Crypto holders are increasingly exposed to airdrop scams because of the use of phishing attacks and malicious wallet approval. In a phishing attack carried out by criminals on June 3, 2025, according to FBI warnings, the criminals used unsolicited NFT airdrops on Hedera, which forced users to visit phishing websites. At least $14 billion in crypto was sent to scam addresses in 2026, as reported by the Chainalysis report.
Airdrops refer to a way through which a token is distributed among the early users or community members. The same method, however, has been used for phishing. There is a risk for users when they click the claim link, connect the wallet, or sign the transaction without verifying the airdrop campaign.
Development of airdrop scam techniques
Scam dangers related to airdrop scams evolved along with the expansion of DeFi, NFT, and Web3 ecosystems. One of the most significant token distributions is the one of Uniswap’s UNI that took place on September 1, 2020.
With the development of new communities associated with NFT and Web3, there emerged more chances for scamming by impersonating different projects, community members, and project moderators. Malwarebytes noted fake airdrop websites in May 2022.
In December 2023, Check Point Research discovered the crypto-drainer campaigns that attacked several networks, such as Ethereum, BNB Chain, Polygon, and Avalanche. Such attacks involved phishing web sites and malicious activities within the wallets of the victims.
In 2024, however, the scale of such attacks was bigger. According to the data from Scam Sniffer provided by BleepingComputer, wallet drainers managed to steal $494 million worth of cryptocurrency from more than 300,000 wallet addresses. About 56.7% of reported thefts involved permit signatures.
| Year | Reported development |
| 2020 | Uniswap distributed UNI to historical users. |
| 2022 | Malwarebytes documented fake airdrop websites |
| 2023 | Drainer campaigns targeted multiple blockchains. |
| 2024 | Drainers reportedly stole about $494 million. |
| 2025 | The FBI warned about malicious Hedera NFT airdrops. |
| 2026 | Research identified transaction-simulation phishing. |
The FBI’s 2025 warning showed how unsolicited NFTs could become part of an attack. Criminals could place phishing URLs in transaction memos or distribute them through social media, third-party websites, and phishing emails.
How users can avoid airdrop scams
An unexpected token or NFT does not necessarily mean that a wallet has already been compromised. The risk can emerge when users interact with the asset or follow an embedded link.
The safest approach to avoid airdrop scams is to verify the campaign through independently located sources before taking any wallet action. Users are supposed to identify the domain of a project themselves as opposed to depending on links provided within an unusual email or wallet notification.
Domain names need to be keenly looked into for any spelling mistakes, additional words, and strange extensions. Token contract addresses should be compared with independently confirmed official information before users interact with them.
Wallet prompts require equal attention. A claim transaction that requests an unexplained approval, permit signature, or transfer should be rejected. Users should read the action displayed by their wallet rather than relying on the stated purpose of the website.
Key safety measures include:
- Never provide a seed phrase, private key, password, or one-time authentication code.
- Do not send cryptocurrency first to receive supposedly free tokens.
- Do not click unsolicited claim links, and do not interact with unverified dust tokens.
- Review approvals and transactions before signing.
- Consider using a separate wallet for experimenting with applications.
Approvals from the wallet might lead to the greatest danger.
Attackers might lure users into approving spending of some free token while seeking an approval to spend assets that have value. Approval phishing was explained by Chainalysis back in June 2026 as a technique where social engineering lures victims onto on-chain infrastructure that drains their wallets eventually.
Permit signatures might be especially important since they allow spending tokens in a way other than traditional transaction execution. Sniffer data reported by BleepingComputer showed that permit signatures accounted for 56.7% of reported drainer thefts in 2024.
Transaction simulation also cannot be treated as an absolute guarantee. Research published July 30, 2026, identified transaction-simulation phishing, in which specially designed contracts could produce apparently benign or profitable simulation results while the executed transaction produced a harmful outcome.
Researchers identified more than 4,000 phishing contracts deployed between August 2024 and June 2025. Chainalysis also reported that AI-enabled scams were 4.5 times more profitable than traditional scams.

Source: Chainalysis
According to its 2026 report, impersonation scams have increased by 1,400% annually, thus posing another problem in terms of authenticating online promotions.
What victims should do after a suspicious interaction
Users who entered a recovery phrase into a suspicious website should treat that phrase as compromised. Assets associated with the wallet should be moved to a new secure wallet as soon as practical.
Anyone who signed a suspicious transaction or approval should review wallet permissions and revoke malicious approvals where the relevant blockchain tools support it. The affected wallet should also be monitored for additional unauthorized activity.
Victims should preserve transaction hashes, wallet addresses, dates, times, amounts, screenshots, and suspicious URLs if funds were stolen. The FBI recommends providing cryptocurrency addresses, transaction hashes, amounts, and transaction dates and times when reporting cryptocurrency crimes.
The FBI also warns that cryptocurrency recovery offers can become another scam, particularly when someone demands an upfront payment to recover stolen assets.
Conclusion
Airdrop scams have progressed from fake giveaway pages to coordinated phishing, wallet-draining approvals, impersonation, and transaction-simulation attacks.
The FBI and security researchers have documented multiple methods used to exploit unsolicited promotions and deceptive wallet interactions. Independent verification remains central to helping users avoid airdrop scams before clicking links, connecting wallets, or signing transactions.
FAQs
What are airdrop scams?
Phishing websites or wallet malware can be induced through scams based on the distribution of fake tokens or NFTs.
Is it possible for an authentic airdrop to ask for a seed phrase?
No. Authentic projects should never need a seed phrase or private key to distribute their tokens as a reward.
What measures can be taken by the users before participating in the airdrop?
The users should investigate the airdrop campaign on their own, check the domain and contract address, and also thoroughly analyze any wallet requests.
What steps should a person take if they have shared their recovery phrase?
This phrase would be compromised, and all the funds associated with the wallet should be transferred to anothe





