An airdrop โ€” a project handing free tokens or an NFT to early users โ€” is a real thing. Wallets that used Ethereum, Arbitrum, or Uniswap early collected four- and five-figure drops for activity they'd already done. But the crypto version of a giveaway scam doesn't work like a fake sweepstakes. It never asks you to send anything. It asks you to sign something โ€” and one bad signature can move every token you own to a stranger, often days later, with no undo button. This is the one trap that has no equivalent anywhere else in giveaways.

The drain happens at the signature, not the "connect" button

When a fake claim site says connect your wallet, connecting itself is harmless โ€” it's read-only, like showing someone your address. The theft is in the next prompt, the transaction you're asked to approve to "finish claiming." It rarely says "send my money." It reads as a routine token approval or an approve all permission that quietly grants the scammer's contract the right to move your tokens or NFTs on demand. You sign once, see nothing happen, and forget about it. The wallet gets swept later, sometimes a week on, so you never link the loss to the click.

The defense is to read the signature request before you sign it. MetaMask, Rabby, and Phantom all show the exact permission in the details pane โ€” the contract you're approving and what it can touch. A genuine claim is a gas-only transaction: you pay a small network fee and receive tokens, and you are never asked to approve spending to accept a gift. Two prompts are always fatal: an approve all on your NFT collection, and a gasless permit signature (it costs nothing, which is exactly why people click it โ€” it silently authorizes a transfer). And nothing legitimate ever needs your seed phrase; the instant a "claim" asks you to type your recovery words, it is 100% theft. When unsure, revoke: revoke.cash and Etherscan's token-approval page let you cancel permissions you've already handed out.

Vet the drop with a wallet that holds nothing

The single best habit is separating your money from your curiosity. Keep a burner wallet โ€” a fresh address with no meaningful balance โ€” and use it for any drop you haven't fully verified. If a signature there turns out to be malicious, the attacker inherits an empty wallet and your real holdings never touched the site. Fund it only with the tiny amount of gas a real claim needs, and move any tokens you actually receive out to your main wallet afterward.

Then do the boring checks a scammer is counting on you to skip. Real airdrops reward things you already did, and eligibility is verifiable against your address on the project's official site and its checkmarked X, Discord, and GitHub โ€” not a link in the replies. ๐Ÿšฉ Impersonator accounts with a near-identical handle post fake "official claim" links under real project tweets within minutes of any announcement; type the URL yourself from the pinned post instead. Paste the token's contract into a block explorer and glance at holder distribution โ€” if three wallets hold 90%, walk. And treat any "deposit to verify" or "pay a gas fee to this address" step as the scam it is: a real drop only ever gives.

Crypto giveaways can be legitimate. The rule that keeps you whole is blunt โ€” a real drop never asks you to send, and never asks you to approve.

Read every signature, claim from a burner, and never reveal your seed phrase. ๐Ÿ›ก๏ธ