Official MASTR logo MASTR Support the work
Contents
← Wiki home

Scam patterns

Fake airdrops and claim pages

An unexpected asset can be an advertisement for a malicious website.

Scam guide · 1 min read

Research articles and reference entries are published in English. Navigation is available in seven languages.

In this article
  1. Check the claim outside the message

An unsolicited token or NFT may carry a name, image or message directing the recipient to a reward website. Its presence in the wallet does not mean the wallet was compromised or that the claim is legitimate. The dangerous step may be the later website interaction or signature.

Check the claim outside the message

Use the project's established announcement channels and verify the exact domain. A similar spelling, a paid search result or a reply from an account using the same avatar is not enough. Determine what the claim transaction actually does and which permissions it requests.

Do not interact merely to remove an unfamiliar asset from view. Wallet interfaces may offer ways to hide spam without visiting the token's website. A displayed reward can be worthless or impossible to sell.

If a claim requests broad spending authority, understand that operation before signing. A permit can have consequences despite requiring no immediate gas payment. The exact token identifier matters more than its name.

Sources

  1. Ethereum: security and scam prevention
  2. MASTR: Crypto Survival Guide, four original panels

Research checked 5 September 2026. Historical cases retain the date and legal status of the cited record.

Related reading

scams

Fake NFT mints

A promoted mint asks for broad permissions or transfers unrelated to the purchase.

MASTR

Support independent research

The investigations, original evidence and guides here are free to read. Voluntary donations help fund the research and keep MASTR’s tools available.

Open wallet