Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Fake Wallet App Built-in Fake Airdrop Authorization Asset Theft: High-imitation interface disguising claim page, draining all on-chain assets without seed phrase

The primary victims are retail investors newly entering the crypto market during the 2025-2026 recovery, aged between 25 and 45. They possess certain digital assets but lack blockchain security knowledge, habitually obtaining airdrop information and downloading wallet apps through social media groups, Telegram channels, and search engines, while lacking the ability to judge whether an app is genuine. Their psychological vulnerabilities include a desire to take advantage of small gains, strong expectations for free tokens, and trust projection when facing high-imitation interfaces—these users often wrongly transfer the security of well-known wallet brands to counterfeit apps. Prompted by pop-up red dots and high airdrop temptations, they hastily sign authorization transactions, only realizing hours or days later that their assets have been wiped out.

SCAM

Key Fields

FIELD STAMPS
IndustryFintech
RegionGlobal(全球(亚太重灾区))
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

The primary victims are retail investors newly entering the crypto market during the 2025-2026 recovery, aged between 25 and 45. They possess certain digital assets but lack blockchain security knowledge, habitually obtaining airdrop information and downloading wallet apps through social media groups, Telegram channels, and search engines, while lacking the ability to judge whether an app is genuine. Their psychological vulnerabilities include a desire to take advantage of small gains, strong expectations for free tokens, and trust projection when facing high-imitation interfaces—these users often wrongly transfer the security of well-known wallet brands to counterfeit apps. Prompted by pop-up red dots and high airdrop temptations, they hastily sign authorization transactions, only realizing hours or days later that their assets have been wiped out.

骗局怎么运作

  • Attackers first promote a counterfeit app closely mimicking a well-known wallet through third-party app stores, social media ads, and search engine bidding rankings. The icon, interface, and even official website domain are almost completely replicated. After downloading and installing, users can normally create or import a wallet; the malicious code does not trigger any anomalies during this stage, leaving users completely unaware that they have installed a counterfeit application.
  • During use, the fake wallet app periodically pops up airdrop claim notifications via built-in push messages or homepage red dots, claiming that the user has won rewards ranging from thousands to 100,000 USDT due to their holding period or participation in a protocol. It urges immediate claiming to create a sense of scarcity and urgency, inducing users into the fake airdrop claim page built into the app.
  • The fake airdrop page requires users to complete an authorization signature before claiming. In reality, this invokes the Permit or Permit2 on-chain authorization mechanism. The pop-up window seen by the user inside the fake app only displays a vague authorized amount and a long string of contract addresses, omitting complete transaction call data. Users often see only the confirm claim button and click to sign.
  • Once the user signs the authorization, what the attackers obtain is not the seed phrase, but unlimited authorization permissions for specific token contracts within the user's wallet. After monitoring the authorization event offline on-chain through smart contracts, attackers batch-execute transfer operations to move all high-value tokens like USDT from the user's wallet into an intermediate address controlled by the attacker.
  • After transferring to the intermediate address, attackers immediately launder the assets via cross-chain bridges, decentralized exchanges, or mixing solutions, completing on-chain splitting and transferring within minutes. When users discover their balance is zero and check the block explorer, they typically only see a series of outgoing transactions, and the funds cannot be recovered. Some attackers also use the acquired on-chain permissions to continuously monitor the wallet, waiting for users to deposit assets back from exchanges to steal them a second time.
  • To expand their coverage, attackers simultaneously spread forged official airdrop announcements in Discord communities and Telegram channels, attached with fake wallet download links and claim tutorials. Some social engineering scripts use phrasing like 'limited time to claim or expire' and 'internal slots for former employees' to create urgency. Users are guided to the fake app, and the authorization and theft process repeats.

红旗信号(看到这些快跑)

  • 🚩 The wallet app is downloaded solely from third-party app stores, lesser-known websites, or social media links without verification from the official GitHub repository or website. The app icon looks identical to a well-known wallet, but the developer is listed as an unfamiliar name.
  • 🚩 The wallet frequently pops up airdrop claim red dot messages claiming high USDT rewards, but requires prior authorization or signing to claim. The contract address displayed in the authorization pop-up cannot be found on official blockchain explorers in relation to the project party.
  • 🚩 The mnemonic phrase format displayed when exporting seed phrases after creating or importing a wallet is abnormal, or it requires additional input of the mnemonic for secondary verification. Genuine wallets typically do not require secondary input of the mnemonic immediately after creation.
  • 🚩 The domain name of the airdrop claim page does not match the official project domain, possibly using homoglyphs (such as the number 0 instead of the letter O) or short meaningless domain suffixes, and no corresponding airdrop announcement can be found on the project's official social media.
  • 🚩 The authorization pop-up does not display complete transaction call data, or the authorized amount is shown as unlimited. Normal airdrop claims typically do not require granting unlimited transfer permissions to token contracts.
  • 🚩 Airdrop announcements pushed in communities are attached with wallet download links and use urgent phrasing such as limited-time claims and expiration warnings to pressure users into immediate action, while no corresponding announcements can be found on official project channels to substantiate them.

真实案例

  • In August 2026, the SlowMist security team released a report indicating that a batch of fake wallet apps impersonating well-known brands such as TokenPocket and imToken were widely listed on third-party app stores. Tens of thousands of users had already downloaded them and signed authorizations on fake airdrop pages, with total losses amounting to approximately $1.3 billion. Attackers induced users to sign Permit authorizations through the built-in airdrops in the fake apps, batch-transferring user tokens without needing seed phrases. (As reprinted by Zhengjia Fortune Network from the SlowMist report) (Source: [https://news.sysxhz.com/newskx/20260810/1664010.html](https://news.sysxhz.com/newskx/20260810/1664010.html))
  • In March 2026, a cryptocurrency investor in South Korea saw a high-yield airdrop claim ad on social media, downloaded a counterfeit wallet app via the link, and signed a smart contract authorization while claiming the airdrop. Subsequently, approximately 800 million KRW worth of USDT in their wallet was entirely transferred away. Security researchers analyzed and confirmed that the attack exploited the Permit2 unlimited authorization mechanism, and the victim completely failed to notice that the authorized amount was set to unlimited during signing. This case was later referred to by the industry as the 800 Million KRW USDT Phishing Case. (Reported by Tencent Cloud Developer Community Security Research) (Source: [https://developer.cloud.tencent.com/article/2634581](https://developer.cloud.tencent.com/article/2634581))
  • In May 2026, a citizen in Dongguan, Mr. A, received an airdrop claim message via a Telegram channel claiming to be from a DeFi project party. After clicking the link, he downloaded a counterfeit MetaMask app. After following instructions to claim an airdrop claimed to be worth 100,000 U, he discovered the next day that both USDT and ETH in his wallet had been wiped out, resulting in cumulative losses of about 1.1 million RMB equivalent in crypto assets. Upon receiving the report, the Dongguan police urgently initiated payment-stopping procedures and successfully intercepted a portion of the funds. (As reprinted by ChainCatcher from the Dongguan Police case bulletin)

Official Stance

  • In November 2025, the National Anti-Fraud Center issued a warning reminding the public to be alert to virtual currency fake airdrops and fake wallet scams, pointing out that bad actors induce users to sign authorizations and steal assets by impersonating well-known wallet applications, and urging users to download related apps only from official channels.
  • In January 2026, the SlowMist blockchain security team released a security report on fake wallet apps, disclosing that counterfeit wallet apps had caused tens of thousands of users to be hacked, with cumulative losses of about $1.3 billion, and advised users to download wallets through official GitHub repositories or websites and verify app signatures.
  • In June 2026, the National Internet Finance Association of China issued a risk warning reminding investors to beware of authorization scams carried out under the guise of virtual currency airdrops, pointing out that such scams exploit the Permit signing mechanism to imperceptibly transfer user assets without touching seed phrases.

How to Protect Yourself

  • ✅ Download and install wallet apps exclusively from well-known wallets' official GitHub repositories, official websites, or official app stores like Apple App Store and Google Play. Carefully check developer names and user reviews before downloading, and never download directly from unknown links in social media messages.
  • ✅ Before signing any authorization transaction, use tools like Revoke.cash or Etherscan to check the authorized amount and target contract address. If the authorization limit is unlimited or the target contract cannot be verified on the official explorer, refuse to sign immediately.
  • ✅ Use hardware wallets for cold storage of core assets, and separate daily operation wallets from large-asset wallets. Perform authorization operations only on small-balance hot wallets to avoid exposing all assets to environments that may be called by unlimited authorizations.
  • ✅ Regularly use authorization management tools like Revoke.cash and Allowance Checker to inspect contract permissions granted by your wallet, and immediately revoke any abnormal or unused authorizations to reduce the risk of attackers exploiting existing authorizations for secondary theft.
  • ✅ Report suspicious fake wallet app clues through the 12321 Internet Illegal and Junk Information Reporting Center or local public security organs' anti-fraud centers, and simultaneously provide feedback to the official team of the impersonated well-known wallet to help other users avoid falling victim.