Phishing Scam Impersonating Mythical Games: Fake NFT Airdrops Induce Wallet Connections to Drain Assets
Victims are primarily blockchain gamers and NFT collectors aged 18 to 40 who are familiar with wallet operations but lack knowledge of smart contract security. They are often driven by FOMO (fear of missing out) on scarce assets, inherent trust in major gaming brands, and speculative desires to find low-priced deals in secondary markets. Scammers exploit the psychological inertia of users who, upon seeing a limited-time free mint, lower their guard and rush to sign authorizations. In some cases, all tokens and NFTs in a victim's wallet are drained within seconds of signing.
Key Fields
FIELD STAMPSWho Gets Targeted
Victims are primarily blockchain gamers and NFT collectors aged 18 to 40 who are familiar with wallet operations but lack knowledge of smart contract security. They are often driven by FOMO (fear of missing out) on scarce assets, inherent trust in major gaming brands, and speculative desires to find low-priced deals in secondary markets. Scammers exploit the psychological inertia of users who, upon seeing a limited-time free mint, lower their guard and rush to sign authorizations. In some cases, all tokens and NFTs in a victim's wallet are drained within seconds of signing.
骗局怎么运作
- Step 1: Distributing fake ads and phishing links. Syndicates post ads on Twitter/X and Discord or lurk in official community comment sections to post high-fidelity phishing links. They claim Mythical Games is launching a limited-time FIFA-themed NFT free mint or a whitelist airdrop, using narratives of 'official collaborations' or 'limited-edition tributes to legendary players' to create a sense of urgency and discourage verification.
- Step 2: Building pixel-perfect fake websites. The phishing sites replicate the official page structure, visual assets, and domain appearance, changing only a single character (e.g., replacing 'l' with '1' or adding a hyphen). Combined with AI-generated promotional images and fake user comments, these sites are nearly indistinguishable from the real ones to the average user.
- Step 3: Inducing crypto wallet connection. The page prompts a 'Connect Wallet' button, supporting mainstream wallets like MetaMask. The pretext is to verify eligibility for the airdrop or check whitelist status. While the initial connection only establishes a link to a malicious contract, most users do not understand the difference between a connection and a signature authorization, leading them to easily approve subsequent pop-ups.
- Step 4: Triggering malicious signature authorization requests. After connection, the system triggers a signature or transaction authorization window. In reality, this grants the attacker unlimited allowance to spend tokens or directly transfer NFTs from the wallet. The request is disguised as a 'confirmation of minting gas fees' or 'on-chain identity verification.' Once signed, the malicious contract gains control over the user's assets.
- Step 5: Automated draining and site shutdown. The moment authorization is granted, a pre-set script automatically transfers all stablecoins, ETH, and NFTs from the victim's wallet to a money-laundering address, usually within seconds. The phishing site then changes its domain to continue the scam. Victims are left with no customer support or recourse, and because on-chain transfers are irreversible, recovery is extremely difficult.
红旗信号(看到这些快跑)
- 🚩 Subtle differences in the domain name compared to the official site, such as an extra hyphen, numbers replacing letters, or the use of uncommon top-level domain suffixes.
- 🚩 Any NFT minting or airdrop page that requests a signature authorization immediately after connecting the wallet, especially if the authorization includes unlimited token spending or asset transfer permissions.
- 🚩 Promotional language promising limited supply, guaranteed price appreciation, or free high-value NFT minting to create urgency and prevent users from verifying the claims.
- 🚩 Official community admins never initiate private messages. Any account sending airdrop links via DM or in random communities claiming 'insider spots' or 'official partnerships' is highly suspicious.
- 🚩 The website lacks verifiable corporate information, business registration details, or official authentication badges, and the transaction contract address shows no historical reputation on blockchain explorers.
- 🚩 A large number of identical accounts in the community spamming screenshots of profits or using the exact same scripts to comment on each other's posts to create a false atmosphere of prosperity.
真实案例
- Around 2024, the Bitdefender security lab disclosed multiple phishing campaigns targeting gamers, identifying numerous fake sites impersonating Mythical Games, OpenSea, and PepsiCo. These sites claimed to issue FIFA-themed or limited-edition blind box NFTs to steal assets. The report detailed the batch registration characteristics and propagation paths of these phishing domains.
- A player saw a fake Mythical Games account on Twitter promoting a limited-edition player NFT free mint. After connecting their wallet to the phishing site and signing a transaction disguised as 'verification,' thousands of dollars worth of NFTs and tokens were drained within seconds. Blockchain explorer tracking later linked the recipient address to multiple similar phishing cases.
- Multiple users on the Reddit 'CryptoScams' board reported being defrauded by fake Mythical Games trading platforms or secondary markets. After depositing funds, the accounts showed fake profits but withdrawals were blocked. Customer support then demanded 'taxes' or 'security deposits' to unlock the funds, a classic 'fake platform + secondary harvest' scam.
- Blockchain security professionals on platforms like Zhihu summarized common AI blockchain game and token scams in 2026, noting that criminals frequently use the names of well-known gaming brands to issue fake tokens and staking schemes. These scams involve massive amounts of money and follow the same pattern as the brand-impersonation phishing model.
- In March 2026, Hangzhou police broke up a major AI investment 'pig-butchering' scam involving over 200 million RMB and more than 5,000 victims. The gang used free 'AI stock picks' as bait to lure victims into groups, brainwashed them with fake profit screenshots, and eventually induced them to invest heavily in illegal platforms before disappearing. (Source: https://www.cls.cn/detail/2409793)
- In the March 2026 Hangzhou police case, one investor was lured into a group, made a small profit of 20,000 RMB, and was then induced to invest 500,000 RMB to follow the 'teacher's' stock picks. Within a week, they lost 450,000 RMB, the group was disbanded, and the teacher went silent, leaving the victim with nothing. (Source: https://www.cls.cn/detail/2409793)
Official Stance
- In 2024, the Bitdefender security lab released a special report titled 'Phishing Campaigns Masquerading as PepsiCo, OpenSea and Mythical Games,' systematically disclosing the characteristics of phishing domains, propagation channels, and asset theft processes, while urging users to verify URLs and be cautious with wallet signature requests.
- During the 2026 Anti-Fraud Awareness Month, media outlets like Cailian Press reported on the full-chain scams of AI investment 'pig-butchering' schemes. Regulators warned that high-yield promises using AI, the Metaverse, or blockchain asset appreciation as bait are high-risk signals and urged the public to report suspicious projects via the National Anti-Fraud Center App.
- In April 2026, public security organs in various regions listed gaming-related scams and fake digital asset investments as high-frequency threats in their fraud warnings, reminding players not to click on unknown links or sign unknown contracts, and to call the anti-fraud hotline immediately if scammed.
- In August 2026, CCTV News reported on the governance of illegal online stock recommendations and AI investment scams, pointing out that packaging scams with new concepts and impersonating legitimate platforms to lure victims is illegal, and that regulators will continue to crack down on such activities.
How to Protect Yourself
- ✅ Only access Mythical Games and any blockchain gaming platform through officially announced domains and verified social media accounts. Manually type or bookmark official websites and never click on links sent via private messages or advertisements.
- ✅ Distinguish between 'connecting' and 'signing' before interacting with a wallet. Pause before any signature request, check the contract address's history and community feedback on a blockchain explorer, and never approve unlimited token spending.
- ✅ Treat any promotion promising NFT or gaming asset appreciation, guaranteed returns, or limited whitelist spots as a red flag. Legitimate blockchain gaming assets are highly volatile; there is no such thing as an official guarantee of principal protection or appreciation.
- ✅ Use a separate wallet with zero or minimal balance for minting new projects, and keep large assets in a hardware wallet that is not connected to any websites to ensure physical isolation.
- ✅ If you detect abnormal wallet authorization, immediately use tools like revoke.cash to revoke permissions and transfer remaining assets. Save chat logs, transaction hashes, and page screenshots, and report the incident to the police and the National Anti-Fraud Center immediately.