Fake airdrops and fake support staff
Nobody needs to fool everyone. They need a few dozen out of the tens of thousands currently waiting to claim something. And "currently waiting to claim something" happens to be the state in which people click fastest — you were expecting a link.
Always arrive through your own bookmark or the app. Never through a link someone gave you — not from a DM, not from a group, not from search results, not from a comment. A genuine event is always findable inside the official app; if you can't find it there, it isn't happening.
Why airdrop season is peak season
Because for a few weeks, "unfamiliar link + do something + get tokens" is a completely normal-looking combination. Any other month you'd hesitate. During a launch that's precisely what you're waiting for.
Two things amplify it. Time pressure — claim windows run until the allocation is gone, and people in a hurry skip checks. And noise — the same event is reposted by countless accounts, genuine and otherwise mixed together, so identifying the original source is genuinely hard.
Which is why the defence isn't "learn to identify fake pages" — they keep getting better. It's changing how you arrive: whatever you see, go back to an entrance you already trust and confirm from there.
Method one: the fake claim page
Visually near-identical, with a domain that differs by a character or two, or uses a similar-looking suffix. You connect a wallet, press claim, and what actually executes is a transfer or an approval.
Things that help:
- Read the domain character by character, not by overall impression. Common tricks: an inserted hyphen, one swapped letter, a different top-level domain.
- Notice what it wants from you. Claiming an exchange promotion normally happens inside the exchange app; it doesn't require connecting an on-chain wallet and signing.
- Notice whether it's rushing you. "9 minutes 58 seconds remaining" pressure design is uncommon on official activity pages.
Still, the reliable move is the same one: don't click, open the app and find the entry yourself. If the event exists, it's there. If it isn't there, the opportunity wasn't yours to begin with.
Method two: the signature request
The most expensive of the four, precisely because nothing gets debited at the time.
Signing means granting a contract permission over a token in your wallet. After an unlimited approval, the other party can move that token at any point they like — possibly right then, possibly three months later when you've long forgotten about it.
① which token you're approving; ② what the limit is (if you can set a specific amount, do); ③ who the approved address is. If any of the three is unintelligible, cancel. Confirming something you don't understand is the most expensive habit available here.
Both Megadrop and Alpha involve Binance's Web3 Wallet, which means you carry one more layer of on-chain exposure than someone using only the exchange. The underlying difference between the two is in Web3 Wallet is not your exchange account.
Method three: the helpful stranger
Exchange notices arrive via in-app messages, announcements and push notifications. Staff do not start private conversations with you. No exceptions — hold that one line and an entire category disappears.
The usual script: you ask in a group why you didn't receive something, and within minutes a "support agent" messages you offering to look into it, then steers you towards a "verification page" or asks for a "sync code". That code is generally your seed phrase or a login verification code.
The boundary is unambiguous: nobody, for any reason, needs your seed phrase, private key or verification code. Real support won't ask; anyone asking isn't real support.
Method four: the token that appeared by itself
An unfamiliar token shows up in your wallet, apparently worth a decent amount. You go to sell it, and that's where it starts.
These contracts are frequently built with restrictions: buyable but not sellable, or requiring an approval before a sale, or redirecting the trade action to a phishing site. Making you money was never the design; moving you to the next step was.
The handling is trivial: treat it as though it isn't there. Hide it in your wallet, don't tap it, don't research it, don't try to sell. Sitting there it costs you nothing. Interacting is the only way it hurts you.
Why these are getting harder to spot
Because cloning a site now costs approximately nothing. Copy the whole front end, register a lookalike domain, add a certificate — an hour or two of work.
Two consequences worth adjusting for:
- "Looks professional" is no longer a signal. Padlock icon, polished layout, live chat widget — fakes have all of them.
- Domain similarity keeps rising. One letter changed, a hyphen added, a different suffix; at a glance they're indistinguishable.
So move the judgement earlier: not "does this page look genuine" but "how did I get to this page". Arrived from inside the app, you're fine. Arrived from a link someone sent, it's worth re-checking however convincing it looks.
That's why the rule at the top is stated so absolutely — it converts a problem that needs judgement into a habit that doesn't. Habits are more reliable than judgement, particularly when you're in a hurry.
What to say when someone asks you
Someone brings you a link and asks whether it's real. The most useful reply isn't an analysis of that link.
Because analysis can be wrong, and next time they still won't be able to do it themselves. Three sentences work better:
- "Don't click that — open the app and see whether the event is there." Not there means it doesn't exist; there means go in through the app.
- "No event ever needs your seed phrase, private key or verification code." That one sentence blocks the worst losses.
- "If you're not sure, wait a day." Real events don't evaporate because you were slow; fake ones depend on the countdown.
And if you find they've already clicked and already signed: get them to revoke the approval and move the remaining assets first, before asking for the details. Time matters more than information at that point.
Four habits
- Fixed entrances. Exchange and wallet both via app or bookmark, never from search results or someone's link.
- Separate wallets. One wallet reserved for on-chain activities, holding only what that activity needs. Your main position never touches an event page.
- Periodic approval cleanup. Every so often, review approvals with a block explorer's tool and revoke what you no longer need.
- Slow down. Every one of these depends on you being in a hurry. Thirty extra seconds spent going back to the official entrance is the most effective item on this list.
The second one especially. It caps your downside — even if you do get caught, what's lost is whatever was in the small wallet. The overhead of maintaining an extra wallet is negligible, and what it prevents is the worst-case outcome.
If it already happened
In this order, as fast as you can:
- Revoke the approval. Use a block explorer's approval manager to remove that contract's permission. It costs a small fee and stops the bleeding.
- Move what's left. To a brand new address, not another one you've used — you don't know what else is compromised.
- If an exchange account is involved: change the password, reset two-factor, and check whether anything has been added to the withdrawal allowlist or API keys.
- Keep evidence. Transaction hashes, screenshots, message logs.
Don't engage with any "asset recovery service" that appears. People who have just been hit are the primary target for a second round, and these services are essentially all fraudulent — they're aiming at exactly how much you want the money back. And don't send gas to the compromised wallet to "rescue" what's there: if the key is exposed, whatever you send follows the rest.
To be direct: assets sent on-chain are, in practice, not recoverable. Everything above is damage limitation, not retrieval. Which is exactly why the four habits are worth the effort — after the fact, there is very little available.
This category doesn't rely on technical sophistication. It relies on you happening to be waiting for a link. Fix the habit of where you enter from, and you can afford to forget every detail above.
Questions people ask
A token I don't recognise appeared in my wallet. Can I sell it?
Leave it alone. Tokens like these often have contracts built to trap you: trying to sell routes you to a phishing interface or requires an approval first. The safe response is to treat it as though it isn't there and hide it in your wallet.
Would official support ever message me about an airdrop?
No. Exchange notices come through in-app messages, announcements and push notifications. Staff do not open private conversations with you and do not contact you from personal accounts. Treat any support agent who messages first as fake.
What is the difference between signing and sending?
Sending moves tokens out. Signing grants a contract permission over them. Signing takes nothing immediately, which is why people relax — but after an unlimited approval the other party can move that token whenever they choose.
I already signed something. What now?
Revoke that contract's approval immediately using a block explorer's approval manager, then move the remaining assets to a brand new wallet address. Revoking costs a little in fees and is far cheaper than staying exposed.