Learn

Fake airdrops and spam NFTs: how to spot them and what to do

You open your wallet and find a token or NFT you never asked for, often with a name that promises money. This is one of the most common scam patterns on EVM chains. This page explains how it works, what is and is not dangerous, and how to read such entries when you look at a wallet's history.

How a fake airdrop works

Anyone can send tokens or NFTs to any address without its owner's consent. Scammers use this to mass-send worthless tokens to thousands of wallets. The token or collection is given an attractive name, often a fake amount, a claim such as "reward", or a website address. The goal is not the token itself but to make you go somewhere and sign something: visit the site, connect your wallet and approve a transaction that gives the scammer access to your real tokens.

What we see in real wallet histories

While testing Hopchain on real, public wallets we came across entries like these, all received without being requested:

  • an NFT collection named usdgift.org
  • one named Access USDchest.com to claim rewards
  • one named usdcoin.events
  • a token named 1.000.000 $PENDLE, a fake amount and ticker in the name

We are not linking these and you should not visit them. They are shown here because they illustrate the pattern: a website address or a big number sitting in a place where a legitimate name would normally be.

Receiving is not the danger, interacting is

Simply having an unsolicited token in your wallet does not by itself take anything from you. The risk starts when you act on it:

  • Visiting the website in the name and connecting your wallet.
  • Signing a request to "claim", "verify" or "unlock" something, especially one that asks for a token approval.
  • Trying to sell or swap the token through a site you found via the token itself.

A caveat when reading wallet histories, including on Hopchain

A token or NFT contract decides for itself what it reports. That includes the collection name and, in the transfer record, who the tokens appear to come from. A malicious contract can make a transfer look as if it came from a well-known address. So if a familiar name shows up as a connection of a wallet, especially with strange tokens attached, that does not prove the familiar party did anything. Expand the connection and look at what was actually transferred.

What to do

  1. Do not open links, do not connect your wallet and do not sign anything to "claim" it.
  2. Ignore it or use your wallet's option to hide the token. You cannot force-delete it, but hidden tokens are harmless.
  3. Never share your seed phrase or private key. No legitimate airdrop asks for it.
  4. If you already signed an approval, check and revoke it.
  5. If you suspect your wallet is compromised, move what you can to a new wallet created on a clean device.

Related: address poisoning

A neighbouring trick sends a tiny or zero-value transfer from an address that starts and ends with the same characters as one you use, hoping you later copy it from your history by mistake. Always compare the full address, not just the first and last few characters, before sending.

This is general information, not financial or security advice.

Want to see what a wallet has actually received and done? Check any address on Hopchain. It's free and needs no signup.