Scam Recovery & Victim Help

Crypto Airdrop Scam: What to Do If a Fake Airdrop Drained Your Wallet

If you tried to claim a crypto airdrop and now your wallet is drained or missing tokens — you hit a wallet drainer. Here’s what happened, what to do right now, and how to protect yourself.

This happens thousands of times every day. You saw a tweet, got a DM, or clicked a link promising free tokens from Uniswap, Arbitrum, or some new protocol. You connected your wallet, signed what looked like a claim transaction, and then your tokens disappeared. What you walked into was a crypto airdrop scam — one of the most financially devastating traps in this space.

You’re not stupid for falling for it. These scams are professionally designed. Let’s get to work.

How a Crypto Airdrop Scam Actually Works

The mechanics of an airdrop wallet drainer are simple but brutal.

Scammers build websites that look identical to legitimate airdrop campaigns. They copy the branding of real protocols — Uniswap, Arbitrum, LayerZero, and others — right down to the fonts, color schemes, and official-sounding domain names. Instead of uniswap.org, you might land on uniswap-airdrop-claim.io or something just different enough that you don’t notice in the excitement of free money.

They promote these sites aggressively. Twitter/X ads. Discord DMs. Telegram channels. Google and Bing search ads that appear above the real project’s website in results. Search for “Arbitrum airdrop” during a real airdrop campaign and you may see a scam ad at the top of the page.

Here’s the part that matters technically: when you connect your wallet and click “Claim,” you are not receiving tokens. You are signing an approve transaction — a legitimate blockchain function — that gives a drainer smart contract unlimited permission to move every token in your wallet. You have handed over the keys.

Within seconds, an automated bot sweeps every token with any value. The funds are routed through mixers, tumbled through multiple wallets, and converted. By the time you notice something is wrong, they are gone.

The Uniswap airdrop scam and its cousins mimicking every major protocol have operated this way for years — because the attack keeps working. It exploits trust in recognizable brands and uses a legitimate blockchain feature as a weapon. Understanding that is the first step toward not falling for it again.

Act Now: Stop the Airdrop Wallet Drainer Before It Completes

If you signed a suspicious transaction in the last few minutes, stop reading and go to revoke.cash immediately. Every second matters — some drainer bots run on a delay.

Here’s what to do, in order:

  1. Go to revoke.cash and connect the wallet you used to claim. Do nothing else first.
  2. Revoke every unlimited approval, starting with tokens that have the highest value. A drainer may have permissions it hasn’t used yet.
  3. Move remaining tokens to a fresh wallet immediately. If tokens are still showing in your wallet, transfer them to a completely new address before the bot runs. Some bots queue and execute every few minutes, not instantly.
  4. Do not use that wallet again. Create a new one. Treat the compromised wallet as permanently burned.

If your tokens are already gone, revoking approvals still matters — it prevents additional damage if the drainer was granted permissions on multiple token types.

For a full walkthrough on approvals, hardware wallets, and rebuilding a secure wallet setup after a compromise, read our Crypto Wallet Security: Complete Setup Guide. It covers everything from seed phrase storage to starting from a clean security baseline.

Was It Real? How to Verify a Fake Airdrop Crypto Claim

If you’re not certain whether what you claimed was legitimate, here’s how to check.

Go to the official project’s website and Twitter directly — not via any link you’ve been sent. Type the URL yourself or use a bookmark you’ve previously verified. If Uniswap or Arbitrum ran an actual airdrop, it will appear on their official Twitter account, in their documentation, and across major outlets including CoinDesk, The Block, and CoinTelegraph. Real airdrops by major protocols get substantial news coverage before they happen.

Was the only source a DM, a Telegram channel, or a search ad? Then it was fake. Real airdrops don’t need to find you. You navigate to them.

Check your transaction history on Etherscan. Go to etherscan.io, paste your wallet address into the search bar, and look at recent activity. You’re looking for:

  • An approve call to a contract address you don’t recognize
  • Outgoing token transfers you didn’t initiate
  • Interactions with a contract that has no verified source code

If you see an approve transaction followed by outgoing token transfers — you’ve confirmed the drainer was real. The contract address in that approval is the attacker’s drainer contract.

This type of attack shares DNA with broader crypto scam tactics — fake urgency, brand impersonation, and engineered trust. Recognizing those patterns is your best long-term protection.

Document the Crypto Airdrop Scam and Report It

If funds were taken, your next step is building a documentation trail. I’ll be direct with you: the odds of financial recovery are extremely low. But reporting matters for law enforcement investigations and protects other potential victims.

Collect the following before anything disappears:

  • Screenshot the fake airdrop site — including the full URL in the address bar. Scammers take sites down fast.
  • Copy the drainer contract address — visible in your Etherscan transaction history as the contract you approved.
  • Save all transaction hashes for unauthorized token movements out of your wallet.
  • Screenshot the source — the tweet, ad, Discord DM, or Telegram post that sent you there.

Where to file reports:

  • IC3.gov — the FBI’s Internet Crime Complaint Center. File a full complaint with all of the above details.
  • ReportFraud.ftc.gov — the FTC complaint portal.
  • Google Safe Browsing — report the phishing URL at safebrowsing.google.com/safebrowsing/report_phishing/ so Chrome will warn future victims.
  • The platform where you found it — report the ad to Google or Bing, report the tweet or DM to X/Twitter, Discord, or Telegram.

Report even if you believe it won’t lead anywhere. These complaints aggregate into law enforcement databases and help investigators identify repeat actors and infrastructure.

How to Protect Yourself From Every Future Airdrop Scam

You now understand more about fake airdrop crypto attacks than most people in this industry. Here’s what that knowledge looks like in practice:

Never click airdrop links from DMs, emails, or ads. Navigate directly to the official project site. Type the URL or use a verified bookmark. That one habit eliminates most of the attack surface.

Check revoke.cash before any airdrop claim. Go there first, review your current approval state, and revoke anything you don’t recognize. Start every claim from a clean position.

Use a dedicated burner wallet for airdrops. Create a separate wallet — never your main one — specifically for airdrop participation. Fund it with only enough ETH for gas fees. Keep your primary holdings on a hardware wallet that never touches a claim site. If the burner gets drained, you lose gas money, not your portfolio. Our DeFi Wallet Security Best Practices guide covers this setup in detail.

“Free tokens” that require signing a transaction are almost always drainer scams. Real airdrops distribute tokens to your wallet address automatically — they already know your address if you qualify. If claiming requires you to approve a contract, treat it with maximum skepticism. Verify that contract’s source code on Etherscan before you sign anything.

Conclusion

A crypto airdrop scam turns the blockchain’s own approval mechanism against you. It’s technically elegant and financially devastating. If you’ve been hit: revoke permissions at revoke.cash immediately, document everything, and file reports with IC3 and the FTC. If you caught it fast, the steps above may still save your remaining tokens.

The harder truth is that the airdrop wallet drainer playbook has barely changed in four years — because it keeps working. Awareness is the cheapest protection. Free tokens aren’t free if claiming them costs you everything else in your wallet.

Overwhelmed? Book a “Was I Scammed?” session ($149) — on-chain trace + a documentation pack for the FBI/IC3, police, and your bank. I will NOT promise to recover your funds; anyone who promises that is scamming you a second time. Book here

Want the full DeFi research every Friday? Wednesday scam alerts + Friday deep dives — premium newsletter, $9/month.
Upgrade to Premium →