Skip to content
Sat, Jul 25, 2026
BTC $00,000 ETH $0,000 SOL $000
Your keys are yours — we never ask for them Live
RED FLAG

Fake Airdrops and Look-Alike Domains: The Typosquatting Trap

Scammers register domains one letter off from real projects to hijack airdrops. Learn how typosquatting works and how to check a link before you trust it.

TokenSpin will never ask you to connect a wallet or enter a seed phrase — and we never link to the scam itself. This is a safety explainer, not a warning about any one named company.

Airdrops, where a project distributes free tokens, are one of the happiest moments in crypto. Scammers know that, so they build fake airdrop pages on domains that look almost identical to the real ones. This technique, called typosquatting or look-alike domains, turns your excitement into a weapon against you.

What the scam is

A typosquatted domain is a web address deliberately made to resemble a legitimate one. It might swap a letter, add a word, use a different ending, or replace a character with a look-alike. The fake site copies the real project’s branding and hosts a counterfeit airdrop claim, which usually leads to a wallet drainer or a seed-phrase phishing form.

How it works, step by step

1. The near-identical address

Attackers register domains that differ from the real one in tiny ways: an extra letter, a hyphen, a swapped character that looks the same at a glance, or a different domain ending. To a hurried eye, it reads as correct.

2. The distribution push

They spread the link aggressively through replies to real project posts, paid ads that appear above genuine search results, hacked accounts, group chats, and DMs. Seeing it in many places creates a false sense of legitimacy.

3. The convincing clone

The page mirrors the real site closely, right down to fonts and imagery. It announces an airdrop and invites you to connect your wallet or verify eligibility.

4. The payload

Once you engage, the site tries to make you sign a malicious approval, enter your seed phrase, or download a fake wallet update. Any of these can cost you your funds.

The exact red flags

  • An address that is almost right. Extra letters, hyphens, odd endings, or characters that resemble others.
  • Airdrop links arriving in replies, DMs, or ads rather than from the project’s own verified channels.
  • An airdrop for a token you never used or a project you have no history with.
  • Pressure and scarcity, such as a claim window that closes soon.
  • A connect-wallet or verification step that grants approvals or asks for recovery words.

How to avoid it

Never reach an airdrop through a link someone sent you or an ad you clicked. Instead, navigate to the project yourself. Find the official website through the project’s own verified social accounts or a reputable, well-established reference, then bookmark it and use that bookmark every time afterward.

Before trusting any link, inspect the full domain slowly, character by character, reading it from the end backward if that helps you catch a swapped letter. Treat search ads with suspicion, since scammers frequently pay to appear above the real result. When an airdrop sounds too generous or too urgent, assume it is bait until you have confirmed it through the project’s genuine channels. And remember that even a real-looking page is dangerous the moment it asks you to sign an approval or reveal your seed phrase.

It also helps to slow down the whole airdrop ritual. Because these offers arrive wrapped in excitement, people often click first and think second, which is exactly the reaction the scammer designed for. Build a habit of treating every airdrop link as unverified by default, no matter who appears to have shared it, since real accounts get hacked and trusted friends forward things they never checked. If a claim is genuine, it will still be there after you have taken a few minutes to confirm the address through official channels. Nothing about a real distribution depends on you acting in the next thirty seconds, so any pressure to do so is itself a reason to walk away.

What to do if you have interacted with one

  • Stop immediately if you have not yet signed anything, and close the page.
  • If you connected and signed, move your funds to a fresh wallet and revoke approvals using a trusted tool such as revoke.cash.
  • If you entered your seed phrase, treat that wallet as compromised and migrate everything to a brand-new wallet with a new phrase.
  • If you installed anything, remove it and scan your device for malware.
  • Report the fake domain to the real project through its official support, and file a report with your local police and national cybercrime or fraud reporting service. Reputable on-chain security firms often track and warn about active look-alike campaigns.

A promise from us: TokenSpin will never run an airdrop that requires you to connect a wallet to an unfamiliar site or share a seed phrase. Always reach us through your own bookmark, not a forwarded link.

Frequently asked questions

How can I check whether a domain is the real one?

Compare it slowly against a source you already trust, such as an existing bookmark or the project's verified social profile. Read the whole address character by character, watching for extra letters, hyphens, unusual endings, or characters that mimic others. Do not rely on the page looking correct, since clones copy branding easily. When in doubt, do not use the link at all; instead reach the project through its official, previously verified channels.

Are search-engine ads a safe way to find a project's airdrop?

No, they are a known weak spot. Scammers routinely buy ads so their look-alike domain appears above the genuine result, and a rushed click lands you on a fake. Scroll past ads and verify the real address through the project's official social accounts or a well-established reference, then bookmark it. From then on, use your bookmark rather than searching again, which removes the ad risk entirely.

I got an airdrop for a token I never used. Is that a red flag?

It often is. While some legitimate airdrops reward broad on-chain activity, an unexpected drop for a project you have no history with is a common lure to pull you onto a malicious claim page. Do not click the link provided. If you want to check whether a real airdrop exists, go to the project's official channels directly and confirm there, never through the message that surprised you.