Nobody builds a fake claim site and waits. Distribution is where the effort goes.

The page is a commodity — rented from a drainer kit, deployed on a lookalike domain in minutes. What separates a $50 scam from a $500,000 one is traffic quality: getting the link in front of people who (a) hold assets, (b) expect an airdrop, and (c) are in a hurry. This guide maps the five distribution channels that actually deliver victims, using documented incidents, and shows where each one breaks — both technically and psychologically.

If you have already read how the biggest airdrop scams work, this is the traffic layer of that machine.

Channel 1: Hijacked X accounts

X remains the primary distribution channel for fake airdrops because it concentrates both projects and their followers.

Three variants dominate:

  • Full account takeover. The attacker seizes a project account — through credential reuse, SIM swaps, or a compromised employee — and posts the fake claim to an audience that has spent years being trained to trust it. The larger and more legitimate the account, the more efficient the drain.
  • Reply phishing. Under every real announcement, cloned accounts with near-identical handles reply “portal is open” or “claim window extended” with a link. The reply piggybacks on the legitimate signal. This is a volume game: post under hundreds of announcements, harvest the clicks.
  • Verified impersonators. Verification badges are purchasable, and social engineering works better with a checkmark. Users read the badge as an authenticity signal when it is only a payment signal.

The failure mode to internalize: the account is a messenger, not a destination. Any account can be taken over tonight. When a claim link appears, the question is never “who posted it” but “where does it go and what does the claim contract do” — which you can verify with the on-chain airdrop verification workflow.

Channel 2: Discord and Telegram — the fake announcement bot

Discord is where airdrop anticipation lives, and fake bots imitate the real announcement infrastructure.

The pattern is studied: legitimate projects announce things through bots with distinctive names and avatars. Attackers register bots that copy the naming convention — “OfficialAnnouncements” with a nearly identical avatar — then either DM members directly or post in general channels when moderators are asleep. The most effective variant replies to the real announcement within seconds: “Claim portal now open,” with a link.

Discord’s DM-from-strangers setting should be off by default in any server you use for airdrop hunting. The rule that never breaks: no legitimate project distributes claims via DM. If a claim link arrives by DM, it is hostile — not probably hostile, certainly.

Telegram adds the fake-support variant: after you post a question in a project group, impostors DM you “helpfully” with a wallet-connect “diagnostic” page. That page is a phishing attack dressed as customer service.

Channel 3: Paid search ads on branded keywords

Attackers buy ads. Search any major wallet, bridge, or airdrop claim brand and the top result is frequently a paid placement — sometimes the scammer, sometimes the official site, and it rotates.

Scam Sniffer’s 2024 reporting attributed a meaningful share of drainer victims to paid-ad clicks: users searching for a wallet or claim site, clicking the first result, and connecting on a pixel-perfect clone. The ad platforms pull malicious ads when reported, but the economics favor the attacker — a few dollars of ad spend against a potential five-figure drain, on a domain that can be swapped when flagged.

Defense is a habit, not a skill: never click ads for anything crypto. Type the domain directly or use a bookmark. For airdrop claims specifically, get the URL from the project’s official documentation and cross-check it against their GitHub and announcement channels — two independent sources minimum, as detailed in how to claim airdrops safely.

Channel 4: Fake live streams

The format: a “live” event — often a fake version of a real conference appearance or project AMA — on a video platform, with the airdrop link pinned in the description or overlay. The footage is usually a looped recording of a real executive; the QR code or URL in the corner is the payload.

Streams work because they manufacture urgency and legitimacy at once: something is happening right now, authority figures are on screen, and the comment section (frequently bot-populated) celebrates the claim. They also survive longer than a phishy-looking page because the video platform’s domain is legitimate; only the outbound link is malicious.

If a stream is promoting a claim and the URL is not one you can verify against official documentation, treat the entire event as packaging. The address poisoning lesson applies at the URL level too: attackers bet on you glancing instead of reading.

Channel 5: Compromised media and tooling

The highest-trust channel is the victim’s trusted reading surface itself.

On June 23, 2025, CoinDesk reported that Cointelegraph’s front end had been exploited to inject fake “CTG token” airdrop pop-ups urging readers to connect wallets. The same weekend, CoinMarketCap was compromised to serve similar pop-ups. These were not lookalike sites — they were the actual properties, serving attacker content through a front-end exploit.

This channel breaks the standard advice loop completely. “Only trust official sources” assumes the source is intact. When the delivery layer is compromised, verification must move to the only layers the attacker cannot easily fake:

  • The destination contract. Look it up on a block explorer; check deployer history and holder distribution before connecting. See how to spot wallet drainers.
  • The signature request. Whatever the page says, the wallet prompt shows what you are actually authorizing. Blind signing is how these incidents convert readers into victims.
  • Independent confirmation. A real airdrop exists in multiple independent places — docs, GitHub, explorer history — not only in the pop-up in front of you.

The channel-agnostic rules

Every channel above delivers the same payload: a URL. Strip away the delivery mechanism and the defense collapses into four habits:

  1. Bookmark your claim destinations. Decide the URL from official documentation before the frenzy, not during it.
  2. Treat urgency as evidence of attack. Countdown timers, “last chance” claims, and “portal closes in X minutes” are pressure tools. Real distributions run for days or weeks.
  3. Isolate the blast radius. Use a dedicated wallet for claims so that even a perfect fake only reaches an empty account — the workflow is in how to claim airdrops safely.
  4. Never let the messenger authenticate the destination. Account, DM, ad, stream, or even the news site itself — all of them are channels, none of them are proof.

The full pre-claim verification list lives in the airdrop safety checklist. This article is part of our Airdrop Safety series.

Frequently Asked Questions

How do scammers promote fake airdrops?

Through five main channels: hijacked X accounts (including verified and project accounts), fake announcement bots in Discord and Telegram communities, paid search ads that outrank the official site for branded keywords, pre-recorded video streams posing as live events, and in rare cases compromised media websites — in June 2025 both Cointelegraph and CoinMarketCap were exploited to serve fake airdrop pop-ups directly to readers.

Is an airdrop link safe if it comes from a project's official account?

No. Official accounts get hijacked regularly, and even uncompromised accounts sometimes get impersonated by copies with near-identical handles. An account is a messenger, not a destination. Confirm the claim URL against the project's official documentation and GitHub, and verify the claim contract on a block explorer before connecting a wallet.

Why do fake airdrop ads appear above real results in search engines?

Because attackers buy them. Ad platforms do keyword moderation imperfectly, and bidding on a project's brand name is cheap relative to what one drained wallet returns. Scam Sniffer's 2024 reporting attributed a meaningful share of drainer victims to users who clicked paid ads for wallet and airdrop brands. Train yourself to skip ads entirely when navigating to anything crypto-related.

What do fake Discord airdrop bots look like?

They imitate announcement bots: same avatar style, similar username, posting a fake mint or claim link in general channels or via DM. Some wait for a real announcement and reply to it with a 'portal open' link. Rule: Discord DMs containing claim links are hostile by default, and no legitimate project distributes claims through DM bots.

What was the Cointelegraph fake airdrop incident?

On June 23, 2025, CoinDesk reported that Cointelegraph's website had been hit by a front-end exploit that injected pop-ups promoting a fake CTG token airdrop, prompting readers to connect wallets. CoinMarketCap was compromised the same weekend with similar pop-ups. It proved that even trusted media properties can become the delivery mechanism, which is why verification has to happen at the contract and URL layer, not the publisher layer.