BTC:
ETH:
SOL:
BNB:
XRP:
Wallet safety

Spotting malicious links and fake claim pages

Almost every drainer starts the same way: a link that looks close enough to legitimate to earn one click, and one connected wallet.

6 min readReviewed July 14, 2026Wallet safety

The short answer

Malicious links rarely look obviously fake. They imitate a real project's branding, use a domain that's one character off from the original, and are distributed through channels—ads, DMs, compromised accounts—that borrow credibility from somewhere else. The link itself is rarely the dangerous part; what you sign after clicking it is.

Common patterns

  • Typosquatted domains. A single swapped, added, or removed character—juplter.ag instead of jupiter.ag—designed to pass a quick glance.
  • Urgency framing. Countdown timers, "limited claim window," or "your allocation expires soon" language designed to shortcut careful review.
  • Cloned interfaces. Pixel-accurate copies of a real dApp, often produced quickly with generative tools, hosted on a domain that only differs in the URL bar.
  • Borrowed credibility. Links shared from a compromised official account, a hacked Discord admin, or a deepfaked video using footage from a real event to appear endorsed.
  • Rotating domains. Active campaigns frequently swap domains every 24–48 hours specifically to stay ahead of blocklists and browser warnings.

Before you click connect

  1. Type the URL yourself or use a bookmark you saved from a verified source—don't follow a link from a DM, ad, or comment.
  2. Check the exact domain character by character, including the TLD.
  3. Confirm the claim, mint, or airdrop independently on the project's official channel before connecting anywhere.
  4. Treat any unexpected DM about a claim, refund, or "you were selected" as fraudulent by default.
  5. If you do connect, use a burner wallet, and read the transaction contents before signing rather than clicking approve on reflex.

Primary and official sources

Turn the lesson into evidence

Verify a suspicious address before trusting a link.

Preflight a public address linked from any claim page to see what it's actually done on-chain.

Open wallet preflight