EntryCrypto

Airdrop scams, wallet drainers and pig-butchering: how they work and how to avoid them

8 min read · Updated

The playbook behind fake airdrops, drainer kits, romance and 'investment' scams, fake job offers and address poisoning, with the specific defence for each.

Scams, not hacks, are the biggest source of losses for individuals. The techniques evolve, but the structure repeats: create urgency or greed, move you to a channel the scammer controls, and get one signature or one transfer. Here is the current playbook and the counter to each move.

Fake airdrops and drainer sites

How it works. A post, DM or unsolicited token points you to a claim site for a hyped project. The site asks you to connect and sign. The signature is a setApprovalForAll, a Permit for your stablecoins, or a direct transfer. Drainer kits are sold as a service and split proceeds with the affiliate who lured you.

Defence.

  • Real airdrops are announced on the project’s verified channels, and you check eligibility from a bookmarked official site, never a link in a DM.
  • Use a burner wallet for any claim. It holds nothing, so it can lose nothing.
  • Read every signature prompt. Anything mentioning approve, permit, spender or setApprovalForAll when you only expected to connect is a drain attempt. See the approvals guide.

Fake support and account recovery

How it works. You post a complaint about an exchange or wallet. A “support” account replies or DMs within minutes and asks you to “validate” your wallet on a form, share your screen, or install remote-access software.

Defence. No exchange or wallet company initiates DMs. Use only the in-app support chat. Never share a screen while your wallet or exchange is open.

Pig butchering and fake trading platforms

How it works. Weeks of relationship building, then an introduction to a platform (often a polished app) with fake charts and a “mentor”. Early small withdrawals succeed. Then you are asked to deposit more to unlock profits, pay “tax” or “verification fees”. The platform vanishes.

Defence.

  • Anyone you met online who steers conversation toward crypto investing is running this scam. There are no exceptions.
  • Real exchanges are on our ranking. If the “platform” is not on CoinGecko and has no regulatory footprint, it is fake.
  • Guaranteed returns do not exist.

Fake job offers and malicious “test tasks”

How it works. Recruiters offer a well-paid Web3 role and ask you to run a coding test from a GitHub repo, install a “video call app” or open a PDF. The payload steals wallet extensions and seed files. This is how the Ronin Bridge was breached and how Lazarus Group targets developers today.

Defence. Run untrusted code only in a disposable VM. Keep no wallets on your work machine. Verify recruiters through the company’s official careers page.

Address poisoning and clipboard hijacking

How it works. Scammers send you 0-value transfers from an address whose first and last characters match an address you use, so it appears in your history. Malware can also swap addresses in your clipboard.

Defence. Copy addresses only from the destination service or your saved contacts, verify the first and last six characters after pasting, and use your exchange’s whitelist so poisoned addresses cannot receive funds.

SIM swap

How it works. The attacker convinces your mobile carrier to port your number, receives your SMS codes and resets your email and exchange passwords.

Defence. Remove SMS 2FA everywhere, set a carrier port-out PIN, and use an authenticator app or hardware key. See exchange account security.

Universal rules

  1. Nobody legitimate asks for your seed phrase, ever.
  2. Nobody legitimate DMs you first.
  3. Nobody legitimate needs you to send funds to receive funds.
  4. Urgency is the scammer’s tool. Slow down.
  5. Use a burner wallet for anything new; keep the vault offline.

Work through the security checklist to close every gap on this page in one sitting.

Questions

I received tokens I never bought. Is my wallet hacked?

Almost certainly not. Anyone can send tokens to any address. Unsolicited tokens are bait: the scam happens when you try to sell or 'claim' them on the site named in the token, which triggers a drainer. Ignore them; hide them in your wallet UI.

What is pig butchering?

A long-con investment scam. A stranger builds a relationship over weeks (dating app, wrong-number text, LinkedIn), then introduces a 'trading platform' showing fake profits. Small withdrawals work to build trust, then a large deposit is demanded and the platform disappears. Losses average tens of thousands of dollars per victim.

Can stolen crypto be recovered?

Rarely. Exchanges can freeze funds if the thief deposits to a KYC account and you report quickly with transaction hashes. 'Recovery services' that ask for an upfront fee are a second scam targeting the same victims.

More guides