Fake Airdrops and Malicious NFTs
Surprise tokens and NFTs can be traps. Receiving them is harmless; interacting to 'claim' can trigger a wallet-draining approval. Ignore them, or burn spam with a trusted tool.
What it means
Scammers send tokens or NFTs to thousands of wallets. The item's name or metadata contains a link promising a valuable 'claim.' The claim page is the trap.
Why it matters
It exploits curiosity and greed — a surprise item that appears to be worth thousands. But value you didn't earn appearing from nowhere is the hook.
What happens if you ignore this
Connecting and signing on the claim site can grant spending approvals that let the attacker move your real assets. The 'reward' is bait for that signature.
Safety considerations
Never interact with unexpected airdrops. Don't click links in token metadata. Use a trusted wallet cleanup tool to burn spam safely, and keep valuables in a separate wallet.
Beginner tips
- Receiving a spam token is not dangerous — clicking or 'claiming' it is.
- Treat any 'you won' surprise in your wallet as spam by default.
- Use a burner wallet for experiments so a bad signature can't touch your main funds.
Common mistakes
- Clicking the link inside a surprise NFT to 'see what it is.'
- Approving a signature on a claim site to unlock a 'reward.'