how to check if a crypto airdrop is safe before claiming

What Authority Will the Airdrop Claim Receive From Your Wallet?

A legitimate airdrop can require a wallet signature or blockchain transaction, but the word claim does not describe what the wallet is authorizing. The same button can authenticate an address, transfer gas, approve token spending or call an unknown contract. Safety begins by identifying the exact authority granted and limiting what the claim wallet can lose.

Most faucet rewards are tiny. FaucetPay can help you collect small payouts from supported faucets, PTC sites and reward platforms in one microwallet before withdrawing later.

Set up FaucetPay to collect small rewards →

Use the Claim Authorization Budget

Treat every requested capability as part of the claim price.

  • Public address exposure
  • Message signature
  • Native-coin gas
  • Token approval amount
  • Contract transaction
  • Wallet assets visible to the dapp
  • Personal information and eligibility proof
  • Time limit and revocation plan

Start from an official announcement you can verify twice

Open the project website or established project account independently, then confirm that both identify the same claim domain and eligibility rules. Do not begin from a direct message, reply, search advertisement or token metadata link.

Eligibility should make historical sense

A real campaign normally explains why the address qualifies: prior protocol use, a snapshot, contribution, testnet activity or another defined event. A random page promising valuable tokens to every visitor creates no credible allocation logic.

The domain should match the project’s current documentation

Look for homographs, extra subdomains, shortened links and recently created copies. A polished design and valid HTTPS connection do not prove that the site is controlled by the project.

Verify the claim contract separately

Compare the contract shown by the wallet with the address published through an official project source or a verified explorer page. A token name, logo or familiar symbol is not a contract identity.

A message signature and a transaction are not equivalent

A simple message may prove address control without changing blockchain state. A transaction can move native coin, approve tokens or execute contract logic. Read the wallet’s full request rather than assuming every signature is harmless.

Token approval creates continuing authority

MetaMask explains that an approval lets a dapp move a specified token amount. An unlimited approval can remain active after the airdrop and expose unrelated holdings of the same token.

Gas should be paid through the wallet to the network

A legitimate on-chain claim can consume gas when the user submits the contract transaction. Sending a separate deposit, tax or activation payment to a supplied wallet address is a different action and a major warning.

Use a separate claim wallet with a strict loss limit

Move only the native coin needed for the verified transaction and avoid keeping valuable tokens or NFTs in the claim account. A separate address under the same exposed seed does not protect against recovery-phrase theft.

Simulate and inspect when the wallet supports it

Review predicted asset changes, contract method, approval target and spending limit. Stop when the wallet cannot explain the action or the result differs from receiving the expected token.

Random airdropped tokens are not invitations

MetaMask warns that unsolicited tokens often direct holders to fraudulent sites where they are asked to approve transactions or reveal recovery secrets. A token appearing in the wallet does not validate the linked claim page.

Do not disclose recovery or authentication secrets

No airdrop needs a seed phrase, private key, wallet backup, email password or two-factor code. A site asking for any of them is seeking account control rather than eligibility proof.

Use a Pre-Claim Evidence Card

Save the official announcement, domain, contract address, eligibility reason, wallet request, estimated gas, approval scope and date. This also supports later approval review and scam reporting.

After a legitimate claim

Verify the received contract in the explorer, review active approvals and disconnect the dapp. Move meaningful value to the intended storage wallet only after the token and route are independently understood.

Worked authorization comparison

Claim A uses an official domain, a published contract and one transaction that spends a small native fee and receives the expected token. Claim B arrives through a random DM, requests unlimited USDT approval and promises that a larger allocation unlocks after a deposit. The second claim exceeds every reasonable authorization budget.

Current conclusion

A safe airdrop claim is not defined by free tokens. It is defined by verified eligibility, a known contract and a narrowly limited wallet authorization whose maximum loss is understood before signing.

Evidence boundaries

Current MetaMask guidance documents airdrop phishing and approval abuse. Individual projects can use different claim architectures, so their published contracts and eligibility records remain decisive.

Pre-claim security documentation — July 29, 2026

Airdrop, approval and unsolicited-NFT guidance supports the authorization budget.

  • MetaMask airdrop phishing guidance: https://support.metamask.io/stay-safe/protect-yourself/tokens-and-transactions/how-to-tell-the-difference-between-a-regular-airdrop-and-airdrop-phishing-scams/
  • MetaMask token approval explanation: https://support.metamask.io/stay-safe/safety-in-web3/what-is-a-malicious-token-approval/
  • MetaMask NFT airdrop scams: https://support.metamask.io/stay-safe/protect-yourself/nfts/nft-airdrop-scams/
Scam-aware reminder

Be careful with websites that promise unrealistic rewards, ask for deposits before withdrawal, or require suspicious wallet connections. Small reward sites should never need your seed phrase.

FAQ

Is a gas fee always evidence of a real airdrop?

No. Gas can be legitimate, but the domain, contract and exact transaction still require verification.

Should an airdrop need unlimited token approval?

Usually no. An approval unrelated to receiving the claimed asset creates unnecessary continuing risk.

Can I claim from my main wallet?

Use a separate low-value claim wallet so the authorization cannot expose important holdings.

Does receiving a random token prove eligibility?

No. Unsolicited tokens are often used to direct users toward phishing sites.

What should I save before signing?

Save the official source, claim domain, contract, eligibility rule, gas estimate and wallet request.