Official Wallsec emails only ever come from an @wallsec.co.uk address.
← All daily briefings

Identifying Malicious Token Airdrops and Deceptive Onchain Claim Interfaces

Fraudsters frequently deposit unsolicited tokens directly into private wallets to entice recipients into visiting credential-harvesting claim portals. Understanding how to handle these unwanted assets safely prevents unauthorised wallet drainage.

  • Treat any unexpected token deposit as suspicious and avoid interacting with attached URLs or smart contract functions embedded within the asset metadata.
  • Never attempt to swap or transfer unsolicited tokens on decentralised protocols, as execution routines may trigger concealed asset-drainage scripts or incur prohibitive network fees.
  • Hide or ignore unrecognised digital assets directly within your wallet interface without signing any associated cryptographic prompts or granting permissions to unknown web applications.
  • Report campaigns involving illicit token distributions to Action Fraud and notify your wallet provider so that known predatory contract addresses can be marked as malicious.

Written by the Wallsec investigations team. General information only, not legal or financial advice.

Need a case reviewed?

Tell us what happened and we will say honestly whether the onchain data supports a trace.

Request a case review