Airdrop Scams Do Not Start at Your Wallet. They Start With a Message You Believe.

An airdrop scam offers you free tokens and takes your wallet instead. The theft takes one click. Everything that makes that click happen occurs earlier, while you are deciding whether a message is real.
Most warnings about this cover the click. Far fewer cover the hour before it. That hour is where the decision actually gets made, and it is the cheapest place to stop.
What an airdrop is when it is genuine
An airdrop is when a project sends free tokens straight to people’s wallets. A wallet is the app that holds your coins and signs for them. Projects do this to reward early users, or to advertise themselves to new ones.
Real ones exist, and that is the whole problem. The word carries an honest meaning, so it does not sound like a warning when somebody dishonest uses it.
The FBI made this point directly in a June 2025 notice about airdrop fraud on one particular network. It described the feature as one built “for marketing purposes” that criminals then exploit. The tool is ordinary. What gets done with it is not.
The click is the last step, not the scam
Here is the ending first, so the rest of this can be about the part that matters.
You arrive at a page offering tokens. To claim them, it asks you to connect your wallet, or to type in your recovery words. Recovery words are the short list of words that restores a wallet, and anyone holding them owns everything inside it.
The FBI notice describes this step precisely. The connection “often requires the user to input their login and security information, including seed phrases to complete the connection”. After that the wallet gets emptied.
Read it as a sequence rather than as a single event. By the time you are looking at that page, you have already made three or four smaller decisions. Every one of them was easier to get right than the one that followed it.
| Stage | What happens | What it costs the attacker | Can you still stop? |
|---|---|---|---|
| The bait | An offer of free tokens appears in front of you | Almost nothing | Yes |
| The setting | It arrives somewhere you already trust | A few minutes of copying | Yes |
| The address | You follow a link to a page that looks right | The price of a domain name | Yes |
| The clock | You are told the window is closing | Nothing | Yes |
| The click | You connect the wallet or type the words | Nothing | No |
Where the money actually goes
This is not really a crypto problem, and the public numbers say so plainly.
The US Federal Trade Commission publishes what people report losing, sorted by how the scam reached them. Its April 2026 summary found that in 2025, nearly 30% of people who reported losing money to a scam said it started on social media. Reported losses along that route reached $2.1 billion.
That was roughly eight times the 2020 figure. The agency carries two caveats of its own worth repeating: reports were not collected during the 2025 government shutdown, and most scams are never reported to anybody at all. So this is a floor rather than a total.
The crypto-specific picture matches. The FBI’s 2025 annual crime report puts cryptocurrency investment fraud at the top of American losses for the year, at $7.2 billion reported. It describes the approach in one sentence: scammers “typically initiate contact through text messages, social media sites, advertisements, or dating applications and then quickly move the conversation to a messaging platform”. Contact in public, then a private room.
That last move matters more than it looks. A public reply can be seen, doubted and reported by other people who are watching. A private message has no witnesses at all.
None of that means these platforms are bad. It means reaching millions of people costs a scammer close to nothing. The Commission states it plainly: “At very little cost, scammers can reach billions of people from anywhere in the world.”
So the skilled, expensive part of the attack is not technical at all. It is persuasion, and it happens in public where anyone can watch it.
The four moves that do the real work
Nearly every fake airdrop is built from some mix of four things. None of them need any technical ability.
The lookalike address. A web address one character away from the real one. A swapped letter, an extra word, a different ending. Skimmed left to right it reads correctly, and reading it slowly is the entire defence.
The reply underneath the real post. A genuine account posts something. Within seconds, accounts wearing its name and picture reply beneath it with a claim link. The reply borrows the credibility of the post it is attached to, which was the point of attaching it there.
The handle that is almost the handle. An added underscore, a doubled letter, a capital I standing in for a lowercase L. Side by side you would catch it every time. You are almost never shown them side by side.
The clock. A closing window, a countdown, a limited allocation. The FTC describes the pressure as deliberate: “Scammers want to rush you.” It also notes that being “excited about a free gift” makes the warning signs harder to see, which is the same mechanism as fear and works as well.

This community has its own live example. Sites have appeared offering a “$POORGOAT airdrop” with an allocation supposedly waiting to be claimed. We documented one on 9 August 2026 and it was still answering on 16 August. There is no evidence that any of them are connected to PoorGoat, and they carry the familiar signs. They are described here and deliberately not linked.
Why “the official account linked it” proves less than it sounds
This is the part most guides skip, and it is the one worth keeping.
A link from an official source is a claim about one moment in time. Accounts get suspended. Profile fields go stale. Descriptions carry on pointing at things that were replaced weeks ago.
The honest example is close to home. This project’s own Telegram channel description spent part of this month still advertising a website and an account that had both been superseded. Nobody was being deceptive. A field was filled in once and not revisited. We checked it again on 16 August 2026 and it now carries the current pair.
There is a stranger version of this that anyone can see today. Two of the largest coin trackers publish different official links for this same coin. One lists the community website and the community channels. The other lists an Instagram story and a single post by the account that first created the coin. Both are being honest. They read from different places, which is the whole explanation. We checked both on 16 August 2026.
Nothing about that stale field was an attack, and that is exactly why it is worth showing. If an ordinary forgotten setting can point you somewhere wrong, an attacker does not need to break anything to achieve the same result.
The project’s education site states its own position in one line: “We will never DM you. We will never ask you to connect a wallet.” An unexpected message is the tell, whatever name is sitting on top of it.
What actually protects you
The defence is unglamorous, and it involves inspecting nothing technical whatsoever.
Go to the address you already have, rather than the one in the message. The FTC’s guidance on impersonation puts it in a sentence: contact the organisation “using a phone number or website you know is real”, and “don’t use the information in the message”. That one habit defeats all four moves above at once, because every one of them depends on you following a link somebody handed you.
Then treat unexpected offers as attacks by default. The FBI’s advice has the same shape. If you did not sign up for a rewards programme and an offer of free tokens turns up, confirm it with the provider before handing over anything, including your attention.
Nothing is lost by checking. A real airdrop is still there in ten minutes, and a real project will not mind you arriving through your own bookmark. The only offer that cannot survive a short pause is the one that was never real.

Slow down when a message tells you not to. Urgency is a claim like any other, and it is the one claim in a scam that is reliably false.
One last warning, because it catches people twice. The FBI advises being “cautious of individuals or companies claiming they can assist in recovering funds lost in scams, as this may be an additional scam”. People who have been drained get targeted again by the offer to undo it.
The click is the cheapest part of this to defend against, because by then there is nothing left to decide. Everything expensive happens earlier, in ordinary moments that never feel like security decisions while they are happening.
If you want the machinery underneath the click, it is next door. How wallets actually get drained covers what you approve when you sign, and how to check what you have already approved. What a seed phrase is explains why those words are the entire account. What a rug pull is covers the losses that come from inside a project rather than from outside it.
Free is the oldest hook there is. Ignoring one has never cost anybody anything.
Official contract address · Solana
Ai66LHZG9MCzg1WKdawwqduVAXpNDUuV8M3uyq5ppump