Every testnet season follows the same script. A project announces an incentivized testnet, Twitter fills with farming guides, and thousands of users start connecting wallets to unfamiliar dashboards daily — checking tasks, claiming points, bridging fake tokens. Within a week, the drainer sites appear: lookalike domains, fake point checkers, “early claim” pages.

The farming itself is not the problem. Testnet tokens are worthless by design, and a genuine testnet transaction can’t touch your mainnet assets. The problem is that testnet seasons create the perfect hunting ground: a concentrated population of users who are trained to connect wallets to new sites and sign things repeatedly. This guide covers what actually goes wrong and the workflow that makes it stop mattering.

What testnet scammers actually do

Three attack patterns account for nearly everything:

Seed phrase harvesting. The site presents itself as a faucet or eligibility checker and asks you to “import” or “verify” your wallet by entering the recovery phrase. Sometimes dressed up as a sync step or KYC. No legitimate service — faucet, testnet, airdrop checker, or otherwise — ever needs your seed phrase. There is no version of this that is real.

Network bait-and-switch. You connect on what looks like a testnet dashboard, click claim, and the wallet prompt is actually a mainnet transaction — an unlimited approval or permit signature to a drainer contract. The tell is in the signing prompt itself: the network field, the contract address, and what’s being approved. People click through because they’ve signed twenty harmless testnet transactions that week and their guard is down. Muscle memory is the vulnerability.

Fake task lists and point checkers. These harvest wallet connections and build a targeting list, then DM users personalized phishing links (“you have unclaimed points, verify here”). The checker itself may even work; the follow-up DM is the weapon.

The safe testnet workflow

Four habits, in order of leverage:

1. Dedicated burner wallet. Create a fresh wallet used only for testnets and airdrop farming. It holds nothing on mainnet — or only the gas needed when a legitimate claim later requires a mainnet transaction. When a “testnet” site turns out to be a mainnet drainer, the attacker gets an empty wallet. Generate it from a separate seed phrase stored the same way as your main one.

2. The seed phrase firewall. Your recovery phrase gets typed exactly two places: when you create the wallet, and when you restore it in a wallet app you chose. Any other prompt asking for it — faucet, checker, support agent, “sync” — is a scam by definition. This rule has no exceptions in eleven years of crypto.

3. Read the signing prompt, every time. Before approving, check three fields: the network (does it say the testnet you expect?), the contract (does the address match the one in the project’s official docs?), and the permission (is it a plain transfer, or an approval — and if an approval, what amount?). Unlimited approvals are the signature of drainers. Reject anything that doesn’t check out, and treat “verification messages” that don’t clearly state what they authorize as hostile.

4. Verify domains from official sources only. The project’s X account, GitHub, or docs — never a DM link, never a sponsored search result. Lookalike domains (extra letters, hyphens, wrong TLD) are the default drainer delivery mechanism. Bookmark the real dashboards after verifying once, then only use the bookmarks.

On-chain checks before any claim

When a testnet season graduates to a real token claim, the game changes — now there are mainnet contracts involved. Before connecting anywhere:

Trace the claim contract. The official announcement links a contract address; open it on the chain’s block explorer and check its age (deployed last week is a warning), verification status, and whether it holds the permissions drainers need. Check the deployer: a contract deployed by an account created two days before the announcement is not a project contract.

For token contracts, holder distribution tells most of the story — a legitimate distribution has many small holders; a scam concentrates supply in a few fresh wallets. Automated risk scanners (Token Sniffer, GoPlus) compress these checks into a score if you don’t want to do them manually.

Our wallet drainer identification guide covers the approval patterns to recognize before signing, and Permit2 exploits explained breaks down the single-signature approval abuse that powers most modern drainer kits.

If something went wrong

Signed something suspicious on your burner wallet: let it go, rotate to a fresh burner, and revoke approvals on the old one for hygiene. Signed something on your main wallet: immediately revoke all token approvals via a revocation tool, move high-value assets to a fresh wallet, and check your transaction history for transfers you didn’t make. The post-incident guide covers tracing next steps on-chain.

Testnet seasons will keep coming, and the scam infrastructure around them industrializes a little more each cycle. The farmers who last are not the most suspicious — they’re the ones whose setup makes suspicion mostly unnecessary. An empty dedicated wallet turns almost every attack in this category into a non-event.

Frequently Asked Questions

Are testnet airdrops safe?

The testnet activity itself is safe — testnet tokens have no value and testnet transactions cannot touch mainnet assets. The risk comes from fake sites around the testnet narrative: fraudulent faucets, fake eligibility checkers, and claim pages that are actually mainnet drainer contracts. Using a dedicated wallet with no mainnet funds eliminates almost all of this risk.

Can a testnet transaction drain my mainnet wallet?

Not directly — testnets and mainnet are separate networks. But a malicious site can ask you to connect your mainnet wallet and present a mainnet transaction disguised as a testnet action. Always check which network the signing prompt references before approving, and keep testnet activity on a separate wallet.

Why do scammers target testnet farmers?

Testnet seasons concentrate exactly the people most likely to connect wallets to unfamiliar sites repeatedly. Scammers follow the attention: fake faucets, fake task lists, fake eligibility sites. The demographic is also newer to crypto on average, making social engineering more effective.

Should I use my main wallet for testnet activity?

No. Use a dedicated burner wallet funded with nothing (or only the gas needed for rare mainnet claims). If a testnet site turns out to be a mainnet drainer, the most it can take is what's in that wallet. This is the single highest-leverage habit for airdrop farming.

What makes a testnet faucet fake?

A legitimate faucet asks only for your testnet address and maybe a captcha. A fake faucet asks for a seed phrase, a signature, or a mainnet transaction 'to verify you're human.' No real faucet ever needs custody of your keys. If a faucet demands anything beyond a pasted address, leave.