You get an email. It looks official. It says a token you once used has snapped a picture of holders, and you qualify for a drop worth a few thousand dollars. Click the button, connect your wallet, sign the message. This page explains why almost every email that reads like that is a trap, and how to tell the small number of honest ones apart.

Why real drops do not need your inbox

A crypto airdrop is a transaction on a public ledger. The project knows which addresses qualify because it can read the blockchain. It does not know who those addresses belong to and has no reliable email tied to any of them. There is no mailing list of on-chain users.

Because of that, the honest way to announce an airdrop is the same for everybody: post the news on the project's own site and verified social channels, publish the eligibility list, and let people check by pasting their address. Nobody is emailed. If email were part of the flow, the drop would only reach the small share of holders who ever gave the project their email address, and that would be a bad drop by design.

Our page on where do I find airdrops on my phone covers the correct check-and-claim flow across common apps.

The anatomy of the scam email

Open one and you will see a familiar shape:

  • A logo you recognise. Copy-pasted from the real project.
  • A deadline in the subject line. Claim within 24 hours, or lose out. Urgency shuts down slow thinking.
  • An amount that feels plausible. Not too big, not too small. Enough to overrule caution.
  • A button that leads to a lookalike domain. Hover over it before clicking; the URL is almost never the project's real one.

When you click, you land on a clone claim page. From there the scam is the usual drainer โ€” an approve or permit signature that lets the site take a token you already hold. Our detailed breakdown lives at airdrop scams and the fake-page tell-tale checks are in how to identify fake airdrops.

Where does the email list come from

Scammers do not need to guess your address. Data breaches leak email lists by the millions every year, often tagged by which service the address was used at. A leak from a defunct exchange, a wallet-tracking app, or a news site with crypto readers is enough. If your email ever went to a crypto product, it is on many of these lists.

That is why the scam email often names a real service you have used. It is not clever targeting; it is just the leak metadata being read out loud. Being surprised by the accuracy is exactly what the scammer hopes for.

The rare cases where email is real

A few honest situations use email:

SituationWhy email is involvedWhat to do
A centralised exchange promoThe exchange has your email from account signupLog in to the exchange directly and check the promotions page there
A KYC-gated drop on a regulated venueRegulation requires identity checks, which include emailVerify the drop on the venue's official site before clicking any link in the email
A newsletter you subscribed toYou opted in and expect crypto news, sometimes including dropsStill verify the drop on the project's own site โ€” newsletters can be spoofed

In every real case, the email is a heads-up. The action still happens on the real service, reached by typing the URL yourself. No link in an email is ever the safe path.

A clean defence against the inbox scam

You can shut down this entire attack class with three habits.

  1. Never click a claim link inside an email. Type the project's URL yourself, or open it from a bookmark you saved earlier.
  2. Assume any email that carries urgency is fake until you have confirmed the drop on the project's own site.
  3. If you use a hardware wallet, do all claim signing on it. The physical screen makes a bad signature harder to miss.

Add a fourth for peace of mind: use a separate email for anything crypto. When the address leaks โ€” and it will, eventually โ€” the scam mail lands somewhere you already treat with suspicion. See is airdrop secure for the wider security routine that surrounds the click.

The inbox is not the airdrop

The rule to remember is short. Airdrops live on-chain. Your email lives in a database that has been leaked many times. Nothing about the second one belongs in the story of the first. When the message arrives promising money in return for one urgent click, close it, log in to the project or exchange yourself, and check the promotions page there. That single habit turns the oldest phishing pattern in crypto into background noise.