Crypto Wallet Red Dot Fake Airdrop Permit Authorization Theft Scam: Using High-Value Pop-ups to Induce Signatures and Drain Assets
Victims are primarily cryptocurrency novices or retail investors unfamiliar with the underlying logic of smart contracts. Driven by the 'too good to be true' mentality, they easily click on high-value airdrop red dots popping up in their wallets. Lacking knowledge of off-chain signature authorization, they mistakenly believe they are claiming free tokens, unaware that they are granting hackers control over their assets at the moment of signing, ultimately leading to their life savings being wiped out in an instant.
Key Fields
FIELD STAMPSWho Gets Targeted
Victims are primarily cryptocurrency novices or retail investors unfamiliar with the underlying logic of smart contracts. Driven by the 'too good to be true' mentality, they easily click on high-value airdrop red dots popping up in their wallets. Lacking knowledge of off-chain signature authorization, they mistakenly believe they are claiming free tokens, unaware that they are granting hackers control over their assets at the moment of signing, ultimately leading to their life savings being wiped out in an instant.
骗局怎么运作
- Hackers analyze on-chain data to identify target wallet addresses holding significant amounts of stablecoins or mainstream currencies. They then precisely transfer tiny amounts of unknown tokens to these addresses or use technical means to force a red-dot notification in the victim's wallet, claiming a '100,000 USDT prize,' leveraging visual cues to trigger curiosity and greed.
- Upon clicking the red-dot pop-up, victims are directed to a meticulously forged airdrop website. These sites often clone the UI of well-known projects and even use sponsored search engine ads to drive high traffic. The pages typically display claims that connecting a wallet will grant airdrop rewards worth up to $100,000, which is highly inflammatory and difficult for novices to guard against.
- After clicking the claim button on the fake site, the wallet triggers a Permit signature request. Hackers exploit the ERC-20 authorization mechanism; the signature content is not a direct transfer, but an authorization for the hacker's address to control core assets like USDT in the victim's wallet. The process consumes no gas, leading victims to blindly click confirm without realizing the risk.
- Using the smart contract permissions obtained through the authorization, hackers deploy automated scripts to monitor the victim's wallet address in real-time. Once the victim deposits enough funds to cover gas fees, the hackers immediately trigger the transfer logic, instantly draining all authorized high-value tokens and moving them to an isolated address.
- To mask the flow of funds and evade tracking, hackers split and transfer the stolen assets multiple times through non-KYC cross-chain bridges or crypto mixers. Sometimes, hackers use on-chain messaging to send secondary phishing lures, attempting to trick victims into paying 'unfreezing fees' or continuing operations on fake sites to extract any remaining value.
红旗信号(看到这些快跑)
- 🚩 Sudden appearance of unexplained red-dot notifications in the wallet, accompanied by unknown small-amount token transfer records.
- 🚩 High-value airdrop rewards claimed by unofficial channels that far exceed standard project distribution, reaching tens or hundreds of thousands of dollars.
- 🚩 Claiming an airdrop without paying any gas fees to complete the signature confirmation, which is a hallmark of offline authorization.
- 🚩 Signature messages popping up after connecting a wallet that contain dangerous terms like 'Set Approval For All' or 'Permit'.
- 🚩 Airdrop websites promoted via sponsored search engine ads, with domain names showing minute character differences from official homepages.
真实案例
- In 2024, an 800 million KRW USDT phishing case was reported in South Korea. A woman participating in a fake DeFi project with high-yield lures had her smart contract permissions hijacked. After clicking to sign an authorization on a forged page, her massive stablecoin holdings were instantly transferred by the hacker's automated contract, resulting in devastating, unrecoverable losses.
- According to blockchain security firm ChainCatcher, a user clicked on a top-ranked sponsored search ad that led to a high-fidelity phishing site mimicking a hardware wallet companion app. After connecting their hardware wallet, the user signed a malicious Permit request, leading to the total theft of their life savings.
- Many decentralized wallet users have reported unexplained red-dot notifications. Clicking them led to fake airdrop pages claiming a 100,000 USDT reward. After signing the authorization, their USDT was instantly drained by hackers using the granted permissions. On-chain records later showed the funds were split and moved through mixing platforms. (Source: http://www.tzjp.cn/news/60191)
- According to a report by blockchain security firm CertiK, crypto ATM fraud losses reached $330 million in 2025, a year-on-year increase of approximately 33%. AI technology has escalated criminal sophistication, with phishing signatures and authorization hijacking remaining the primary causes of loss. (Source: https://www.panewslab.com/zh/articles/019ce23f-98fe-72de-8bc6-3bdffc56f2e9)
- According to the CertiK annual report, 248 phishing incidents were recorded in 2025, resulting in approximately $723 million in losses. Over 700 Web3 security incidents throughout the year caused a total of $3.35 billion in losses, with phishing authorization attacks being one of the most costly types of attacks. (Source: https://view.inews.qq.com/a/20251224A03DGA00)
Official Stance
- In November 2023, the Ripple Foundation issued an official warning regarding widespread fake XRP airdrop campaigns, urging users to remain vigilant against unknown links and never sign unauthorized signatures.
- In 2024, the Tencent Cloud Developer Community published security defense research on Web3 phishing attacks, classifying fake project airdrop phishing as a high-risk security event and disclosing the attack mechanisms behind fake Solana token incidents.
- In April 2024, blockchain tracking agency ChainCatcher issued a security alert warning users about phishing wallet links spread through Google sponsored ads, noting that attackers are exploiting Permit signature vulnerabilities to steal users' life savings.
How to Protect Yourself
- ✅ Never click on unexplained red-dot notifications in your wallet. If you receive small, unknown token transfers, hide them directly in your wallet and never visit related websites to connect your wallet.
- ✅ Before signing any transaction or message, carefully read the content of the wallet pop-up. If dangerous authorization terms like 'Permit' or 'approve' appear, cancel the signature immediately and close the webpage.
- ✅ For daily operations, it is recommended to use secure wallets with malicious authorization interception features. Keep large assets in cold storage and reserve only a minimal amount of funds in hot wallets for daily use to reduce risk exposure.
- ✅ Verify airdrop information through multiple channels, such as the project's official Twitter, Discord, or authoritative community websites. Never access decentralized applications through search engine ads or short links shared in unfamiliar social groups.