DEV Community

Verixia
Verixia

Posted on Originally published at trustdex.app

Airdrop Scams, Decoded — Dusting, Drainer Links and Fake Claims

TrustDex TrustDex › Guides › Airdrop scams

Tokens you never asked for showing up in your wallet is not luck — it's a fishing lure cast at scale. The dust itself is harmless. What it invites you to do next is the attack.

Educational guide · reviewed August 2026 · not financial advice

Open almost any active wallet and you'll find them: tokens you never bought, NFTs you never minted, names like "5000USDT-voucher" or a famous project's ticker with a website baked into it. Sending them costs the scammer almost nothing, because on most chains a single transaction can spray a worthless token to thousands of addresses at once. The economics only work because a tiny fraction of recipients does the one thing the token exists to provoke — and that action, not the airdrop, is what empties wallets.

This guide separates the three layers of the scheme — the dust, the destination, and the signature — so the next unexpected "reward" in your wallet reads as what it is: unsolicited advertising for a trap.

Found a mystery token in your wallet?

Paste its mint address before touching it — mass-dusted scam tokens tend to light up a scan immediately.

Why anyone would send you free tokens

Legitimate projects airdrop for a reason you can articulate: rewarding past users, decentralizing governance, bootstrapping a network. Scammers airdrop for a different reason — an unsolicited token is the cheapest way to place a clickable message inside your wallet UI, past every spam filter that guards your inbox. The token's name is the ad ("Claim at ..."), its metadata carries the link, and your own curiosity does the delivery. Some campaigns add a pricing trick: the scam token trades against itself on a pool the scammer controls, so your wallet may display the dust as "worth" hundreds of dollars. That number exists to make ignoring it feel expensive.

The dust layer: tokens, NFTs, and memo spam

The bait takes a few forms depending on the chain. Fungible dust — a few thousand units of a token named after a real protocol or a fake voucher. NFT spam — an image whose entire artwork is a URL and an instruction. Memo or metadata spam — transfer notes attached to tiny native-coin deposits, common on chains with cheap memo fields. All three share one property that matters more than anything else in this guide: receiving them changes nothing about your security. Tokens cannot execute code on arrival. No balance sitting in your wallet can move your other assets. The dust is inert until you interact with it or with the address it advertises.

The trap is participation, not possession. Every airdrop drain in the wild requires a step you take: visiting the printed URL, connecting a wallet, and approving something. Refuse that step and the entire kill chain dies in your token list, worth exactly nothing and threatening exactly nothing.

The destination: anatomy of a fake claim site

Follow the printed link (don't) and you land on a site built to feel official — cloned branding from a real project, a countdown, an eligibility checker that congratulates every address it's shown. The eligibility theater matters: being told your specific wallet "qualifies for 2,400 tokens" converts a stranger's website into your pending payout, and people protect payouts. The connect-wallet button works normally, because connecting is harmless and builds trust. The harm is queued behind the button labeled Claim, which does not claim anything — it asks your wallet for a signature or transaction whose true effect is written in the fine print your excitement is designed to skip.

What the "claim" actually asks you to sign

Drainer kits are modular, and the request they serve depends on what your wallet holds. The table below is the field guide — the left column is what the site says, the middle is what the wallet prompt really does.

Two properties make these requests nastier than ordinary bad transactions. First, several are gasless signatures — nothing leaves your wallet at signing time, so the theft can execute hours later, disconnected from anything you remember doing. Second, an approval is durable: it survives until revoked, so a single careless click can sit dormant in your account like an unlocked door.

Safe handling: what to do with dust

The correct response is deliberately boring. Hide the token using your wallet's spam controls, or simply leave it — it cannot hurt you by existing. Never open the URL in its name or metadata, never Google the token looking for a claim page (search ads are a major drainer distribution channel), and never try to sell or swap the dust: interacting with a scam token's own contract is precisely the engagement its designer wants, and some are built so any interaction reverts, wastes fees, or fires an approval request. Burning is likewise unnecessary — you'd be spending gas to tidy a threat that isn't one. If you did sign something on a claim site, treat it as an active incident: revoke the approval from a trusted revocation tool and move remaining assets to a clean wallet, in that order of urgency.

How real airdrops behave differently

Legitimate distributions have a shape you can recognize. Eligibility is determined by a snapshot of past activity, announced through the project's long-established channels — never by a token materializing in your wallet with instructions. Genuine claim flows are hosted on the project's primary domain, linked consistently from every official surface, and the claim transaction interacts with a published, verifiable distributor contract; many teams simply send tokens directly with no claim step at all. And no honest airdrop, anywhere, asks for your seed phrase, an upfront "release fee," or an approval over unrelated assets. When an airdrop is real, you generally learn about it from the project. When the "airdrop" is how you learned the project exists, you already have your answer.

One more habit closes the loop: treat claim deadlines as a pressure gauge. Fraudulent flows lean hard on urgency — hours-long countdowns, "unclaimed allocations redistributed tonight" — because reflection is fatal to them. Established projects run claim windows measured in weeks or months precisely so nobody has to rush a signature. The more a flow insists you act immediately, the more certain you can be that waiting costs you nothing and protects everything.

Check before you touch anything

A scan of the dropped token's address costs nothing and takes seconds — the opposite of a drained wallet.

No. Tokens are passive entries in a ledger; receiving one grants its creator no power over your other assets. Every real-world drain tied to airdrop scams required the victim to act — visit a link, connect, and sign something. The dust is the lure, and a lure in your tackle box catches nothing.

Neither. Selling means interacting with a contract written by a scammer, which can revert, waste gas, or prompt you for approvals; burning spends fees to remove something that poses no threat. Hide the token with your wallet's spam filter and move on.

Go to the project through a channel you already trusted before the announcement — its long-standing domain, its documented social accounts — and confirm the airdrop is described there with a claim flow on that same domain. Skip search results and ads entirely, and treat any flow demanding fees, seed phrases, or broad approvals as fake regardless of branding.

Assume an approval or standing signature now exists against your account. Immediately revoke recent approvals with a reputable revocation tool, then transfer remaining assets to a freshly created wallet, prioritizing whatever the signature touched. Speed matters more than certainty; some drainers cash out in minutes, others wait for a bigger balance.

Because wallet UIs often price tokens from whatever pool exists, and the scammer created a pool that quotes their own token at a fantasy price. The displayed value is self-reported by the attacker and cannot be realized — attempting to is the engagement the whole scheme is built around.

TrustDex is an educational risk tool, not financial advice. On-chain data can be incomplete or manipulated; a clean check is a dated snapshot, not a guarantee. Always do your own research. Free · no signup · a TrustDex product


Originally published at trustdex.app/guides/airdrop-scam-mechanics/. Check any Solana or EVM token free with the TrustDex scanner.

Top comments (0)