Deepfake CEO Airdrop Hijacking: Fake Executive Videos Lure You into Claiming Rewards, Draining Wallets Upon Authorization
Victims are primarily new and experienced cryptocurrency users who have been lurking in communities, eager to capture the 'free airdrop' windfall and possessing an inherent trust in well-known projects or CEOs. Psychologically, they are easily triggered by scarcity tactics like 'limited supply' or 'first-come, first-served' countdowns, leading to FOMO (Fear Of Missing Out). Because the videos and landing pages are highly realistic, they often skip secondary verification on official websites, ultimately resulting in their entire long-term savings being wiped out.
Key Fields
FIELD STAMPSWho Gets Targeted
Victims are primarily new and experienced cryptocurrency users who have been lurking in communities, eager to capture the 'free airdrop' windfall and possessing an inherent trust in well-known projects or CEOs. Psychologically, they are easily triggered by scarcity tactics like 'limited supply' or 'first-come, first-served' countdowns, leading to FOMO (Fear Of Missing Out). Because the videos and landing pages are highly realistic, they often skip secondary verification on official websites, ultimately resulting in their entire long-term savings being wiped out.
骗局怎么运作
- Scammers collect speech clips, facial photos, and voice samples of famous tech CEOs or financial celebrities from public channels to generate a 'CEO-endorsed' video using deepfake tools. The video claims that the project is celebrating an anniversary or rewarding the community with a massive airdrop, providing a link to a so-called official event. To enhance credibility, scammers forge official logos, blockchain explorer interfaces, and even insert real-time TVL data into the video to create a sense of authenticity.
- The airdrop page is designed to look almost identical to the project's official website, with a domain name differing by only one letter or suffix. After clicking the link, users are prompted to connect wallets like MetaMask and are told to 'perform a Gas fee transfer to verify eligibility' or 'complete an authorization signature to bind your address.' Scammers then arrange for 'shills' in Telegram/Discord groups to post screenshots of successful claims, while private messaging users with urgency: 'Spots are running out, act now or lose your chance.'
- If a user follows the instructions to perform an 'authorization signature,' they are effectively granting the malicious contract permission to transfer tokens from their wallet. On-chain, this is simply a standard 'approve' operation, and the interface displays a familiar signature request, which many users mistakenly believe is a necessary step to claim an airdrop. Once confirmed, the malicious contract gains the right to drain all transferable tokens from the user's wallet at any time, while the user sees nothing suspicious on the surface.
- To increase deception, some scams first transfer a tiny amount of tokens or NFTs to the victim's wallet as a 'test airdrop,' making the user believe they have truly received a reward and lowering their guard. Subsequently, scammers induce the user to pay higher 'processing fees' or 'security deposits' to unlock larger airdrops. In reality, this money goes directly to the scammer's address, with no further rewards provided.
- Once the user completes a large transfer or authorization, a malicious script rapidly sweeps all transferable USDT, ETH, and other tokens from the wallet, a process taking only seconds. The scammers then delete the website, disband the community, and change the domain. The assets are quickly moved through mixers or decentralized exchanges, making tracking extremely difficult due to on-chain anonymity. Victims often only realize their balance is zero when they reopen their wallet, by which time hours or even days have passed.
红旗信号(看到这些快跑)
- 🚩 Official CEOs will never release airdrops through unverified channels, nor will they ever require users to transfer funds or perform wallet authorizations to claim them.
- 🚩 Airdrop domain names are extremely similar to official sites but contain extra numbers, letters, or use suspicious non-.com suffixes like .xyz or .top.
- 🚩 The person in the video has unsynchronized lip movements and audio, abnormal blinking frequency, occasional blurring or distortion at facial edges, and a slight electronic synthesis quality to the voice.
- 🚩 The page requests a wallet connection and an 'authorization signature' or 'contract approval' instead of a simple 'login to claim.'
- 🚩 A large number of newly registered accounts in the community are spamming the comment section with profit screenshots, accompanied by countdowns and scarcity-driven urgency tactics.
真实案例
- On August 2, 2026, Singapore's 'Lianhe Zaobao' reported on deepfake tech scams: From February to June 2024, discussions on deepfakes in Telegram forums popular with Southeast Asian cybercriminals surged by 60%. Singapore Police Force data shows 37,308 scam cases in 2025, with total victim losses of 913.1 million SGD. In March 2025, a financial executive at a multinational corporation was nearly defrauded of nearly 500,000 USD. (Source: https://www.zaobao.com.sg/news/singapore/story20260802-9443667)
- In 2026, overseas gangs impersonated the AI computing unicorn VAST.AI to set up a Ponzi scheme, claiming that 'staking tokens earns airdrop rewards.' Project watchdog sites issued a major warning, stating that the 'AI unicorn that just raised 1 billion has been spoofed for a pyramid scheme, spreading across multiple regions.' The gang created fake websites and promotional materials to induce victims to pay deposits before absconding with the funds.
- In 2026, AI-generated deepfake videos appeared in Taiwan, showing a 'financial commentator' and a 'central bank governor' together recommending high-return investment projects, which were publicly refuted by the individuals involved. Sanli News reported that these tactics have expanded from celebrity endorsements to cryptocurrency airdrop scams, with investors already losing assets after clicking fake links.
- In July 2026, Pingpan.cc issued a warning regarding the fake VAST.AI Ponzi scheme: Overseas gangs spoofed the AI unicorn VAST.AI to conduct pyramid schemes. The platform used 'AI computing power leasing' as a front, setting tiered investment levels starting at 500 USDT with a 0.5% daily return, up to 59,880 USDT for the highest tier, while implementing a multi-level referral commission mechanism. (Source: https://pingpan.cc/article/5933.html)
Official Stance
- In August 2026, Malaysian police issued a warning through media outlets like 'Oriental Daily News,' urging the public to be vigilant against investment scams using AI-synthesized celebrity videos and calling for verification through official channels.
- In July 2026, Taiwan's Ministry of Digital Affairs announced the formation of a 'Digital Advertising Trust Alliance' with platform operators to label and filter AI-forged content, while reminding the public to return to official sources to confirm when seeing celebrity-endorsed airdrops or investments.
- On August 2, 2026, 'Lianhe Zaobao' cited warnings from Singapore police and cybersecurity experts, noting that deepfake technology has become 'indistinguishable from reality.' The public should remain skeptical of online videos, especially those involving transfers or authorizations, and verify them with official sources.
How to Protect Yourself
- ✅ Upon receiving any 'airdrop' information, first visit the project's official website and Twitter to verify if the event exists; never click links in comment sections or private messages.
- ✅ Do not connect hot wallets containing large assets to unfamiliar DApps; consider creating a secondary 'test wallet' to participate in such activities.
- ✅ Remain vigilant against any requests for 'authorization signatures' or 'contract approvals,' and check if the contract address matches the official announcement before signing.
- ✅ Install security detection plugins for mainstream wallets or use hardware wallets, lower daily withdrawal limits, and regularly check and revoke suspicious contract authorizations.