Fake Airdrop-Checker Browser Extensions and Wallet-Draining Add-Ons Checklist for 2026

By CoinDrop Editorial (gspteck) · Published 2026-10-02 · Last verified 2026-10-02

During rumor season, “airdrop checkers,” “eligibility scanners,” and “portfolio alerts” appear as browser add-ons that promise to tell you if you qualify—without visiting a claim site. Some are harmless analytics toys; others inject scripts into wallet UIs, rewrite transaction prompts, or harvest seeds from fake recovery flows. This 2026 checklist explains how malicious airdrop-checker extensions and wallet-draining add-ons work, how they differ from claim-site phishing and Connect Wallet eligibility drains, and what to do before you install anything. Pair it with our claim-site phishing checklist, the Connect Wallet eligibility-verify drain checklist, and the Discord/Telegram DM impersonation checklist. Educational safety only—not financial advice; cite browser extension security guidance and wallet hygiene; no invented extension IDs or recovery guarantees.

Diagram of fake airdrop-checker browser extension path from install bait to wallet drain

Why airdrop-checker extensions are a distinct threat

Classic claim phishing pushes a website. Eligibility-verify drains push a Connect + signature on a page. Malicious extensions sit inside the browser: they can run on every tab, read DOM from dApps and wallet popups, inject overlays, and update silently after a clean first version. Security research has documented campaigns where productivity or Web3 tools later ship wallet-draining payloads—sometimes after an ownership change of a previously trusted listing.

Chrome’s own extension security guidance stresses minimal permissions, HTTPS-only data paths, tight content-script boundaries, and treating messages from content scripts as potentially hostile. For users of crypto wallets, that maps to a simple rule: an “airdrop checker” that asks for broad site access, clipboard read, or “read and change all your data” is not a harmless calculator—it is a privileged resident in the same browser profile as your hot wallet.

How a typical fake checker / draining add-on unfolds

  1. Bait. Discord/Telegram promo, sponsored search, lookalike Chrome Web Store listing, or a “must-have eligibility tool” link next to rumor threads.
  2. Install. Extension requests broad host permissions (<all_urls>, wallet domains, or every HTTPS site) and optional clipboard / storage access far beyond “check my address.”
  3. Persistence. Content scripts inject into claim pages, explorers, or the wallet extension UI; some load remote config so behavior can change without a new store review.
  4. Drain path. Fake “sync wallet / verify seed / enable checker” overlay; rewritten Approve/Permit prompts; or silent approval of malicious spenders while the UI shows a green “eligible” badge.

This sits earlier and deeper than a one-off phishing tab: the add-on can attack every future session until you remove it. Broader literacy: avoiding scams in cryptocurrency airdrop participation and the fake gas token and approval drain checklist.

Four-step flow: bait install, broad permissions, content-script injection, then drain or seed theft

Red flags before you click Add to Chrome

For Solana-specific claim hygiene when tools still appear in your feed, see the Solana airdrop wallet and claim hygiene checklist.

Three cards: dedicated crypto browser profile, refuse seed prompts, audit extension permissions weekly

Safer habits for rumor-season tools

If you already installed a suspicious checker

More foundational material: cryptocurrency airdrop safety considerations and snapshot eligibility and sybil red flags.

Checklist graphic of fake airdrop-checker extension red flags including broad permissions seed prompts and remote config

Safety checklist (YMYL)

Key takeaways

Not financial advice. Browser extensions and claim tools can be impersonated or weaponized after install. Re-verify every publisher, permission set, and spender allowance on official project documentation and reputable explorers before installing add-ons or signing. This article does not provide recovery guarantees. Primary references include Chrome extension security guidance (Stay secure / Web Store best practices) and standard wallet hygiene. Last verified 2026-10-02.