How to Spot a Fake Airdrop or Wallet-Draining Scam Before Connecting a Wallet
Fake airdrops and wallet drainers are engineered to make you connect your wallet and sign one bad transaction. This defensive guide shows the warning signs, the dangerous approvals to watch for, and a safe routine to follow before you ever click connect.

Table of contents
Wallet drainers are one of the most effective scams in crypto because they turn your own actions against you. You are not hacked in the traditional sense; instead you are tricked into approving a transaction that hands your assets to an attacker. Fake airdrops — free-token offers that feel too good to miss — are the most common bait. The good news is that these scams follow patterns, and a calm checklist before you ever click "connect" will stop the overwhelming majority of them.
How the scam actually works
A drainer scam has a simple goal: get you to sign something with your wallet. It usually plays out in stages.
- The lure. You see an airdrop announcement, a "claim your reward" banner, a token you didn't buy appearing in your wallet, or a message that you've won an allocation.
- The urgency. A countdown, a "limited claim window," or a warning that you'll miss out pushes you to act before you think.
- The connection. You land on a slick site that asks you to connect your wallet — which by itself is usually harmless — and then prompts you to sign a transaction.
- The drain. That signature is not a claim. It is often a token approval or a message that gives the attacker permission to move your assets, sometimes all of them, sometimes repeatedly.
The whole design is psychological. It relies on excitement and time pressure to skip the moment of scrutiny. Our broader overview of crypto scams and how they evolve covers the wider landscape; this piece focuses on the pre-connection decision.
Red flags before you connect
Most scams reveal themselves before you touch your wallet, if you slow down.
- Unsolicited free money. Real, safe airdrops rarely require you to rush to a random site to "unlock" tokens. Surprise tokens that appear in your wallet and beg you to visit a site are a classic drainer setup — do not interact with them.
- Urgency and scarcity. Countdown timers and "claim now or lose it" language exist to stop you thinking. Legitimate projects do not usually threaten you into signing instantly.
- Lookalike domains. Attackers register domains that are one character off, use different extensions, or hide behind link shorteners and ads. Always reach official sites through a source you already trust, not through a DM, ad, or search result you didn't verify.
- Promoted through DMs, comments, and ads. Unsolicited direct messages, reply-guy links under popular posts, and paid ads impersonating known projects are prime delivery channels.
- Requests to "validate," "sync," or "migrate" your wallet. Legitimate apps never need you to re-enter your seed phrase or perform a special "validation." Any site asking for your recovery phrase is a scam, full stop.
The dangerous approvals to recognise
If you do reach a signing prompt, this is the moment that matters most. Learn to read what you are being asked to sign.
- Token approvals with unlimited allowance. Many drains work by getting you to approve a spender contract for a very large or unlimited amount. Once granted, that contract can move those tokens whenever it wants.
setApprovalForAllfor NFTs. This grants a contract permission over your entire collection. Malicious sites use it to sweep NFTs in one signature.- Blind "sign message" requests. Some signatures don't cost gas but still authorise off-chain orders that let an attacker claim your assets. A gas-free signature is not automatically safe.
- Transactions your wallet flags as risky. Modern wallets and browser extensions increasingly warn when a signature looks like a known drainer pattern. Do not click through the warning to "make it work."
If you cannot clearly explain, in one sentence, what a signature does and why this action needs it, do not sign.
A safe routine before you connect
Build a habit you run every single time, no exceptions:
- Pause on any surprise reward. Assume unsolicited airdrops are hostile until proven otherwise.
- Verify the source independently. Navigate to the official project through a bookmark or a channel you already trust, never through the link that reached you.
- Use a separate "hot" wallet for experiments. Keep a small, disposable wallet for claiming and testing, and keep your main holdings elsewhere. A hardware wallet used carefully keeps long-term assets off the machine that browses.
- Read the signing prompt fully. Check the contract, the permission type, and the amount. Prefer wallets that translate signatures into plain language.
- Reject unlimited approvals. Set a specific spending limit where possible, or decline.
- Revoke approvals periodically. Use a reputable approval-revocation tool to remove old permissions you no longer need.
If you think you already signed something bad
Move fast but stay methodical. Transfer remaining assets to a fresh, uncompromised wallet, then revoke the malicious approvals from the affected one. Assume the exposed wallet is no longer private and stop using it for anything valuable. Our step-by-step guide on what to do if your wallet may be compromised walks through the recovery order in detail.
The mindset that keeps you safe
Drainers do not defeat your security; they borrow your consent. The most protective skill is not technical — it is the willingness to be slow, skeptical, and a little rude to "free money." Real opportunities survive a five-minute pause. Scams rarely do.
This article is educational and defensive. It explains how to protect yourself, not how to conduct any scam. Nothing here is financial advice.


