Wallet safety
Spotting malicious links and fake claim pages
Almost every drainer starts the same way: a link that looks close enough to legitimate to earn one click, and one connected wallet.
6 min readReviewed July 14, 2026Wallet safety
The short answer
Malicious links rarely look obviously fake. They imitate a real project's branding, use a domain that's one character off from the original, and are distributed through channels—ads, DMs, compromised accounts—that borrow credibility from somewhere else. The link itself is rarely the dangerous part; what you sign after clicking it is.
Common patterns
- Typosquatted domains. A single swapped, added, or removed character—
juplter.aginstead ofjupiter.ag—designed to pass a quick glance. - Urgency framing. Countdown timers, "limited claim window," or "your allocation expires soon" language designed to shortcut careful review.
- Cloned interfaces. Pixel-accurate copies of a real dApp, often produced quickly with generative tools, hosted on a domain that only differs in the URL bar.
- Borrowed credibility. Links shared from a compromised official account, a hacked Discord admin, or a deepfaked video using footage from a real event to appear endorsed.
- Rotating domains. Active campaigns frequently swap domains every 24–48 hours specifically to stay ahead of blocklists and browser warnings.
Before you click connect
- Type the URL yourself or use a bookmark you saved from a verified source—don't follow a link from a DM, ad, or comment.
- Check the exact domain character by character, including the TLD.
- Confirm the claim, mint, or airdrop independently on the project's official channel before connecting anywhere.
- Treat any unexpected DM about a claim, refund, or "you were selected" as fraudulent by default.
- If you do connect, use a burner wallet, and read the transaction contents before signing rather than clicking approve on reflex.
Primary and official sources
Turn the lesson into evidence
Verify a suspicious address before trusting a link.
Preflight a public address linked from any claim page to see what it's actually done on-chain.
Open wallet preflight