How Does a Fake Token Airdrop Drain Your Wallet When You Try to Sell It?
A fake token airdrop drains your wallet through a combination of social engineering and a malicious smart contract. The attacker sends you a worthless token that looks legitimate. When you attempt to sell or swap it, you unknowingly sign a transaction that gives the attacker permission to move all the valuable tokens in your wallet. The core prevention is simple: never interact with tokens you did not request or expect, and always verify the contract address of any token before approving a transaction.
The setup: how the fake token arrives
The attacker creates a new ERC-20 or BEP-20 token with a name, ticker, and logo that mimics a well-known project. They might call it "USDC" or "UNI" and use a logo that looks identical to the real one. The contract address, however, is completely different from the legitimate token's address.
The attacker then airdrops a small amount of this fake token to thousands of wallet addresses. These addresses are often gathered from public blockchain data, such as recent transactions on popular DEXes or NFT marketplaces. The airdrop itself costs the attacker almost nothing: deploying a token contract on Ethereum or BSC can be done for a few dollars, and the transfer fees to send the tokens are minimal.
The Trap: Why You See a "Valuable" Balance
When you open your wallet, you see a new token with a familiar name and a balance that appears to have significant value. The attacker can make this value appear arbitrarily high by manipulating the token's price on a decentralized exchange. They might create a small liquidity pool for the fake token paired with a real token like ETH or BNB, set the initial price to something like $10 per fake token, and then buy a tiny amount to create a visible price. Because liquidity is extremely shallow, the displayed "value" of your airdropped balance can be thousands of dollars.
This is an illusion. There is no real buyer at that price. If you try to sell a meaningful amount, the price would collapse to near zero because the liquidity pool is tiny. The attacker's goal is not for you to sell the token for profit. It is for you to try.
The execution: what happens when you try to sell
When you attempt to swap the fake token for a real token on a decentralized exchange, your wallet will prompt you to approve a transaction. This is a standard step for swapping any ERC-20 token: you must give the DEX's router contract permission to spend your tokens. However, the fake token's contract is controlled by the attacker and can be written to do something different.
Here is the sequence of events in a typical drain:
- You connect your wallet to a DEX interface (or sometimes a fake front-end that looks like a real DEX).
- You select the fake token and the real token you want to receive, and click "Swap."
- Your wallet shows a transaction request. You review it briefly. It asks you to approve the DEX router to spend your fake tokens.
- You sign the approval transaction. This transaction is not the problem itself - it only grants permission to move the fake tokens.
- The wallet then prompts you for a second transaction: the actual swap. This is where the attack happens.
- The swap transaction you sign is not a simple token transfer. It is a call to a function on the fake token's contract that the attacker has written to do something else entirely. The function might be named "swap" or "sell" to look normal, but its actual code does the following:
- Calls the
approveorincreaseAllowancefunction on your real tokens (like USDC or ETH) to grant the attacker unlimited spending permission. - Transfers your real tokens to the attacker's wallet.
- Optionally, completes a small swap of the fake token to make the transaction look legitimate.
Because you signed the transaction, your wallet executed it. The attacker now has permission to move your real tokens, and they do so immediately.
Why blind signing enables this
Hardware wallets and software wallets that do not decode the transaction data for you are especially vulnerable. When you sign a transaction on a hardware wallet, the device often shows you only the gas fee and the contract address - not the full function call. If the contract address is the fake token's contract, you might not realize that the function you are calling is malicious. This is called blind signing. The transaction you approve could be anything the contract author designed.
Some wallets and hardware devices now offer "clear signing" or transaction preview features that decode the function call and show you what the contract will do. If you use a wallet that supports this, and the transaction attempts to drain your real tokens, the preview will show you a red flag. If your wallet does not support this, you are signing blind.
What actually prevents this attack
- Never interact with airdropped tokens. If you did not request the token or earn it through a known process, ignore it. Do not attempt to swap, sell, or even transfer it. Many wallets now allow you to hide tokens so you do not see them.
- Verify the contract address. Before interacting with any token, check its contract address against the official source. For example, the real USDC on Ethereum is at
0xA0b86991c6218b36c1d19D4a2e9Eb0cE3606eB48. If the airdropped token's address is different, it is a fake. - Use a wallet that supports clear signing. Wallets that decode transaction data and show you what a contract will do before you sign can prevent you from unknowingly approving a drain. This is one of the strongest technical protections available.
- Maintain a separate "hot" wallet for experimentation. Keep the majority of your funds in a wallet that you never use to interact with unknown tokens or DEXes. Use a separate wallet with minimal funds for trying new things.
- Revoke allowances regularly. If you have previously approved a malicious token contract, that approval persists. Use a token approval checker to review and revoke any allowances you do not recognize. This is covered in detail in the site's article on revoking smart contract allowances.
What does not prevent this
- Having a hardware wallet alone. A hardware wallet signs whatever transaction you approve. If you approve a malicious transaction, the hardware wallet will execute it. The security of a hardware wallet lies in protecting your private key, not in vetting the transactions you choose to sign.
- Checking the token's name or logo. Attackers can copy these exactly. The name and logo are not verified by the blockchain.
- Using a DEX aggregator. Aggregators like 1inch or ParaSwap route trades through multiple liquidity sources, but they still require you to approve tokens. If you approve a fake token's malicious contract, the aggregator cannot protect you.
Not financial advice. 4547onsol.xyz publishes market data and general information about digital assets. Crypto assets are volatile and you can lose everything you put in. Nothing here is a recommendation to buy, sell or hold, and we make no price predictions.
Prices are sourced from third parties and may be delayed or wrong. Verify anything you intend to act on against a primary source.