Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Multi-Chain Fake Token Airdrop and Multi-Sig Authorization Asset Theft Scam: Scammers transfer worthless fake tokens to wallets and lure users to fake DApps claiming they can be swapped, subsequently tricking them into multi-sig authorizations to drain all assets.

Victims are predominantly middle-aged and young crypto wallet holders, including both veteran on-chain players and novices attracted by communities and short videos. They are usually unfamiliar with airdrop rules, and when they see unfamiliar tokens or red-dot popups in their wallets, they experience a fear of missing out and a sense of being selected for rewards. Eager to swap or claim, they overlook contract authorization details. Some users misinterpret forwarded community tutorials and screenshots, believing they are safe as long as they do not input their seed phrase, only realizing they have been scammed after their assets are silently transferred away following authorization. New users, small-capital retail investors, and investors chasing trending narratives are most easily targeted.

SCAM

Key Fields

FIELD STAMPS
IndustryFintech
RegionGlobal(全球(发币与钓鱼页面常托管在境外,受害者多在华语区与东南亚))
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

Victims are predominantly middle-aged and young crypto wallet holders, including both veteran on-chain players and novices attracted by communities and short videos. They are usually unfamiliar with airdrop rules, and when they see unfamiliar tokens or red-dot popups in their wallets, they experience a fear of missing out and a sense of being selected for rewards. Eager to swap or claim, they overlook contract authorization details. Some users misinterpret forwarded community tutorials and screenshots, believing they are safe as long as they do not input their seed phrase, only realizing they have been scammed after their assets are silently transferred away following authorization. New users, small-capital retail investors, and investors chasing trending narratives are most easily targeted.

骗局怎么运作

  • Scammers use multi-chain ecosystems to batch-generate seemingly authentic project tokens, distributing fake coins into a large number of wallet addresses via on-chain transfers. The transfer remarks or token names embed claiming links, official websites, or community portals to create the illusion that you have been selected for an official airdrop.
  • After seeing unfamiliar token balances or red-dot notifications in their wallets, users often search for the token name themselves or click the links in the remarks to enter phishing pages. The pages mimic popular project interfaces, providing swap, claim, voting, or staking portals to reinforce the atmosphere of grabbing dividends.
  • Once the wallet is connected, the page does not directly ask for seed phrases; instead, it triggers an authorization popup, luring users to execute multi-token unlimited authorizations or multi-sig permissions on fake contracts. Common tactics include claiming that USDT authorization is needed as gas fees, that contract authorization is required to distribute airdrops, or that signatures are needed to complete anti-sybil verification.
  • Once authorization is completed, scammers use the obtained permissions in the backend to directly transfer mainstream assets such as USDT and Ethereum out of the user's wallet via smart contracts. Some attacks first use small-amount transfers to test whether the operation succeeds before batch-draining the account, and users may not receive any obvious notifications throughout the process.
  • Afterward, phishing pages and transfer remark links often quickly change domains or go offline, community portals are cleaned up, and on-chain authorizations remain valid. Even if users discover it afterward, it is difficult to trace, and they can only see on a block explorer that assets were transferred to a centralized address and then laundered across multiple paths.

红旗信号(看到这些快跑)

  • 🚩 Unfamiliar tokens that you never actively applied for suddenly appear in your wallet, with links, official websites, or Telegram group entrances directly embedded in the token name or transfer remarks.
  • 🚩 The claiming page requests connection of the wallet and immediately demands unlimited authorization for all tokens or USDT, accompanied by urgent language urging quick action, limited quotas, or requests to authorize gas or anti-sybil signatures.
  • 🚩 The domain name is highly similar to the official project but contains subtle differences, such as an extra letter, numbers replacing letters, or a different suffix from the official website, while the page copies the official logo and copywriting.
  • 🚩 The authorization popup shows the invocation of an unfamiliar contract address that does not match the contract address published in official documentation, requesting SetApprovalForAll, Permit, or multi-sig permissions instead of a regular transfer.
  • 🚩 Neither the project community nor the official block explorer has any announcements regarding such tokens and airdrops, which appear only as wallet red dots or unknown links. The sender of the transfer is an unfamiliar address with no official verification whatsoever.

真实案例

  • In 2026, SlowMist disclosed that scams related to fake wallet apps had caused tens of thousands of people to be hacked, with estimated losses reaching $1.3 billion. Reports indicated that attackers induced users to authorize transactions through forged wallet applications and fake airdrop entry points, after which mainstream assets were drained. The case value was huge, though specific subjects have not been convicted, and the report only provided technical alerts regarding the model. (Source: [https://news.sysxhz.com/newskx/20260810/1664010.html](https://news.sysxhz.com/newskx/20260810/1664010.html))
  • In 2026, an 800 million Korean Won USDT phishing case occurred in South Korea. A technical article from Tencent Cloud Developer Community analyzed that victims were lured by high-yield baits to fake DApps, and after executing authorizations for malicious smart contracts, their permissions were hijacked, and USDT was directly transferred away on-chain. The article used this as a research case for the restructuring and defense strategies of on-chain security mechanisms. (Source: [https://developer.cloud.tencent.com/article/2634581](https://developer.cloud.tencent.com/article/2634581))
  • In 2026, the Tencent Cloud Developer Community published research stating that a CJUP fake token incident occurred on the Solana chain, where attackers impersonated project airdrops to induce users to connect wallets and sign authorizations, after which assets were stolen. The article used this event to analyze the attack mechanism and defense of impersonated project airdrop phishing.

Official Stance

  • On August 10, 2026, domestic financial media cited SlowMist reports stating that fake wallet apps had caused tens of thousands of people to be hacked, with estimated losses as high as $1.3 billion, reminding users to be vigilant against apps and airdrop pages of unknown origin.
  • In 2026, the Tencent Cloud Developer Community released security research stating that smart contract permission hijacking was behind the 800 million Korean Won USDT phishing case, reminding users that high-yield bait and unfamiliar authorization risks coexist, and urging caution regarding on-chain signatures.
  • In 2026, the Tencent Cloud Developer Community published technical analysis stating that the Solana chain CJUP fake token incident belongs to impersonated project airdrop phishing attacks, reminding users to remain vigilant against authorizations for unfamiliar tokens and fake DApps.

How to Protect Yourself

  • ✅ Treat unfamiliar tokens in your wallet that you did not actively apply for as a default risk signal; do not click links in token transfer remarks, and do not connect your wallet directly after searching for tokens.
  • ✅ Always execute operations involving authorization popups using official domain names and contract addresses published in official documentation. Cross-check through multiple channels before interacting, and refuse unlimited authorizations.
  • ✅ Use wallets and security plugins that support transaction simulation and authorization alerts, review the contract addresses, permissions, and limits requested in authorization requests, and remain highly vigilant against SetApprovalForAll, Permit, and multi-sig requests.
  • ✅ Regularly use blockchain explorers or authorization management tools to check your wallet's authorizations for various contracts, revoke unnecessary and suspicious authorizations in a timely manner, and reduce the risk of authorizations being abused.