Fake Airdrops & Drainer dApps

A claim page promising free tokens doesn't send you anything – it asks you to approve one thing. Here's the difference between a real claim and a dangerous permission.

The bait and the mechanism

Fake airdrop

A claim page dressed up as a reward. It promises tokens for an address, a task, a follow, or simply for existing – then asks you to confirm a transaction to “receive” them.

Drainer dApp

The site or contract behind the claim button. It isn't a token – instead of sending you anything, it requests permission to move assets you already hold.

The airdrop is the bait. The drainer is the mechanism. For what a granted approval actually lets an attacker do – and how to revoke one – see wallet drainers.

$800M+

in wallet-drainer losses tracked by Scam Sniffer since 2023

83%

drop in 2025 drainer losses vs. 2024 – $83.85M from $494M

$6.5M

the single largest 2025 theft, via one forged Permit signature

Losses tracked market activity, peaking near $31M in Q3 during 2025's strongest rally (Scam Sniffer) – the trend is down, the mechanism isn't gone.

How the fake claim reaches you

A promoted post or ad

For a familiar project's “reward”, linking to a convincing lookalike claim site.

A hijacked, trusted account

Attackers have pushed the same links through compromised accounts on X, Instagram and Discord.

An unprompted token in your wallet

Receiving it is harmless. The risk starts only if you follow its linked “instructions” elsewhere.

When the safety advice becomes the trap

April 2026 was the worst month for crypto theft on record: more than $629 million drained across two attacks – Drift Protocol ($285M, a compromised Security Council key) and KelpDAO ($292M, a forged bridge message).

Within hours, lookalike "revoke" sites echoing the real security guidance – revoke, migrate, claim, compensation – were seeded into reply threads under the genuine posts. The advice itself became the bait.

Six checks before you claim

  • Ask what the page wants

    A real claim needs a transaction or signature alone. Broad access to your USDT, ETH or NFTs is the thing to question.

  • Get to the page yourself

    Don't follow a claim link from a post, reply or ad – go to a bookmarked, independently verified site.

  • Don't mistake gas for an unlock fee

    A real claim may cost ordinary network gas. Sending crypto elsewhere to “unlock” your allocation is a red flag.

  • Don't disable a warning for a site

    A page telling you to enable blind signing or dismiss a wallet alert wants protection gone exactly when you need it.

  • Use a separate wallet for claims

    Keeping experimental dApp activity apart from your main holdings caps the damage of one bad approval.

  • Check your active permissions

    Leaving a site doesn't cancel an approval – see wallet drainers for the full revoke steps.

Where this meets your swap

Not a wallet connection

You choose a pair, provide a delivery address, and send an ordinary one-time transfer. A standard SimpleSwap exchange never asks you to connect a wallet or grant a token approval.

Address Check

Screen the address behind an unfamiliar token or "reward" first. Available to registered users, with monthly checks scaling by Loyalty Program tier, from 5 on Bronze to 25 on Platinum.

Neither tool undoes an approval granted elsewhere – see wallet drainers to check and revoke old permissions.

The rule to remember

Before approving anything, ask why a page that's supposed to hand you free tokens needs permission to spend tokens you already own. If you can't answer that clearly, don't approve it.

Key takeaways

  • A fake airdrop is the bait; a drainer dApp is the mechanism that actually moves your assets.
  • A real claim needs a transaction or signature alone – broad access to your tokens is the red flag.
  • Get to a claim page yourself; never through a link in a post, ad, or message.
  • Leaving a site doesn't cancel an approval – check and revoke it separately.

Fake Airdrops FAQ

A fake airdrop is the claim page pretending to give you tokens. A drainer dApp is the contract or site behind it that actually executes the theft, by requesting a token approval, an NFT authorization, or a signature that lets it move assets you already hold.

No. Receiving an unfamiliar token or NFT in your wallet doesn't give anyone control over your funds by itself. The risk starts only if you follow its linked instructions to an external claim page and approve something there.

No. Disconnecting from a site only ends that browsing session – it doesn't revoke anything on-chain. A malicious approval or signed permission stays active until you explicitly revoke it.See the full revoke steps

Yes. A standard SimpleSwap exchange never asks you to connect a wallet, grant a token approval, or sign a Permit-style permission – you send an ordinary, one-time transfer to a deposit address. It also can't remove approvals you granted elsewhere. Our only official domain is simpleswap.io.

Yes. SimpleSwap has processed more than 20M swaps since 2018 without ever requiring a wallet connection or token approval for a standard exchange. If a page claiming to be SimpleSwap asks you to connect a wallet and approve a contract, that request itself is the sign it isn't really SimpleSwap.Verify SimpleSwap