Fake Airdrop-Checker Browser Extensions and Wallet-Draining Add-Ons Checklist for 2026
During rumor season, “airdrop checkers,” “eligibility scanners,” and “portfolio alerts” appear as browser add-ons that promise to tell you if you qualify—without visiting a claim site. Some are harmless analytics toys; others inject scripts into wallet UIs, rewrite transaction prompts, or harvest seeds from fake recovery flows. This 2026 checklist explains how malicious airdrop-checker extensions and wallet-draining add-ons work, how they differ from claim-site phishing and Connect Wallet eligibility drains, and what to do before you install anything. Pair it with our claim-site phishing checklist, the Connect Wallet eligibility-verify drain checklist, and the Discord/Telegram DM impersonation checklist. Educational safety only—not financial advice; cite browser extension security guidance and wallet hygiene; no invented extension IDs or recovery guarantees.
Why airdrop-checker extensions are a distinct threat
Classic claim phishing pushes a website. Eligibility-verify drains push a Connect + signature on a page. Malicious extensions sit inside the browser: they can run on every tab, read DOM from dApps and wallet popups, inject overlays, and update silently after a clean first version. Security research has documented campaigns where productivity or Web3 tools later ship wallet-draining payloads—sometimes after an ownership change of a previously trusted listing.
Chrome’s own extension security guidance stresses minimal permissions, HTTPS-only data paths, tight content-script boundaries, and treating messages from content scripts as potentially hostile. For users of crypto wallets, that maps to a simple rule: an “airdrop checker” that asks for broad site access, clipboard read, or “read and change all your data” is not a harmless calculator—it is a privileged resident in the same browser profile as your hot wallet.
How a typical fake checker / draining add-on unfolds
- Bait. Discord/Telegram promo, sponsored search, lookalike Chrome Web Store listing, or a “must-have eligibility tool” link next to rumor threads.
- Install. Extension requests broad host permissions (
<all_urls>, wallet domains, or every HTTPS site) and optional clipboard / storage access far beyond “check my address.” - Persistence. Content scripts inject into claim pages, explorers, or the wallet extension UI; some load remote config so behavior can change without a new store review.
- Drain path. Fake “sync wallet / verify seed / enable checker” overlay; rewritten Approve/Permit prompts; or silent approval of malicious spenders while the UI shows a green “eligible” badge.
This sits earlier and deeper than a one-off phishing tab: the add-on can attack every future session until you remove it. Broader literacy: avoiding scams in cryptocurrency airdrop participation and the fake gas token and approval drain checklist.
Red flags before you click Add to Chrome
- Permissions mismatch. A local address checker should not need access to all sites, webNavigation, or clipboard of every page.
- Unverified or brand-new publisher with lookalike names, stock screenshots, or copy-pasted descriptions of a real project tool.
- Asks for seed, private key, or “wallet sync” inside the extension popup—instant reject. Real checkers never need recovery words.
- Install link only in DMs / ads, not from bookmarked official docs or the project’s verified site.
- Sudden ownership or permission change on an extension you already trust—Chrome updates can ship hostile code silently; re-audit after updates.
- Remote “config” behavior that changes claim URLs or inject targets without a clear changelog.
For Solana-specific claim hygiene when tools still appear in your feed, see the Solana airdrop wallet and claim hygiene checklist.
Safer habits for rumor-season tools
- Separate browser profile (or device) for wallet use—zero airdrop “helpers,” clipboards tools, or random productivity add-ons on that profile.
- Prefer official web checkers you open from bookmarked docs (address paste / read-only) over any extension that injects into pages.
- Read the permission dialog like a wallet prompt: reject
<all_urls>and clipboard unless you can explain why a checker needs them. - Never type a seed into an extension—hardware wallets and official wallet apps only; treat extension “recovery” UIs as phishing.
- Minimize and review monthly: remove unused extensions; after any store update, re-check permissions and publisher identity.
- Assume content scripts are hostile to your wallet UI—Chrome’s stay-secure guidance is written for developers, but users benefit from the same threat model.
If you already installed a suspicious checker
- Remove the extension immediately from browser settings—then restart the browser.
- Disconnect sites in the wallet UI; disconnect ≠ revoke on-chain approvals.
- Review and revoke unfamiliar spenders on explorer/revoke tools you already bookmark (not links from the add-on’s site).
- Move remaining funds to a fresh address/hardware wallet if you entered a seed or signed opaque Approves while the extension was installed.
- Ignore “recovery” extensions and DMs that appear after you post about the loss—second-wave drains are common.
More foundational material: cryptocurrency airdrop safety considerations and snapshot eligibility and sybil red flags.
Safety checklist (YMYL)
- Airdrop-checker extensions with broad host permissions are high risk until proven otherwise from official project docs.
- Never share seed phrases or private keys with any browser add-on or popup.
- Keep wallet browsing on a profile with no optional Web3 “helpers.”
- Treat store updates and publisher changes as re-install decisions—re-audit permissions.
- After a bad install, remove extension, revoke allowances, quarantine the burner—ignore recovery add-ons.
- No invented extension IDs or guaranteed recoveries in this guide—re-check official docs and Chrome Web Store publisher details yourself.
Key takeaways
- Fake checkers attack from inside the browser—deeper than a single phishing tab.
- Permission mismatch and seed prompts are the main tells—not the green “eligible” badge.
- Dedicated crypto profiles beat installing rumor-season add-ons next to your wallet.
- Remove, revoke, and migrate after mistakes; do not trust second-wave recovery extensions.
- Affiliates empty; educational only—pair with claim phishing, eligibility-verify, DM, gas-token, and Solana hygiene guides on CoinDrop.
Not financial advice. Browser extensions and claim tools can be impersonated or weaponized after install. Re-verify every publisher, permission set, and spender allowance on official project documentation and reputable explorers before installing add-ons or signing. This article does not provide recovery guarantees. Primary references include Chrome extension security guidance (Stay secure / Web Store best practices) and standard wallet hygiene. Last verified 2026-10-02.