Claiming a Crypto Airdrop? Run This 7-Point Checklist First

By Alexandr Kerya · · 7 min read

TL;DR - Run this seven-step checklist before you claim any crypto airdrop, so a fake claim page or an unlimited approval doesn't drain your wallet.

A countdown timer is ticking on a claim page, the tweet promised free tokens, and connecting your wallet is the only thing standing between you and the airdrop. This checklist applies any time something claims tokens are waiting for you: a token generation event, a retroactive reward for early users, or a claim page linked from a tweet or a Telegram DM. Run it before you connect a wallet, not after a balance shows up you didn't expect.

Before you start

You don't need the project's cooperation to check whether a claim is real. Every legitimate airdrop contract sits on a public chain, and its address either matches exactly what the project announced on its own account, or it doesn't. Confirm the announcement first - the official site, the verified X account, or a pinned post in the project's own Discord - never a link that reaches you first.

A manual look is possible. You can open the claim contract on Etherscan and read its verified source and recent approvals, checking whether anything looks obviously wrong. That shows you what the contract does in isolation. It does not show you whether the destination wallet it's approving already carries drainer, scam, or sanctions exposure from a different campaign entirely. Rather than reading raw contract code, screen the claim address and your own wallet with Plastron before you sign, and get one risk score covering scam, mixer, and stolen-funds exposure across Ethereum and six other chains.

Four checks that stand between an airdrop claim and a drained wallet A four-stage flow: verify the airdrop through the project's official channel, check the claim URL and contract address, cap the spending approval instead of signing unlimited, then revoke that approval once the claim confirms on-chain. Four checks before you sign an airdrop claim Skip one and the "free tokens" step is the one that empties the wallet. 1 Verify source Confirm through theproject's official siteor account only - nevera link sent to you. 2 Screen contract Match the claim URLand contract to theofficial one, then screenthe destination wallet. 3 Cap the approval Simulate the transaction,then approve only theexact claim amount -never "unlimited." 4 Revoke after Cancel the approvalonce the claim confirmson-chain, even ifnothing looks wrong. △ Skipping step 3 is how an unlimited approval outlives the claim window by months.
Four checks stand between a claim link and a drained wallet: verify the source, screen the contract and destination, cap the approval, revoke it after.

The checklist

Work through these in order. Each one closes a specific failure mode the ones before it can't catch.

  1. Confirm the airdrop through the project's official channel only - its verified website, its verified X account, or a pinned message in its own Discord.
    • Ignore anything that reaches you first by direct message, even from an account with the right name and photo.
  2. Type the claim URL yourself instead of clicking a shared link, and check every character against the project's known domain.
    • Phishing clones usually differ by one letter, a hyphen, or a swapped top-level domain.
  3. Verify the claim contract address against the one the project posted, not the one the claim page displays.
    • A cloned front end can point a real-looking interface at a completely different contract.
  4. Screen the claim contract and your destination wallet before you connect anything.
    • Check for prior scam reports, drainer associations, or sanctions exposure tied to either address.
  5. Simulate the transaction in your wallet before you approve it.
    • Most modern wallets show a plain-language preview of what a signature actually authorizes.
  6. Cap any spending approval to the exact amount you're claiming - never sign "unlimited."
    • An unlimited approval lets the contract pull tokens long after the claim window closes.
  7. Revoke the approval once the claim confirms on-chain, even if nothing looks wrong.
    • An approval left open is a standing liability, not a one-time risk.

Why are airdrop claims the easiest wallet-drainer vector?

Airdrop claims give an attacker something no other crypto scam gets for free: a legitimate-sounding reason to connect your wallet and sign something. On March 19, 2026 the FBI issued a public alert about a fake "FBI Token" airdrop circulating on the Tron network, impersonating a federal agency to get victims to approve a TRC-20 contract. Days later, when Backpack's token generation event went live on March 23, 2026 and distributed tokens to a quarter of its community, copycat phishing sites appeared within hours of the real claim window opening.

The mechanism barely changes from case to case. Scammers running a fake Jupiter airdrop pushed a token called $CJUP to Solana wallets, then pointed recipients at a phishing site that drained assets within minutes of a wallet connecting. Scam Sniffer has tracked over $800 million in wallet-drainer losses since 2023, and one operation alone - Inferno Drainer - took roughly $81 million from 134,000 victims between March and November of that year. None of those victims handed over a seed phrase. They signed an approval that looked routine.

The three places an airdrop scam hides its red flags Three groups of red flags: source red flags including unsolicited direct messages and unofficial channels, contract red flags including a mismatched address and an unverified claim page, and approval red flags including unlimited spending requests and a lack of transaction simulation. Where airdrop scams hide their red flags Three places to check - most fake claims fail at least one. Source - Reached you first by DM or an unofficial group- No post on the project's own verified channel- Asks for a seed phrase or a "gas fee" upfront Contract - Claim address doesn't match the official one- Domain differs by one character or a hyphen- Address carries prior scam or drainer reports Approval - Requests "unlimited" token spending rights- Wallet preview doesn't match what you expect- Approval sits open long after the claim closes △ One matched red flag in any column is reason enough to stop and re-verify.
Fake airdrop claims fail at least one of three checks: who the source really is, whether the contract matches, and what the approval actually authorizes.

FAQ

What happens if you already approved a malicious airdrop contract?

Stop connecting that wallet to anything else first. An open approval doesn't drain funds by itself - the contract still has to call it - so the immediate risk is time, not certainty. Go to a revocation interface and check what your wallet has approved, address by address, starting with unlimited approvals on your highest-value tokens. Then screen the wallet itself: if funds already moved, screening shows whether they touched a known drainer cluster, a mixer, or an address that later landed on a sanctions list.

Does a wallet screening tool catch a scam token before you claim it?

It catches the address, not your intentions. A screening tool reads the claim contract and the destination wallet against labeled scam, mixer, and sanctions data, then reports what it finds - it won't tell you whether the token has real utility or is worth claiming at all. Plastron's own labeled address set carries 3,901 addresses drawn from real scam, hack, and sanctions cases, with more than 3,354 of those tagged specifically for scam activity, plus the full OFAC sanctions list checked on every scan. A clean result isn't a guarantee the project is legitimate - it just means nothing in that address's history has been reported yet.

Is claiming an airdrop with a fresh, empty wallet actually safer?

It limits the damage, not the risk of the claim itself. A dedicated claim wallet with no other assets means a bad approval can't touch your main holdings, but the malicious contract or destination address is exactly as dangerous as it would be otherwise. Screen the contract before connecting either wallet, and never bridge funds from your main wallet into a claim wallet you haven't verified yet.

Do legitimate crypto airdrops ever ask for a fee before you can claim?

Only the network's own gas fee, paid from your own wallet to the network - never a separate payment to "unlock" or "activate" tokens. Any claim page that asks you to send funds to another address first, before you receive anything, is the scam. Legitimate projects don't gate a giveaway behind a payment.

Disclaimer: This article is for educational and informational purposes only and is not legal, financial, tax, or compliance advice. Crypto carries risk; you act on this information at your own risk. Always do your own research and consult a qualified professional before making decisions. Views are the author's own and do not constitute financial, legal, or investment advice.

About Plastron

Plastron is a free, non-custodial wallet screening tool. It checks Ethereum and six EVM chains for AML and KYT risk — sanctions exposure, mixer contact, and stolen-funds proximity — and returns a risk report in seconds. It reads public on-chain data only: it never takes custody of funds and never asks for private keys.

How Plastron works and who runs it →

Keep reading

What Is a Crypto Wallet Drainer? How to Tell If Your Wallet Was DrainedHow to Check and Revoke Risky Token Approvals on Your WalletHow to Check if a Crypto Address Is a Scam Before You SendCan a Multisig Wallet Get Sanctioned Like Any Other Address?