A token appears in your wallet. You did not buy it, claim it, or sign up for anything. The name is exciting — something like “REWARD-CLAIM” or a plausible governance token — and the balance looks meaningful.

Nothing about this is a gift.

Unsolicited airdrops are one of the highest-volume attack surfaces in crypto precisely because receiving an asset feels different from clicking a link. This guide covers the variants (bait tokens, bait NFTs, the import scam, dusting), what interaction actually costs you, and the only correct response. It is part of our Airdrop Safety series; for the drainer mechanics behind the claim pages, read how the biggest airdrop scams work.

Why the trick works: receiving feels like proof

The exploit is psychological inversion. When you go looking for an airdrop, some skepticism is active — you chose to visit the site. When the airdrop comes to you, the situation feels inverted: they found me, which feels like eligibility.

But sending tokens to addresses is nearly free and completely permissionless. An attacker who has your address — harvested from a previous transaction, a leaked database, or generated in bulk — can spam millions of wallets for the cost of gas on a cheap chain. Scam Sniffer documented a single wave of roughly 1,354 malicious NFTs on Polygon impersonating legitimate airdrops that stole about $1.25 million — the send cost almost nothing, the yield was enormous.

Your address is public by design. Anything can be sent to it. Receiving is not consent, and it is not evidence of anything except that your address exists.

The four payloads hiding in a spam airdrop

1. The claim link. The most common form: the token or NFT name, symbol, or metadata contains a URL — “claim your rewards at [domain]” or “visit to activate.” The site behind it is a standard drainer page: connect wallet, “verify eligibility,” sign an approval or permit. The signature mechanics are covered in airdrop signature scams; the short version is you grant spending rights and never see the transfer that empties you.

2. The import-token scam. The token’s description tells you it will not display in your wallet until you “import” it at a linked site. The import page eventually asks for your seed phrase or private key “to sync the token.” There is no legitimate version of this — no token import in any wallet requires your recovery phrase. This variant harvests wallets wholesale rather than draining them transaction by transaction.

3. Dusting and de-anonymization. In its dusting attack form, the tiny unsolicited transfer is not bait for a click — it is a tracer. If you later move that dust (or consolidate accounts), the attacker can cluster your addresses and build a profile of your holdings for targeted phishing. We cover the mechanics in crypto dusting attacks explained.

4. Address poisoning setup. Some unsolicited transfers exist to pollute your transaction history with lookalike addresses, so a future copy-paste of a “recent counterparty” goes to the attacker. The details are in address poisoning attacks explained.

What interaction costs you

Every response to a spam airdrop leaks something, in ascending order of damage:

  • Claiming. Signature-based drain — potentially every asset the connected wallet holds under approval.
  • Importing. Total wallet surrender if a seed phrase is typed anywhere.
  • Sending it back or burning. Confirms a live, human-operated address — raising your value in targeted attack lists — and can seed poisoning patterns.
  • Even browsing the linked site. Confirms a clickable target and exposes you to clipboard-hijacking style tricks; see clipboard hijacking for how copied addresses get swapped mid-paste.

The asymmetry is the point: every action pays the attacker, and inaction pays nobody.

The correct response: nothing

  1. Do not click anything embedded in the token’s name or metadata. The URL is the payload.
  2. Do not import, sync, or “activate” the token. No real token needs this.
  3. Do not sign anything to “claim” it. If you are curious whether an airdrop could be real, verify independently: find the project’s official claim documentation from its own site and GitHub, then run the on-chain verification workflow — contract age, deployer history, holder distribution.
  4. Read the transfer as data, not mail. If you want to know who sent it, look at the sender and token contract on a block explorer — reading is free. Learn the habit in how to read a blockchain explorer.
  5. Hide the asset if you want. Most wallets let you hide spam tokens. Hiding changes nothing on-chain; it just removes the noise.

Special case: the NFT you cannot sell

Bait NFTs often show a floor-price-looking value in aggregator sites — unsellable, because no marketplace liquidity exists. Listing it is usually harmless in itself but marks the address active, and some “listing” flows on fake marketplaces are themselves signature traps. If an NFT arrived uninvited and something urges you to act on it, that urgency is the tell.

One habit that covers all of it

Treat every asset you did not consciously acquire as untrusted input — the same way you treat a DM from a stranger. The fake token glossary entry covers the token-side mechanics, and how to verify a token before buying the diligence side. For the complete pre-claim checklist, see the airdrop safety checklist.

Unwanted airdrops will not stop — sending is permissionless. The defense is a flat, boring policy: it appeared, therefore I ignore it. No exceptions for large balances, official-looking names, or limited-time language. That policy costs you nothing and breaks every variant above.

Frequently Asked Questions

I received a token I never bought or claimed. Is it valuable?

Almost certainly not. Unsolicited tokens in your wallet are typically spam bait with no market value. Their purpose is to get you to visit a claim site or import the token — both attack vectors. Check the token on a block explorer before doing anything: holder count, liquidity, contract age. If you never signed up for the airdrop, treat it as hostile data, not an asset.

Can claiming an unknown airdrop drain my wallet?

Yes. The claim flow on the linked site typically asks you to connect a wallet and sign an approval or permit signature — which grants the attacker's contract spending rights over your tokens. You never send a transaction; the drainer moves your assets under the approval you granted. This is the dominant pattern in wallet drainer losses.

What is the 'import token' scam?

The spam token's name or description instructs you to visit a site and 'import' the token to see it in your wallet — but the page asks for your seed phrase or private key to complete the import. No legitimate token import ever requires your recovery phrase. Importing means surrendering the wallet.

Why do scammers airdrop tokens for free? What do they gain?

Three things: clicks (the token metadata contains the phishing URL), activity data (any interaction confirms your address is live and operated by a human, making it more valuable for targeted attacks), and in dusting variants, de-anonymization — tracing which other addresses belong to you. The send costs fractions of a cent; one drained wallet pays for millions of sends.

Should I burn or send back unsolicited airdrop tokens?

No. Sending anything back — or anywhere — reveals the address is actively used and sometimes triggers address poisoning patterns where scammers seed your transfer history with lookalike addresses. The cheapest response is no response. Hide the token in your wallet's asset list if it bothers you; the on-chain record exists whether you look at it or not.