How to Tell Real Airdrops from Fake: 5 Signs It's a Scam
A friend sent me a screenshot: he'd seen a "such-and-such project airdrop now open, 24 hours only" in some group, clicked through to a site that looked the part, connected his wallet, and a confirmation window popped up. He was about to tap it when he thought to ask me first, "is this safe?" — thank goodness he asked. Tap that window and the coins in his wallet would more or less stop being his. This kind of phishing is common enough that even Binance Academy has a dedicated explainer on airdrop scams.
Fake airdrops are getting slicker, and you genuinely can't tell real from fake by "how pretty it looks." But the good news: to pull it off, a scammer has to make you do at least one of a few specific actions. Learn to recognize the signals behind those actions and, however good the packaging, you can call a stop on the spot. Here are five — see any one of them and don't move yet.
Sign 1: it asks you to connect and approve the moment you arrive
The normal order for claiming an airdrop is: connect the wallet first (this step only lets the site see your address), check you're eligible and how much, and only then sign once when you claim. The problem is in what that one signature is "for."
A fake airdrop often pops up, the instant you connect, a window asking you to "approve" some contract to spend your tokens — and usually with an unlimited approval. You think you're claiming an airdrop; you're actually handing the other side a permit to "move this kind of coin out of your wallet whenever they like."
How to verify on the spot: read clearly which kind of action the wallet window is asking for. If you're only claiming an airdrop, the reasonable thing is "sign a message (signature)" — there shouldn't be wording like "approve some contract to spend your USDT / USDC / a token." See an approval, see a long contract address asking you to authorize spending your assets, cancel first. The difference between signing and approving, and how a malicious approval moves your coins out, is explained most clearly in malicious signatures and approval scams.
One more small detail: an upstanding claim page usually shows you "how much your address can claim" first, so you have some sense of it before you sign. If the moment you connect, with no eligibility or amount shown yet, it's rushing you to hit a confirm button — that order is itself wrong. Asking you to approve before giving you any information means what it wants isn't to let you claim coins, but that single tap of confirm.
Sign 2: it asks for your private key or seed phrase
This is the simplest, and the most fatal. Any page, any "support agent," any "verify your wallet" step that tells you to enter your private key or seed phrase is a scam, 100% of the time, no exceptions.
The seed phrase is the master key to your entire wallet, and a normal airdrop never needs it from start to finish. The only person who'll ask for it is someone who wants to steal everything you have. The pitch will be dressed up reasonably: "to confirm it's really you," "we need to sync your wallet to claim," "the system detected something unusual, please re-verify" — however reasonable, it's fake. Burn one rule in: this string of words is only ever entered when "you yourself" create or restore a wallet, inside a wallet app you trust. Any web page, any chat window telling you to type the seed phrase is a scam.
Watch out for variants too. Some don't tell you to type it directly, but give you a "scan a QR code to connect your wallet" step, or pose as a popular wallet's official page asking you to "import" your account. The point isn't what packaging it uses — it's that the moment your seed phrase leaves your own wallet app and goes anywhere else, there's a problem. Even MetaMask's official docs list "never reveal your seed phrase to anyone" as the first rule, which shows how basic this one is.
Sign 3: it wants you to pay first to unlock
"You've won a big airdrop, but you have to pay a little fee / deposit / unlock charge first to withdraw it." This is a classic of classics.
The truth: claiming a real airdrop costs you at most a little on-chain gas fee (paid by your wallet directly to the network, not to a person), and the amount is usually small. No upstanding airdrop will ever ask you to "wire a sum to them first" before releasing coins. The logic is simple — if it's a free gift, where's the sense in you paying before it's given?
How to verify on the spot: distinguish "paying gas" from "paying a person." Paying gas is your wallet signing a transaction, charged by the network; but "please wire a sum to this address to unlock," which asks you to actively transfer to an address, close it immediately. You can also paste the address they give you into Etherscan or BscScan — you'll usually find a pile of incoming records from victims, which is the smoking gun.
This kind of scam has a sequel too, the "pig-butchering top-up": you pay the first sum, the other side says "it's not enough, you need to add a bit more to release the larger amount," and step by step they reel you in deeper. The moment you find yourself in the loop of "paying again just to get back the money you already paid," that's the textbook structure of a scam — the time to cut your losses is now, not on the next payment. Remember: you never actually won that airdrop; the so-called withdrawal is just a hook to keep you paying.
Sign 4: the URL is a little off
The body of a phishing site is that string in the address bar. Scammers make the domain almost identical to the official one: off by a letter, an l swapped for a 1, a similar spelling, or a string of noise tacked on the end. You glance at it and think "yep, that's the one," but it's off by a hair.
How to verify on the spot: don't click links from DMs, groups, or ads. Always go through from a source you trust — the project's official channel, a major exchange's listing page, the official link indexed by a block explorer. For the habit of checking before you paste an address or enter a site, run through wallet address check once. Read the domain in the browser's address bar character by character before connecting your wallet.
There's one scenario that's especially easy to fall for: you search a project name in a search engine, and the top one or two results are ad slots whose domain looks close enough — but clicking through lands you on a phishing site. So the ads at the very top of search results are exactly what to be most wary of. Another commonly overlooked detail: the little HTTPS padlock only means the connection is encrypted, not that the site is run by good people — a scammer's phishing site can have a padlock all the same. Don't treat "has a padlock" as a safety guarantee. To understand the principles behind wallet connection and signing, ethereum.org's security page has a solid intro.
Sign 5: pressure to act "right now"
"24 hours only," "last 100 spots," "expires if you miss it" — these countdowns and scarcity lines have one purpose: to deny you the time to check calmly. Because the moment you stop to look into it, you'll probably spot the cracks.
A genuinely sizable airdrop usually has a long claim window and isn't short of your few minutes. The more it rushes you, the more it plays on your fear of missing out, the more you should slow down.
How to verify on the spot: faced with pressure tactics, deliberately stop for 10 minutes, go back to the project's official channel to confirm the thing even exists, and confirm the correct URL of the claim entry. If 10 minutes makes you miss a real airdrop, the loss is limited; but if the thing you impulsively tapped is fake, it could be everything in your wallet. For safety concepts, Binance's official support center has an anti-fraud section for reference too.
Keep an eye out for one variant: the other side builds a "you're special" mood — "only going to the first 100," "your address was chosen." The flattery of being singled out lowers your guard, which is exactly what it's after. A real airdrop is about "everyone who qualifies can claim," and won't stage this picking-you-out drama. Put pressure and scarcity together and nine times out of ten it's packaging.
Read the five signals together: connect-and-approve, asking for your key or seed phrase, paying first, an off URL, rushing you to tap. Hit one and you should stop; hit two or more and it's almost certainly a scam.
Editor's test: nearly fooled by a fake airdrop
The one that stuck with us most was a single "project" for which we got two versions of the claim link back to back — one from the official announcement channel, one shoved into a DM. The two pages looked virtually identical: the colors, the fonts, that green claim button all matched, and you genuinely couldn't tell them apart by the screen. The difference was hidden entirely in the address bar: the DM one swapped a lowercase l in the official domain for the digit 1, and unless you stared at it under magnification, your eye would auto-correct it into the right thing.
We put the two URLs side by side and checked the link against the official channel once more before confirming the DM one was fake. That episode locked in a habit: any airdrop link, we only ever click in from the project's own channel — anything someone "kindly" forwards, we don't touch. The biggest takeaway of the whole thing: a fake airdrop doesn't scam the stupid; it bets you're "in a hurry and too lazy to check the URL character by character." Treat the five signals in this guide as a checklist you carry, and most fake pages give themselves away before you even connect your wallet.
Memorize these five signals and you can block the vast majority of fake airdrops out there. Their shared logic really comes down to one line: a real airdrop lets you "understand it, not rush, not pay first, not hand over your keys"; the moment any one of those is broken, treat it as fake. Better to miss a real one than lose your whole wallet — which is worth more is, honestly, obvious at a glance.
Spotting signals is only step one; the full safety flow for actually claiming an airdrop is in the complete airdrop guide, step by step. To get a systematic picture of the various cons you'll meet with a self-custody wallet, carry on to the 5 most common wallet scams. Whether you claim a given airdrop is fleeting; this "stop a moment before you act" judgment is what stays with you. If you want to quickly check whether an address or URL is right, you can also use our address checker.
One practical closing suggestion: the best place to train your judgment is somewhere you already know, where support can help if something goes wrong. Get fluent with the basic flow on an exchange first, then take that wariness with you to on-chain airdrops — it'll be much steadier. If you don't have an account yet, you can use invite code BNB3311 to sign up for Binance and pick up the fee rebate while you're at it (the actual percentage is whatever Binance shows on its page and may change with their policy).