Attacks
A free token you did not ask for, and a claim page built to empty the wallet. Tokens appear in your wallet, or an advert offers a claim for a project you actually use. The claim page asks you to connect and sign. The signature is not a claim, it is an approval that lets a contract move your tokens, or a transaction that transfers them outright.
What it is
Tokens appear in your wallet, or an advert offers a claim for a project you actually use. The claim page asks you to connect and sign. The signature is not a claim, it is an approval that lets a contract move your tokens, or a transaction that transfers them outright.
How it plays out
The bait arrives
An unrequested token, a reply under a real project’s post, or a paid search advert above the real site.
The site looks correct
Cloned front ends are cheap and the URL is one character out.
The signature is the trap
A blind signature, an unlimited approval, or a permit that authorizes a transfer without a further transaction.
It empties in one go
Drainer kits check what is worth taking first and take the most valuable thing in a single transaction.
What gives it away
- Any airdrop you did not sign up for.
- A claim window with a countdown.
- A signature request you cannot read in plain language.
- A search advert for a crypto site. Scroll past the ads, always.
How to not be caught by it
- Claim only from the project’s own domain, typed by you or reached from a bookmark.
- Use a burner wallet for claims, funded with only the gas needed.
- Read what you are signing. A wallet that simulates transactions makes this realistic.
- Never approve an unlimited allowance for a contract you do not know.
- Check approvals periodically and revoke everything you are not actively using.
If it already happened
- Move remaining assets to a fresh wallet immediately. Speed matters more than tidiness.
- Revoke approvals for the compromised wallet afterward, not before moving funds.
- Assume the wallet is permanently untrusted, including for future airdrops.
- Check whether a hardware wallet seed was ever entered anywhere. If so, that seed is burned too.
Common questions
How common is malicious airdrops and claim sites?
Common enough that it has a name and a playbook. The specific numbers move constantly, so rather than quote a figure that will be wrong next quarter: assume you will meet this one, and set your wallet up so meeting it is survivable.
Can the money be recovered?
Once a blockchain transaction confirms, no. What reporting can occasionally do is get funds frozen at the exchange where a thief tries to cash out, which is why reporting quickly is worth doing even when it feels pointless.
Does a hardware wallet stop this?
It stops anything that needs your keys, because the keys never leave the device. It does not stop you approving a malicious transaction on the device itself, so read what the screen says before you press confirm.
Where to go next
Check your setup before you need to
An hour on a screen share, going through your wallets, your approvals, your backups and your recovery plan. You click everything and we never ask for keys.