Airdrop Claim-Site Phishing Checklist for Crypto Users in 2026
Fake “claim now” portals remain one of the highest-conversion phishing patterns around crypto airdrops in 2026. This checklist focuses on official-domain verification, wallet-connect traps, seed-phrase never-rules, and approval revocation—so you can evaluate claim opportunities without inventing URLs, APYs, or token amounts. Pair it with our Solana airdrop wallet and claim hygiene checklist for chain-specific signing habits. Primary sources only: project docs you typed or bookmarked, plus reputable explorers you already trust.
Why claim-site phishing works
Airdrop season creates urgency: limited windows, social proof in Discord, and FOMO from screenshots. Attackers copy official branding, register lookalike domains, and push wallet-connect prompts before you finish reading. The goal is usually a signature, an unlimited token approval, or a seed “sync.” None of those require the airdrop to be real.
Treat every unsolicited claim link as hostile until you verify it against the project’s own documentation. For broader participation literacy (not a claim URL list), see cryptocurrency airdrop basics and considerations and how to claim free tokens via airdrops and faucets.
Official domain verification (do this first)
- Start from the project’s official site, verified social account, or docs you already bookmarked—not a forwarded Telegram “claimer.”
- Type the domain yourself or open your bookmark. Hover every link; watch for homoglyphs, extra hyphens, wrong TLDs, and subdomain tricks.
- Confirm the claim path lives on that same official host. A mirrored path on another domain is not “the same page.”
- HTTPS is required but never sufficient. Certificates are cheap; legitimacy is not.
- If the announcement and the claim host disagree, stop. Wait for the project’s own docs to clarify.
We intentionally do not publish third-party claim URLs here. Aggregators and trackers can alert you that something exists; they are not authorization to connect a wallet. When official docs are missing, treat the opportunity as unverified and walk away.
Wallet-connect traps and fake claim portals
Many fake portals look finished: logos, countdowns, eligibility checkers, and a big Connect Wallet button. The trap is the connection itself—especially if the site then asks for broad permissions, blind signatures, or “gas fee” payments to unlock a claim.
- Eligibility checkers that require a wallet with real history before showing any public methodology.
- Connect → sign → drain flows that hide harmful instructions behind friendly UI copy.
- Pay-to-unlock claims on non-official domains.
- Support DMs that paste “your unique claim link” after you ask a question in Discord or Telegram.
- Lookalike extensions or apps named after popular wallets.
Use a dedicated claim / burner wallet with only fee gas—not the wallet that holds your long-term stack. Wallet architecture basics: crypto wallet essentials for blockchain users. For Flare-era distribution context (still verify primary sources), see Flare (FLR) after FlareDrops.
Seed phrase: the never-rule
Legitimate airdrop claims do not need your seed phrase, recovery words, private key, or “wallet sync” remote session. If a page, form, QR flow, or support agent asks for any of those—stop. Close the tab. Assume the site is malicious.
Seeds are for offline recovery of wallets you control. They are never a claim step. Screenshots of seeds, cloud backups of unencrypted keys, and “customer support” seed collection are classic loss paths that work on every chain.
Approvals, signatures, and revoke hygiene
When your wallet prompts you:
- Read the permission or instruction summary. Reject blind “sign everything” prompts.
- Be cautious with unlimited token approvals and unfamiliar contracts or programs.
- Keep only fee gas on the claim wallet; keep treasury offline from unknown dapps.
- After a suspicious signature, assume compromise for that wallet: move funds if keys overlap elsewhere, revoke where tools exist, and rotate.
- Re-check revoke tooling and explorer UIs against current vendor docs—labels change; the habit does not.
Revocation is cleanup, not prevention. Domain verification and burner separation still come first.
Bookmark official sources before claim day
Build friction on purpose before urgency hits:
- Bookmark the project’s official site and docs while you are calm.
- Save the verified social account URL the same way—then still click through to the official domain, not a shortened redirect.
- Disable unused browser extensions for claim sessions when practical.
- Record transaction hashes and token contract / mint addresses in your own notes after a real claim; verify them on a reputable explorer.
- Never reverse the flow: do not connect treasury to “double-check” a suspicious portal.
Safety checklist (YMYL)
- Verify the claim host on official project documentation you typed or bookmarked.
- Never enter a seed phrase, private key, or recovery words into a website or “support” chat.
- Use a burner wallet for unknown claims; keep treasury disconnected.
- Read every signature and approval; revoke unexpected allowances afterward.
- Ignore urgent countdowns, DM claim links, and pay-to-unlock portals on non-official domains.
- Do not trust invented APYs, guaranteed token values, or screenshot “proof” in chats.
Key takeaways
- Claim-site phishing converts on urgency—slow down and verify the official domain first.
- Wallet-connect is a privilege; grant it only from primary sources.
- Seeds are never a claim step; approvals deserve a read and a later revoke pass.
- Bookmark official docs before drop day; explorers verify after, they do not authorize before.
- Affiliates empty; no invented claim URLs, amounts, or products in this guide.
Not financial advice. Airdrops can be worthless, taxable, or malicious. Re-verify every claim URL, contract, and mint on official project documentation and reputable explorers before connecting a wallet or signing. Last verified 2026-09-27.