole world route through one site? The scan reads it in seconds.
Frequently asked
Why did a stranger send me a valuable token?
The gift is bait — honeypot, a route to a drainer site, or dust probing whether your wallet is active. The interaction, not the token, is the payload.
Can an unsolicited token drain me by itself?
No — it can't take anything sitting ignored. Danger lives entirely in interacting: connecting, signing approvals, or paying gas to learn it's unsellable.
What is a dust attack?
Near-worthless spray to thousands of addresses — touching it marks your wallet as active, a targeting signal for the real pitch that follows.
Someone I trust sent it — different?
Ask how the trust was built. Weeks of dating-app rapport plus a 'special site' to sell it is the romance-scam delivery mechanism — real gifts sell on normal venues.
What to do with a suspicious token?
Nothing — hide or flag it and move on. Never sell, transfer, or use a site the sender recommends.