random token appeared in my wallet

What Is Safe to Inspect Without Giving the Random Token Any Authority?

A public wallet address can receive tokens from anyone. The unexpected balance does not mean the sender has control of the wallet, and it does not need to be removed on-chain. The danger usually begins when the holder follows a URL, connects to a claim page, approves spending or tries to swap an asset engineered to fail safely only on the scammer’s website.

Most faucet rewards are tiny. FaucetPay can help you collect small payouts from supported faucets, PTC sites and reward platforms in one microwallet before withdrawing later.

Set up FaucetPay to collect small rewards →

Use the Unsolicited Asset Quarantine

Keep investigation passive until legitimacy is independently proven.

  • Do not visit a URL in the name or metadata
  • Do not connect the wallet
  • Do not approve the token
  • Do not attempt a random swap
  • Do not pay to burn or remove it
  • Inspect only the public address and contract
  • Hide or mark the asset as spam

Arrival alone does not authorize spending

MetaMask explains that sending tokens to an address does not give the sender access to funds or secrets. The scam depends on persuading the recipient to perform a later dangerous action.

Public addresses make mass distribution cheap

Scammers can collect active addresses from blockchain history and send tokens or NFTs to many of them. The token’s presence does not mean the sender knows the owner’s identity or has compromised the private key.

Token names can contain instructions

A ticker, NFT image or metadata field can advertise a redemption website or phone number. Treat those instructions as untrusted user-generated content, not as part of the wallet protocol.

Fake value creates the urge to swap

An explorer or wallet can display a large token quantity or unreliable estimated price. A scam contract may lack real liquidity, block normal transfers or direct the user to a malicious custom exchange.

Passive explorer checks are sufficient initially

Inspect the contract creator, holders, transfers, verified source status, explorer warnings and liquidity references without connecting the wallet. Do not assume that a verified contract automatically represents a reputable project.

Token detection is a filter, not certification

MetaMask notes that automatic detection uses curated lists and can omit obscure tokens. Being hidden can be a warning, while being visible does not guarantee safety or market value.

Approving the token can expose other holdings of that asset

An approval lets a contract spend a specified token amount from the wallet. A malicious site can request unlimited access to a valuable token while pretending the transaction is only for selling the random asset.

A swap can contain unrelated calls

Read the contract method, token changes and approval target. Reject a transaction that moves native coin, valuable tokens or NFTs beyond the unsolicited asset.

Do not pay gas merely to erase the token

Blockchain balances cannot always be deleted from public history. Hiding the token in the interface is usually safer and cheaper than calling an unknown burn, transfer or removal contract.

Check whether the wallet was already exposed

If the token appeared after a suspicious connection or signature, review recent transactions and active approvals. The arrival itself is harmless, but it may coincide with another interaction that needs remediation.

Use a Quarantine Record

Save the network, contract, first-seen transaction, explorer warnings, displayed value and whether any interaction occurred. This prevents accidental re-investigation through the scam token’s own links.

If you already signed

Disconnect the site, inspect the transaction and revoke suspicious approvals through a trusted wallet or explorer tool. If a recovery phrase or private key was exposed, move assets to a newly generated secure wallet.

Worked quarantine

A wallet receives 50,000 tokens named CLAIM-USDT.NET. The explorer shows thousands of identical transfers and no credible market. The user hides the token, records the contract and does not visit the domain. No wallet authority is granted and no gas is spent.

Current conclusion

An unsolicited token should remain quarantined. Inspect its public contract only, ignore embedded instructions and never let curiosity turn a harmless balance entry into a wallet approval or transaction.

Evidence boundaries

MetaMask guidance documents unsolicited-token phishing, NFT metadata traps and approval abuse. Contract behavior and explorer labels can change, so inspection should remain passive and current.

Asset-quarantine documentation — July 29, 2026

Token-airdrop, approval and NFT-spam guidance supports the quarantine model.

  • MetaMask airdrop phishing guidance: https://support.metamask.io/stay-safe/protect-yourself/tokens-and-transactions/how-to-tell-the-difference-between-a-regular-airdrop-and-airdrop-phishing-scams/
  • MetaMask malicious token approvals: https://support.metamask.io/stay-safe/safety-in-web3/what-is-a-malicious-token-approval/
  • MetaMask NFT airdrop scams: https://support.metamask.io/stay-safe/protect-yourself/nfts/nft-airdrop-scams/
Scam-aware reminder

Be careful with websites that promise unrealistic rewards, ask for deposits before withdrawal, or require suspicious wallet connections. Small reward sites should never need your seed phrase.

FAQ

Can a token steal funds by appearing?

No. Risk begins when the holder follows links, signs transactions or grants approvals.

Should I try to sell a random token?

Not before independent contract and liquidity verification; scam tokens often use the swap attempt as the attack.

Should I transfer it away?

Usually no. Hiding it avoids gas and unknown contract behavior.

What can I inspect safely?

Use the public explorer to inspect the network, contract, holders, transfers and warnings without connecting the wallet.

What if I already approved a contract?

Review and revoke the approval through a trusted tool, then inspect recent wallet activity.