Fake airdrops are not a boutique scam. They are the front counter of an industry.

When Scam Sniffer published its 2024 annual report, the headline number was $494 million stolen through wallet drainers that year — a 67% increase over 2023 — with more than 300,000 wallet addresses targeted. In 2025, better wallet warnings and growing user awareness cut losses by 83%, to $83.85 million across roughly 106,000 victims. Both years, a large share of that machinery ran on the same fuel: pages that looked like airdrop claim sites.

This article takes the machine apart. Not the folklore version (“greedy users got phished”) but the operational version: who builds these sites, how they acquire victims, what actually happens at the moment of the fake claim, and what the biggest documented operations looked like. If you understand the supply chain, the defense becomes obvious — and it is never “read the page harder.”

The supply chain of a fake claim site

A modern airdrop scam has four layers, and they are usually different actors:

1. The kit developer. Drainer kits are rented, not built. The developer maintains the phishing page templates, the wallet drainer contracts, signature-bait logic, and infrastructure that adapts to wallet security warnings. According to reporting from The Record on Inferno Drainer, the service took a cut of around 20% of stolen funds — a commission structure that explains why kits keep improving.

2. The operator. The renter picks a narrative (an upcoming token claim, a points program, a testnet reward), deploys the kit on stockpiled domains, and drives traffic. Operators are the customer-facing layer; they absorb the risk and keep most of the proceeds.

3. The traffic supplier. Fake claim sites need eyes. Traffic comes from hijacked X accounts, compromised Discord and Telegram communities, paid search ads on branded keywords, and — in the most damaging cases — compromises of trusted media properties themselves.

4. The cash-out layer. Stolen assets move through fresh wallets and mixers, then to exchanges. This layer is why recovery odds are poor; see our guide on how stolen crypto gets traced and recovered.

Users only ever see layer 2: a polished page with a countdown, a “connection strength” meter, and a claim button. Everything behind it is invisible.

Case study 1: Inferno Drainer — the franchise model

Inferno Drainer became the textbook example of the franchise model. Security researchers documented its rise through 2023: by June 2023 it had extracted roughly $6 million from almost 4,900 victims, and by November 2023, The Record reported the operation had surpassed $80 million by spoofing real blockchain projects — cloning the branding of legitimate protocols and standing up fake claim pages on lookalike domains.

In January 2024, Group-IB published analysis tying roughly 16,000 malicious domains to Inferno Drainer’s infrastructure. The scale is the point: a fake claim site is not a one-off artifact but a replaceable edge node in a domain arsenal. When one domain gets flagged or taken down, the operation rotates to the next.

The operation “retired” in late 2023, but that was a rebrand, not an exit. Check Point Research documented its return in 2025 with upgraded infrastructure — better at evading malicious-transaction warnings that wallets had added. The lesson: kit names come and go; the franchise model persists.

Case study 2: the $1.25M Polygon NFT airdrop phishing wave

Not every airdrop scam is a website. Scam Sniffer documented a campaign on Polygon where victims received unsolicited NFTs in their wallets — about 1,354 malicious NFTs impersonating legitimate airdrop campaigns. The NFTs’ names and metadata contained instructions and URLs: claim your reward here, verify your eligibility there.

The psychological trick is inversion. The user did not go looking for an airdrop; the airdrop found them. Receiving an asset feels like evidence of legitimacy (“how would a scammer know my address?”), when in reality bulk-minting NFTs to harvested addresses costs almost nothing. Anyone who followed the link landed on a drainer page.

We cover this vector in depth in our guide to unsolicited airdrop tokens — the short version: an airdrop you never signed up for is not a gift, it is bait with your address on it. Related: crypto dusting attacks.

Case study 3: when the news site itself is the phish

The most efficient traffic source is one victims already trust. On June 23, 2025, CoinDesk reported that Cointelegraph’s website had been hit by a front-end exploit that injected fake “CTG token” airdrop pop-ups urging readers to connect wallets. The same weekend, CoinMarketCap was compromised to serve similar pop-ups.

These incidents matter because they break the standard advice loop. “Only trust official announcements” assumes the official channel is intact. When a compromised media property or a hijacked project account serves the scam directly, verification has to happen one layer deeper — at the contract and signature level, not the page level. Our guide on how fake airdrops reach you maps every major distribution channel and its failure mode.

What actually happens at the “claim”

The claim button is where social engineering turns into a transaction. The sequence:

  1. Connect. You connect a wallet — this alone leaks nothing but hands the site your address and confirms a live target.
  2. The pre-check. Many kits run a live balance scan. Wallets with no approved assets get a “not eligible” message; fat wallets get the full theater.
  3. The signature. The claim triggers not a transfer but a signature request — typically a Permit2 approval or a permit signature — that authorizes the drainer contract to move your tokens later. See airdrop signature scams explained.
  4. The sweep. Off-site, the attacker’s contract transfers every approved asset. You never see a “send” confirmation because no send ever appears in your wallet UI.

That fourth step is why victims describe the theft as instant and invisible. The transfer is executed by the drainer contract under an approval you granted. If you want to audit what you have already granted, read token approval safety and how to audit your wallet activity.

Why 2025’s losses fell — and why complacency is wrong

The 83% drop in 2025 drainer losses is real progress: wallets got better at flagging malicious signatures, and more users learned not to blind-sign. But two cautions.

First, the kits adapt. The 2025 drainer ecosystem re-tooled around new signature surfaces — most notably EIP-7702 delegations after Ethereum’s Pectra upgrade, with the first documented victim losing roughly $147,000 to a single malicious batched transaction in May 2025. We break that vector down in EIP-7702 airdrop phishing.

Second, attack volume tracks airdrop seasons. Every major distribution event re-concentrates exactly the population scammers want: users who expect to connect wallets to unfamiliar claim sites. The 2026 drainer ecosystem is smaller per-victim but broader in reach — more sites, cheaper kits, AI-generated variants of the same core trick.

The defense, condensed

The machine has one load-bearing wall: the signature you give at claim time. Everything else — the page, the brand, the deadline, the pop-up — is set dressing.

  • Treat every claim site as hostile until verified on-chain; start with our 5-step airdrop verification workflow.
  • Never claim with a wallet that holds your main holdings — use a dedicated burner, per how to claim airdrops safely.
  • Read what a signature authorizes before signing anything; blind signing is how most drainer approvals slip through.
  • If tokens or NFTs appear that you never asked for, do not interact: that is the fake token playbook.

For a printable version of every check in one place, see the airdrop safety checklist. This article is part of our Airdrop Safety series.

Frequently Asked Questions

How much money have fake airdrops stolen?

Exact figures for airdrop-specific losses do not exist, but wallet drainers — which run overwhelmingly on fake airdrop, mint, and claim sites — stole approximately $494 million in 2024 according to Scam Sniffer's annual report, targeting more than 300,000 wallet addresses. In 2025 losses fell 83% to $83.85 million across roughly 106,000 victims. Individual operations were large: Inferno Drainer alone was linked to over $80 million in losses by late 2023, according to reporting from The Record.

What is a wallet drainer?

A wallet drainer is phishing-as-a-service malware. The operator rents a ready-made kit — fake claim pages, signature logic, and automated asset-sweeping contracts — and splits stolen funds with the kit developer, reportedly around 20% in Inferno Drainer's case. Victims interact with what looks like a normal airdrop claim site; the signature they approve hands control of token approvals to the attacker's contract, which then sweeps approved assets.

Do fake airdrop sites steal your seed phrase?

The higher-volume attacks do not need your seed phrase. Modern drainers rely on signatures — token approvals, permit signatures, or malicious delegated transactions — that you sign with a wallet you willingly connected. Seed phrase harvesting sites do exist, but the industrial-scale losses come from signature phishing because a connected wallet feels safer to victims than typing a recovery phrase.

Which airdrop scams were the biggest?

Public reporting points to drainer operations rather than any single fake token: Inferno Drainer (over $80 million by late 2023, using a network of roughly 16,000 malicious domains per Group-IB), NFT airdrop phishing on Polygon that stole $1.25 million through about 1,354 malicious NFTs, and compromises of trusted media like the June 2025 Cointelegraph and CoinMarketCap pop-up incidents that pushed fake CTG token claims to readers.

Are airdrop scams still a problem after 2025's drop in losses?

Yes. The 83% drop in 2025 losses reflects better wallet warnings and user awareness, not the industry disappearing. Check Point documented Inferno Drainer returning with improved infrastructure in 2025, and drainer kits continue to adopt new signature types such as EIP-7702 delegations. Attack volume follows airdrop seasons — every major token distribution revives the fake-claim ecosystem.