# Anatomy of the Biggest Airdrop Scams: How Fake Claim Sites Actually Work > Fake airdrop claim sites drained $494M from users in 2024 alone. We take apart the biggest operations — Inferno Drainer's 16,000-domain network, the $1.25M Polygon NFT airdrop phishing wave, and the Cointelegraph pop-up attack — to show the machine behind the losses. **Published by:** [Onchain Diary](https://paragraph.com/@onchaindiary/) **Published on:** 2026-08-18 **Categories:** security, crypto, onchaindiary **URL:** https://paragraph.com/@onchaindiary/biggest-airdrop-scams-anatomy ## Content Fake airdrops are not a boutique scam. They are the front counter of an industry. When Scam Sniffer published its 2024 annual report, the headline number was $494 million stolen through wallet drainers that year — a 67% increase over 2023 — with more than 300,000 wallet addresses targeted. In 2025, better wallet warnings and growing user awareness cut losses by 83%, to $83.85 million across roughly 106,000 victims. Both years, a large share of that machinery ran on the same fuel: pages that looked like airdrop claim sites. This article takes the machine apart. Not the folklore version ("greedy users got phished") but the operational version: who builds these sites, how they acquire victims, what actually happens at the moment of the fake claim, and what the biggest documented operations looked like. If you understand the supply chain, the defense becomes obvious — and it is never "read the page harder." The supply chain of a fake claim site A modern airdrop scam has four layers, and they are usually different actors: 1. The kit developer. Drainer kits are rented, not built. The developer maintains the phishing page templates, the wallet drainer contracts, signature-bait logic, and infrastructure that adapts to wallet security warnings. According to reporting from The Record on Inferno Drainer, the service took a cut of around 20% of stolen funds — a commission structure that explains why kits keep improving. 2. The operator. The renter picks a narrative (an upcoming token claim, a points program, a testnet reward), deploys the kit on stockpiled domains, and drives traffic. Operators are the customer-facing layer; they absorb the risk and keep most of the proceeds. 3. The traffic supplier. Fake claim sites need eyes. Traffic comes from hijacked X accounts, compromised Discord and Telegram communities, paid search ads on branded keywords, and — in the most damaging cases — compromises of trusted media properties themselves. 4. The cash-out layer. Stolen assets move through fresh wallets and mixers, then to exchanges. This layer is why recovery odds are poor; see our guide on how stolen crypto gets traced and recovered. Users only ever see layer 2: a polished page with a countdown, a "connection strength" meter, and a claim button. Everything behind it is invisible. Case study 1: Inferno Drainer — the franchise model Inferno Drainer became the textbook example of the franchise model. Security researchers documented its rise through 2023: by June 2023 it had extracted roughly $6 million from almost 4,900 victims, and by November 2023, The Record reported the operation had surpassed $80 million by spoofing real blockchain projects — cloning the branding of legitimate protocols and standing up fake claim pages on lookalike domains. In January 2024, Group-IB published analysis tying roughly 16,000 malicious domains to Inferno Drainer's infrastructure. The scale is the point: a fake claim site is not a one-off artifact but a replaceable edge node in a domain arsenal. When one domain gets flagged or taken down, the operation rotates to the next. The operation "retired" in late 2023, but that was a rebrand, not an exit. Check Point Research documented its return in 2025 with upgraded infrastructure — better at evading malicious-transaction warnings that wallets had added. The lesson: kit names come and go; the franchise model persists. Case study 2: the $1.25M Polygon NFT airdrop phishing wave Not every airdrop scam is a website. Scam Sniffer documented a campaign on Polygon where victims received unsolicited NFTs in their wallets — about 1,354 malicious NFTs impersonating legitimate airdrop campaigns. The NFTs' names and metadata contained instructions and URLs: claim your reward here, verify your eligibility there. The psychological trick is inversion. The user did not go looking for an airdrop; the airdrop found them. Receiving an asset feels like evidence of legitimacy ("how would a scammer know my address?"), when in reality bulk-minting NFTs to harvested addresses costs almost nothing. Anyone who followed the link landed on a drainer page. We cover this vector in depth in our guide to unsolicited airdrop tokens — the short version: an airdrop you never signed up for is not a gift, it is bait with your address on it. Related: crypto dusting attacks. Case study 3: when the news site itself is the phish The most efficient traffic source is one victims already trust. On June 23, 2025, CoinDesk reported that Cointelegraph's website had been hit by a front-end exploit that injected fake "CTG token" airdrop pop-ups urging readers to connect wallets. The same weekend, CoinMarketCap was compromised to serve similar pop-ups. These incidents matter because they break the standard advice loop. "Only trust official announcements" assumes the official channel is intact. When a compromised media property or a hijacked project account serves the scam directly, verification has to happen one layer deeper — at the contract and signature level, not the page level. Our guide on how fake airdrops reach you maps every major distribution channel and its failure mode. What actually happens at the "claim" The claim button is where social engineering turns into a transaction. The sequence: Connect. You connect a wallet — this alone leaks nothing but hands the site your address and confirms a live target. The pre-check. Many kits run a live balance scan. Wallets with no approved assets get a "not eligible" message; fat wallets get the full theater. The signature. The claim triggers not a transfer but a signature request — typically a Permit2 approval or a permit signature — that authorizes the drainer contract to move your tokens later. See airdrop signature scams explained. The sweep. Off-site, the attacker's contract transfers every approved asset. You never see a "send" confirmation because no send ever appears in your wallet UI. That fourth step is why victims describe the theft as instant and invisible. The transfer is executed by the drainer contract under an approval you granted. If you want to audit what you have already granted, read token approval safety and how to audit your wallet activity. Why 2025's losses fell — and why complacency is wrong The 83% drop in 2025 drainer losses is real progress: wallets got better at flagging malicious signatures, and more users learned not to blind-sign. But two cautions. First, the kits adapt. The 2025 drainer ecosystem re-tooled around new signature surfaces — most notably EIP-7702 delegations after Ethereum's Pectra upgrade, with the first documented victim losing roughly $147,000 to a single malicious batched transaction in May 2025. We break that vector down in EIP-7702 airdrop phishing. Second, attack volume tracks airdrop seasons. Every major distribution event re-concentrates exactly the population scammers want: users who expect to connect wallets to unfamiliar claim sites. The 2026 drainer ecosystem is smaller per-victim but broader in reach — more sites, cheaper kits, AI-generated variants of the same core trick. The defense, condensed The machine has one load-bearing wall: the signature you give at claim time. Everything else — the page, the brand, the deadline, the pop-up — is set dressing. Treat every claim site as hostile until verified on-chain; start with our 5-step airdrop verification workflow. Never claim with a wallet that holds your main holdings — use a dedicated burner, per how to claim airdrops safely. Read what a signature authorizes before signing anything; blind signing is how most drainer approvals slip through. If tokens or NFTs appear that you never asked for, do not interact: that is the fake token playbook. For a printable version of every check in one place, see the airdrop safety checklist. This article is part of our Airdrop Safety series. Originally published at https://theonchaindiary.com/articles/biggest-airdrop-scams-anatomy/. More Web3 security guides and risk-scoring tools at Onchain Diary. ## Publication Information - [Onchain Diary](https://paragraph.com/@onchaindiary/): Publication homepage - [All Posts](https://paragraph.com/@onchaindiary/): More posts from this publication - [RSS Feed](https://api.paragraph.com/blogs/rss/@onchaindiary): Subscribe to updates