Airdrop scams: spot a fake claim before you sign
Tell a real airdrop claim from a drain in under a minute: what a genuine claim asks for, the four asks that mark airdrop scams, and what to check first.
You can tell a real airdrop claim from a drain in under a minute, and the tell sits in the claim flow, not the branding. Airdrop scams copy a logo, a domain one letter off and a countdown timer well enough; what they cannot copy is the shape of a legitimate claim, which asks the eligible wallet for one signature and a network fee and nothing else. This guide is for traders and holders who get a claim link and have thirty seconds to decide. The worked example is Cherry (cherry.fun), a wallet-to-wallet messenger and community app for crypto where you sign in with a wallet, DM any address, and join token-gated, NFT-gated and paid group chats. Teams run airdrop campaigns inside those rooms, so every step below has a real screen behind it.
Before you start
- Know the project’s real home: its own site, its own room handle, its own channel. Find them once, when you are not in a hurry.
- Know which wallet holds the position that would qualify. A real check reads one wallet; the wrong one fails while a fake page waves it through.
- Turn on your wallet’s transaction preview. Every decision below happens there.
- Accept one rule with no exceptions: no claim and no support agent ever needs your recovery phrase. Phantom’s security tips put it plainly, that its support will never ask for your Secret Recovery Phrase.
What airdrop scams ask for
Four asks separate a drain from a payout. Each moves value out of your wallet, and none appears in a claim that pays you.
| The ask | What it does to you | What a real claim does |
|---|---|---|
| Your seed phrase, to “verify” or “restore” the wallet | Hands over every asset in that wallet and every asset sent to it later. The loss is permanent. | Never asks. Your wallet signs; the phrase stays offline. |
| A spending approval, sometimes labelled “enable” or “activate” | On Solana it sets a delegate on your token account, and a delegate can transfer or burn tokens from it without asking you again. On EVM chains the same signature lets a spender pull that token later. | Grants no standing permission. One transfer, done when it confirms. |
| A fee sent up front to an address the site gives you | Takes the coins at once. The payment confirms and the reward never arrives. | Charges the network fee inside the payout transaction you sign. |
| A bridge, a swap or a deposit before the claim | Routes your funds to a contract the attacker controls. | Moves nothing out. The only transfer is inbound. |
The second row catches experienced people, because the wallet shows a small transaction and no outgoing amount. Solana’s documentation spells out what you handed over: revoking a delegate “clears the token account’s current delegate and resets the delegated amount to zero”. Until you revoke, the delegate keeps that authority.
Step 1: Trace the announcement back to the project
A claim link is only as good as the place you found it. Rank the sources: the project’s own site and its own channel are strong, a post in a room you joined on purpose is medium, a direct message from a stranger is the weakest there is. Attackers work the weak end because it is cheap.
Cherry is built around that ranking. A campaign appears inside the room it belongs to, as a card in the message stream and a pinned banner at the top, so the announcement sits next to the group’s history. A first message from a wallet you do not know lands in your Requests folder with no push notification.
You know it worked when the same announcement, with the same link, sits on the project’s own site or its own channel. If you can only find it in the message that reached you, stop.
Step 2: Open the claim page yourself
Type the domain yourself, or reach it from the project’s site. Phantom’s security tips are specific here: do not connect your wallet to any site you did not seek out yourself, and treat links asking you to connect a wallet to claim tokens as hostile. Lookalike domains are why.
You know it worked when the address bar shows the domain the project publishes, character for character. Our guide on connecting your wallet safely covers what a connection gives away.
Step 3: Read the eligibility rule
Real eligibility is decided by something a stranger can check. In a Cherry campaign that is a token balance, an NFT from a collection, a whitelist, a domain you own, messages you sent in the room, wallet age, or a check run by the team’s own server, under an all-must-pass or any-may-pass policy. The rules are read when you claim, so a wallet that sold since the announcement fails.
The claim screen shows the result before anything is signed. The pinned banner carries a “Check Eligibility” button; the panel that opens lists every rule with a pass or fail mark under the heading “Requirements”, and a campaign that accepts any single rule says “Only one requirement needs to be met”. A wallet that qualifies for nothing sees “Not Eligible”. The card also shows “Total Pool”, “Your Reward” and a count of the slots claimed, because a real drop is capped: the first N claimants or a fixed time window, one claim per wallet.
As of September 2026 there are no points, no XP and no quests screen in any of this: a campaign pays a fixed amount to wallets that pass. A fake claim page has no rule at all. Every wallet qualifies, and the reward often grows with the balance the page reads.
You know it worked when you can say in one sentence why this wallet qualifies and what the payout should be.
Step 4: Read the transaction, then sign
A payout transaction pays you: your wallet is the fee payer, a token or SOL arrives, and no permission is granted to anyone. On Solana a first-time token also needs rent for a new token account, the one extra cost a real claim carries.
In a Cherry campaign the slot is reserved the moment you claim, before the wallet opens, so a rejected signature does not cost you the claim. The wallet then opens with the payout transaction while the screen reads “Please sign the transaction in your wallet…”, you pay the network fee, Cherry co-signs from the treasury and sends it, and the claim shows as paid with a “View transaction” link. Cherry never holds your funds. The team’s side of the same flow is in the guide to running an airdrop .
You know it worked when the preview shows value arriving and a network fee leaving. Any approval, any outgoing transfer, any request you cannot read: reject it and close the tab.
Step 5: Clean up afterwards
Two habits cost a minute a month. Review the approvals and delegates on the wallets you claim with, and revoke the ones you no longer need. Then leave unexpected assets alone: Trezor’s guidance is to assume any asset you were not expecting is a scam, not to interact with it, and never to visit a website that shows up in your wallet as a token name. That covers the free NFT with a URL in its description, the usual shape of NFT airdrop scams.
Troubleshooting
The page says I am not eligible, but I hold the token. Check which wallet you signed in with, then whether the balance was there when you claimed. A rule read at claim time fails a wallet that bought too late or sold too early.
The wallet preview is empty or unreadable. Do not sign. Waiting on a transaction your wallet cannot describe costs nothing worse than a missed drop.
I have no SOL for the fee. On Cherry the claim is kept and the slot stays reserved. The message reads “Top up your wallet with SOL to withdraw, or use manual withdraw later.”, and you sign the payout later from the same room.
A claim card appeared in a group I do not recognise. Anyone can create a Cherry group, so a card inside a room proves only that the campaign is attached to that room. Judge the room first: who runs it, how old it is, whether the project links to it. Checking whether a group is official covers it.
I already signed something. Revoke every approval and delegate on that wallet, then move what is left to a wallet whose keys never touched that browser. If you typed a recovery phrase, that wallet is gone.
Related guides
- Message requests and paid DMs , where a stranger’s first message lands
- Anti-spam on Cherry , the rules behind that
- Token-gated chat , how a holders room checks the chain itself
FAQ
Is it safe to connect your wallet for an airdrop?
It is safe when you opened the claim page yourself from the project’s own site, and unsafe when you followed a link someone sent you. Phantom’s security tips tell users not to connect a wallet to any site they did not seek out themselves. Connecting alone does not move funds; the signature you give afterwards does.
How do I check airdrop eligibility without connecting my wallet?
Read the rule the team published and check it yourself in an explorer: the token balance, the NFT collection, the domain, or the address list. A real campaign states the rule before you connect, and a claim page that promises every wallet a reward has no rule at all.
Do real airdrops ask for a fee?
A real claim costs the network fee for the payout transaction, plus rent for a new token account on Solana if your wallet has never held that token. No legitimate campaign asks you to send coins to an address first and promises the reward afterwards.
Are NFT airdrop scams different from token airdrop scams?
The bait differs and the ending does not. NFT airdrop scams arrive as a free item in your wallet with a website in its name or description, and the trap is the site, not the item. Trezor’s guidance is to assume any asset you were not expecting is a scam and not to interact with it.
Join the projects you hold at chat.cherry.fun , so the next campaign reaches you in a room you picked.
Sources
Try Cherry
Sign in with a wallet, DM any address, and join token-gated and paid communities. No phone number, email, or KYC.