Airdrop season always brings the same problem: for every real campaign, there are ten fake ones designed to drain wallets.
The patterns I keep seeing:
- A "claim" site that asks you to sign a transaction instead of a message
- Urgency: "claim in the next 2 hours or lose your allocation"
- A domain that looks almost right — one letter off, or a different TLD
- Promotion coming from a hacked or bought X account with old followers but no real history
- Requests for a seed phrase, which no legitimate project will ever make
What I do before connecting anything: check the project's official channels for the exact link (never click links from replies or DMs), use a burner wallet with nothing valuable in it, and read what permissions the transaction is actually requesting.
But I know people here have better methods than mine.
**Questions:**
- What's the fastest check you run before connecting a wallet to a claim site?
- Have you ever come close to getting drained — what was the warning sign you almost missed?
- Which tools do you use to check contract permissions?
If you've seen a scam campaign recently, post the pattern here (no live links) so others can recognise it.