A claim page asks you to approve one thing. You’re expecting free tokens, so you approve it. Here’s the difference between a real claim and a dangerous permission, and why the nastiest version arrives disguised as safety advice. Part of Know the Scam by SimpleSwap.
Two different things get called “free crypto,” and they work in opposite directions.
A fake airdrop is a claim page dressed up as a reward. It promises tokens for an address, a task, a follow, or simply for existing, then asks you to confirm a transaction to “receive” them.
A drainer dApp is what actually executes the theft. It isn’t a token or a coin: it’s the site or contract sitting behind the claim button, and instead of sending you anything, it requests permission to move assets you already hold, a token approval, an NFT authorization, an off-chain signature.
The airdrop is the bait. The drainer is the mechanism. Put together, the question before signing anything is simple: is this page giving me something, or asking permission to take something I already have?
Why a signature can matter
A wallet drainer doesn’t always need your recovery phrase, password, or private key. Sometimes it does, but the simpler route is to convince you to approve the wrong request in your own wallet. An approval is permission: you let an app or contract move a specific token on your behalf. Legitimate apps use approvals constantly, so seeing one doesn’t prove anything on its own; what matters is the scope. A claim page requesting a large or unlimited allowance on a token you hold is a warning sign; some permissions remain active long after you close the tab, so the theft doesn’t always happen immediately. Other attacks use off-chain signatures that incur no gas fee and leave no visible transfer, yet still carry real financial authority once signed.
The scale is shrinking, though not gone. Scam Sniffer’s 2025 report tracked $83.85 million in wallet-drainer phishing losses across 106,106 victims on EVM chains, down 83% from $494 million in 2024, with victims down 68%. Losses closely tracked market activity, peaking at $31 million in Q3 during Ethereum’s strongest rally of the year. The largest single theft was $6.5 million in September, via a forged Permit signature. Since 2023, Scam Sniffer’s tracked totals in this category have exceeded $800 million.
How the fake claim reaches you
A promoted post or ad for a token claim, airdrop, or reward from a familiar project can link to a lookalike site. Blockaid has documented networks of accounts built to promote malicious dApps disguised as legitimate claims.
A compromised account with real followers and history works just as well as a distribution channel: attackers have pushed scam links through hijacked accounts on X, Instagram, and Discord.
An unfamiliar token or NFT can also appear in your wallet unprompted, sometimes carrying a linked website or “instructions” for claiming or selling it. Receiving the asset doesn’t give anyone control of your wallet; the risk begins only when you follow its instructions to an external page.
When the safety advice becomes the trap
The most convincing version of this scam borrows the language of a real hack. April 2026, by Blockaid’s count, was the worst month for crypto theft on record: more than $629 million drained across upward of twenty incidents, led by two attacks. On April 1, Drift Protocol lost roughly $285 million to a privileged-key compromise at its Security Council. On April 18, KelpDAO lost about $292 million after a compromised LayerZero verifier node allowed a fraudulent cross-chain message to pass through its bridge, draining 116,500 rsETH.
Both attacks were followed almost immediately by an unrelated second wave. Real security guidance tells users to revoke approvals or migrate assets, and drainer operators echo that language back while it’s still fresh: revoke, migrate, claim, compensation. Blockaid found lookalike domains, revokes-drift[.]trade and revoke-kernelsdao[.]com, that live within hours of each hack and are seeded into reply threads under the real security posts rather than running as standalone ads. On the KelpDAO campaign, nine coordinated retweets from repurposed accounts landed within a six-minute window, timed to coincide with peak community anxiety. The same pattern repeated across five incidents that month on different operators’ kits: a technique spread across the whole drainer ecosystem, not the work of one group.
None of the above requires reading a smart contract. Six checks catch nearly all of it.
Ask what the page wants. A legitimate claim may need a transaction or signature alone; that proves nothing. A “free” airdrop that wants broad access to USDT, ETH, NFTs, or anything else in your wallet is one to question.
Get to the page yourself. Don’t follow a claim link from a post, reply, or ad; go to a project’s official site you’ve verified independently. A saved bookmark for services you use often removes one way to land on a lookalike domain.
Don’t mistake gas for an unlock fee. A real claim may cost ordinary network gas. Being asked to send crypto elsewhere as a “deposit” or “verification fee” to unlock your allocation is a serious red flag.
Don’t disable a warning because a site asks you to. A page telling you to enable blind signing, dismiss a wallet alert, or turn off protection before you can “receive” anything wants you to remove protection exactly when you need it.
Use a separate wallet for claims. Keeping experimental dApp activity separate from your main holdings limits the impact of a single bad approval. It’s not full protection, since a live permission can still expose what you send there later, but it caps the damage.
Check your active permissions. Leaving a site or disconnecting your wallet doesn’t cancel an on-chain approval. Revoke.cash or an explorer’s approval checker shows what’s still active; use a verified URL, since fake revocation tools exist too. SimpleSwap’s Safety Academy lists these tools.
Where this meets your swap
A standard SimpleSwap exchange doesn’t expose you to this category of attack, by design: it never asks you to connect a wallet, grant a token approval, or sign a Permit-style permission. You choose a pair, enter the address where you want the asset delivered, and SimpleSwap gives you a deposit address. Then you send an ordinary outgoing transfer from your own wallet, a specific amount, once, not standing permission to spend from it later. A SimpleSwap swap doesn’t add a token allowance to whatever you’re carrying, and it doesn’t clean up approvals granted elsewhere: a permission you gave a DEX, a claim page, or any other dApp stays live until you revoke it, it expires, or it’s invalidated.
To check whether an address is worth trusting, the sender behind an unfamiliar token, say, SimpleSwap’s Customer Account, has a tool for it: Address Check. Enter the address, pick its network, and it screens it through third-party services and returns a risk level. It’s available to registered users, with monthly checks scaling by Loyalty Program tier, from 5 on Bronze to 25 on Platinum. It won’t tell you whether a claim page is a drainer, but it’s a fast way to check the address behind a suspicious token or “reward” first.
The rule to remember
You don’t need to read a smart-contract signature to catch most of these. Before approving anything, ask why a page that’s supposed to hand you free tokens needs permission to spend tokens you already own. If you can’t answer that clearly, don’t approve it.
This article is for educational purposes only and is not financial, legal, or security advice. Scam methods, wallet interfaces, and token permissions change over time. Always verify the website and understand what a wallet request authorizes before signing or sending funds. SimpleSwap’s only official domain is simpleswap.io.