Open app

HostDeFi › Checking an airdrop

How to check if a crypto airdrop is real — the two-minute verification

Every real airdrop announces itself through a channel you already follow; every fake one finds you. That single asymmetry does most of the checking for you — the rest is reading what the claim actually asks your wallet to do.

Practical guide · updated 2026-09-28 · not financial advice

The fake-airdrop channel is the largest consumer-facing drain in crypto — a category sized by the fact that the bait is free to send: a token you never bought appears in your wallet, or a “claim” link arrives in a DM, and the claim site is a drainer wearing a rewards program’s clothes — the whole economy is one mechanism in many costumes. The verification takes two minutes and defeats the entire category.

Every claim below names its source and date.

The source check — where did you hear about it?

Real airdrops are announced from channels you already follow — the project’s official account, its official site, the governance forum you’ve read before. Fake airdrops reach you — a DM, a tagged post, a reply-guy comment, an unsolicited token in your wallet with a “claim” website stamped on it. The channel asymmetry is the first and highest-signal check: if the airdrop found you rather than the reverse, treat it as hostile until proven otherwise.

The verification step that matters: navigate to the project’s known-official presence (the bookmarked site, the long-aged verified account) and look for the airdrop announcement there. If the claim exists only in the DM or the token’s metadata, it doesn’t exist.

The unsolicited-token tell

A token that appeared in your wallet uninvited is the category’s signature move. On Solana and EVM chains, anyone can send anyone tokens — the “airdrop” in your balance is free to the sender and meaningless by itself. The scam is the next step: the token’s name or metadata points to a claim site (“visit claim-rewards.xyz to unlock”), and that site is the drain.

The rule that covers it: an unsolicited token is spam, not a gift. Don’t visit the site its name advertises, don’t interact with the token (on some chains even a transfer attempt routes through a hostile contract), and don’t try to sell it — “selling” an airdropped scam token is the classic way users end up on the drainer page — the “sell” route is a link to the drain.

The claim-transaction read — what the site actually asks

The decisive check is what the claim flow asks your wallet to do. A legitimate claim asks for a connect (read your address) and then a claim transaction — a contract call that transfers tokens to you. A drainer asks for something else: a signature “to verify eligibility”, an approval over your existing tokens, or a seed phrase.

Read the wallet prompt literally — it names the permission in plain text. “Approve spending USDC” on an airdrop claim is a drain (a claim never needs approval over your funds). “Sign this message to prove ownership” is a drain (connecting already proves it). The request that doesn’t match the claim is the whole tell — a real airdrop gives; only a fake one takes a permission.

The eligibility reality check

A real airdrop has a reason you’re eligible — you used the protocol, you held the NFT, you were in the snapshot. The eligibility is verifiable at the official source: the announcement lists the criteria, and the claim page checks your address against them — the eligibility lives in the contract, not the marketing. An airdrop you can’t explain — no prior interaction, no holdings, a generic “you’ve been selected” — is the spray-and-pray version of the scam.

The honest framing: real airdrops are rare, dated, and criteria-bound. If you can’t name the action that earned it, the most likely explanation is that nothing earned it — the “drop” is bait cast at every address the drainer could reach — sprayed wide, waiting for the one claim that signs.

The legitimate-claim environment — when you do claim

When an airdrop passes the checks, claim it in the environment that keeps the win: claim from a hot wallet — a compartmented wallet holding float, not the vault — because even a legitimate claim is a new-site signature, and the separation is cheap insurance against the one-in-a-thousand that isn’t.

And the claim-site navigation rule still applies to the real ones: reach the claim page from the project’s official site or verified announcement (typed/bookmarked), never from the link in the DM or reply. Phishers wrap real airdrops in fake claim pages — the airdrop is real, the link is not. The official-source navigation is the step that separates claiming from donating.

If the check comes back mixed — official announcement exists but you’re unsure of the claim page — the honest move is to skip it. An airdrop is worth what it pays, not what it costs in a drained wallet.

The social-engineering layer — how the fake airdrop finds you

The delivery channels worth recognizing by name: wallet dust (the unsolicited token with a claim-site in its name), reply-guy comments under real project posts (the account is a lookalike; the link is to a claim clone), hijacked threads (a real project’s compromised account posts the “claim now”), and Discord/Telegram pings (the “team member” DM that never is — support does not DM, and neither does the airdrop).

Each channel runs the same mechanism — get you to a claim page that asks for a signature — with the costume changing to fit the channel. The countermeasure is channel-agnostic: verify the announcement at the source you navigate to, not the one that arrived. The airdrop that only exists in the message is the answer to its own legitimacy question — the check finishes before the page loads — the verdict is in the channel — two minutes, four questions, done — cheaper than the alternative every time. The channel is the check. Verify at the source, always.

The two-minute checklist

Channel: did the airdrop come to you, or did you find it at the official source? Token: is it unsolicited spam in your wallet (ignore it)? Claim: does the transaction give you tokens, or take a permission (approval/signature/phrase = drain)? Eligibility: can you name the action that earned it? Four questions, two minutes, and the entire fake-airdrop economy fails against them — four questions is a small price for the whole category.

Frequently asked

How do I know if an airdrop is legit?

Check the channel (official source vs it-found-you), the unsolicited-token tell, what the claim asks for (giving tokens vs taking permissions), and whether you can name the action that made you eligible.

A token appeared in my wallet — is it an airdrop?

It’s spam until proven otherwise. Anyone can send anyone tokens; the scam is the claim site the token’s name advertises. Don’t visit it, don’t interact with the token.

Do real airdrops ask me to sign a message?

No — a real claim is a transaction that gives you tokens. “Sign to verify” or an approval over your funds is the drain pattern.

How do I claim a real airdrop safely?

Navigate to the project’s official site directly (typed URL or bookmark, never the link that reached you), verify the announcement exists there, and use a hot wallet for the claim.

Why did I get an airdrop I never signed up for?

Because it’s not an airdrop — it’s bait. Real eligibility is criteria-bound (protocol use, holdings, a snapshot); unexplained selection is the spray-and-pray scam.

Can interacting with a scam token drain my wallet?

The token itself usually can’t — the drain needs your signature at the claim site. But don’t interact: on some chains even a transfer attempt routes through a hostile contract.

HostDeFi is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a HostDeFi product