HostDeFi › Checking an airdrop
How to check if a crypto airdrop is real — the two-minute verification
Every real airdrop announces itself through a channel you already follow; every fake one finds you. That single asymmetry does most of the checking for you — the rest is reading what the claim actually asks your wallet to do.
The fake-airdrop channel is the largest consumer-facing drain in crypto — a category sized by the fact that the bait is free to send: a token you never bought appears in your wallet, or a “claim” link arrives in a DM, and the claim site is a drainer wearing a rewards program’s clothes — the whole economy is one mechanism in many costumes. The verification takes two minutes and defeats the entire category.
Every claim below names its source and date.
The source check — where did you hear about it?
Real airdrops are announced from channels you already follow — the project’s official account, its official site, the governance forum you’ve read before. Fake airdrops reach you — a DM, a tagged post, a reply-guy comment, an unsolicited token in your wallet with a “claim” website stamped on it. The channel asymmetry is the first and highest-signal check: if the airdrop found you rather than the reverse, treat it as hostile until proven otherwise.
The verification step that matters: navigate to the project’s known-official presence (the bookmarked site, the long-aged verified account) and look for the airdrop announcement there. If the claim exists only in the DM or the token’s metadata, it doesn’t exist.
The unsolicited-token tell
A token that appeared in your wallet uninvited is the category’s signature move. On Solana and EVM chains, anyone can send anyone tokens — the “airdrop” in your balance is free to the sender and meaningless by itself. The scam is the next step: the token’s name or metadata points to a claim site (“visit claim-rewards.xyz to unlock”), and that site is the drain.
The rule that covers it: an unsolicited token is spam, not a gift. Don’t visit the site its name advertises, don’t interact with the token (on some chains even a transfer attempt routes through a hostile contract), and don’t try to sell it — “selling” an airdropped scam token is the classic way users end up on the drainer page — the “sell” route is a link to the drain.
The claim-transaction read — what the site actually asks
The decisive check is what the claim flow asks your wallet to do. A legitimate claim asks for a connect (read your address) and then a claim transaction — a contract call that transfers tokens to you. A drainer asks for something else: a signature “to verify eligibility”, an approval over your existing tokens, or a seed phrase.
Read the wallet prompt literally — it names the permission in plain text. “Approve spending USDC” on an airdrop claim is a drain (a claim never needs approval over your funds). “Sign this message to prove ownership” is a drain (connecting already proves it). The request that doesn’t match the claim is the whole tell — a real airdrop gives; only a fake one takes a permission.
The eligibility reality check
A real airdrop has a reason you’re eligible — you used the protocol, you held the NFT, you were in the snapshot. The eligibility is verifiable at the official source: the announcement lists the criteria, and the claim page checks your address against them — the eligibility lives in the contract, not the marketing. An airdrop you can’t explain — no prior interaction, no holdings, a generic “you’ve been selected” — is the spray-and-pray version of the scam.
The honest framing: real airdrops are rare, dated, and criteria-bound. If you can’t name the action that earned it, the most likely explanation is that nothing earned it — the “drop” is bait cast at every address the drainer could reach — sprayed wide, waiting for the one claim that signs.
The legitimate-claim environment — when you do claim
When an airdrop passes the checks, claim it in the environment that keeps the win: claim from a hot wallet — a compartmented wallet holding float, not the vault — because even a legitimate claim is a new-site signature, and the separation is cheap insurance against the one-in-a-thousand that isn’t.
And the claim-site navigation rule still applies to the real ones: reach the claim page from the project’s official site or verified announcement (typed/bookmarked), never from the link in the DM or reply. Phishers wrap real airdrops in fake claim pages — the airdrop is real, the link is not. The official-source navigation is the step that separates claiming from donating.
If the check comes back mixed — official announcement exists but you’re unsure of the claim page — the honest move is to skip it. An airdrop is worth what it pays, not what it costs in a drained wallet.
The social-engineering layer — how the fake airdrop finds you
The delivery channels worth recognizing by name: wallet dust (the unsolicited token with a claim-site in its name), reply-guy comments under real project posts (the account is a lookalike; the link is to a claim clone), hijacked threads (a real project’s compromised account posts the “claim now”), and Discord/Telegram pings (the “team member” DM that never is — support does not DM, and neither does the airdrop).
Each channel runs the same mechanism — get you to a claim page that asks for a signature — with the costume changing to fit the channel. The countermeasure is channel-agnostic: verify the announcement at the source you navigate to, not the one that arrived. The airdrop that only exists in the message is the answer to its own legitimacy question — the check finishes before the page loads — the verdict is in the channel — two minutes, four questions, done — cheaper than the alternative every time. The channel is the check. Verify at the source, always.
The two-minute checklist
Channel: did the airdrop come to you, or did you find it at the official source? Token: is it unsolicited spam in your wallet (ignore it)? Claim: does the transaction give you tokens, or take a permission (approval/signature/phrase = drain)? Eligibility: can you name the action that earned it? Four questions, two minutes, and the entire fake-airdrop economy fails against them — four questions is a small price for the whole category.
Frequently asked
How do I know if an airdrop is legit?
Check the channel (official source vs it-found-you), the unsolicited-token tell, what the claim asks for (giving tokens vs taking permissions), and whether you can name the action that made you eligible.
A token appeared in my wallet — is it an airdrop?
It’s spam until proven otherwise. Anyone can send anyone tokens; the scam is the claim site the token’s name advertises. Don’t visit it, don’t interact with the token.
Do real airdrops ask me to sign a message?
No — a real claim is a transaction that gives you tokens. “Sign to verify” or an approval over your funds is the drain pattern.
How do I claim a real airdrop safely?
Navigate to the project’s official site directly (typed URL or bookmark, never the link that reached you), verify the announcement exists there, and use a hot wallet for the claim.
Why did I get an airdrop I never signed up for?
Because it’s not an airdrop — it’s bait. Real eligibility is criteria-bound (protocol use, holdings, a snapshot); unexplained selection is the spray-and-pray scam.
Can interacting with a scam token drain my wallet?
The token itself usually can’t — the drain needs your signature at the claim site. But don’t interact: on some chains even a transfer attempt routes through a hostile contract.