|

“You Have a 45% Airdrop Reward Waiting” – Twitter DM Scam

Updated October 4, 2026

How This DM Scam Works and How to Protect Yourself

A real conversation, a real attempt, and exactly how to spot it before it costs you everything.

Someone reached out to me on X within hours of my first post about a crypto token I hold. The message looked helpful. It sounded like a community mod. It almost worked – except I recognized the playbook. I contacted the real project developers to confirm it was fake, then saved the conversation as a teaching moment.

The short version, if you only read one paragraph: no legitimate project will ever DM you about an unclaimed airdrop, ask you to “fix” something in your wallet, or send you a link to connect your wallet. Any message that does all three is a wallet drainer.

Below is the actual exchange, with my wallet addresses blacked out. Read it carefully, because this exact script is being run on huge numbers of accounts every day.

What Just Happened – Step by Step

Step 1: The Hook – A Reward You Didn’t Know You Had

“All eligible holders have gotten their 45% airdrop rewards. Have you received your 45% reward bonus?”

This is the opener. It does a few things at once: it sounds official, it implies everyone else already got something, and it creates mild FOMO. If you’re new to crypto, you might genuinely wonder if you missed a legitimate distribution. So you answer.

That reply – that single “Not yet, where do I claim?” – is all they needed to confirm you’re worth pursuing.

Step 2: Harvesting Your Wallet Address

“Kindly send your wallet address.”

This sounds reasonable. Some legitimate airdrops do collect wallet addresses – but through a form or claim page on the project’s official website, announced publicly. Never through a DM from someone who contacted you first.

Here’s the nuance: a wallet address alone is not dangerous. Addresses are public by design on the blockchain. What they’re doing with it is pre-qualifying you and confirming you have assets worth targeting. They now know your holdings.

Step 3: Inventing a Fake Technical Problem

“There’s an issue with your in-node string which you’ve got to get fixed through the validation process.”

Stop right here. “In-node string” is not a real thing. It’s fabricated jargon designed to sound technical enough that a newcomer won’t question it. The invented problem serves one purpose: to give you a reason to take action – specifically, to connect your wallet to their site.

Legitimate blockchain protocols do not have “in-node string” errors. Legitimate airdrops do not require you to “fix” anything in your wallet to receive them. If tokens are owed to you, they are sent to your address or claimed on the project’s official site. Full stop.

Step 4: The Kill Shot – The Fake DApp Link

“To begin the recalibration, please connect manually to the DApp mainnet below: dappmainnetfixed.netlify.app”

This is the wallet drainer. Here’s why this URL is an instant red flag:

  • netlify.app is a free hosting subdomain. Anyone can create a site there in minutes. No legitimate blockchain protocol runs its official app on a free Netlify subdomain.
  • The name is engineered to sound authoritative. “DApp mainnet fixed” sounds like something official. It’s theater.
  • “Connect your wallet” + “look for Missing Assets” is the standard wallet drainer interface. The danger isn’t the connection itself – it’s what comes next. The site asks you to sign a transaction or a signature request, and that signature authorizes their contract to move your tokens. By the time you realize what happened, your wallet is empty.

Some of those signature requests don’t even look like transactions. “Permit” style signatures can appear as a harmless message to sign, but they grant spending permission just the same. Our wallet drainer approvals guide explains exactly how these permissions work and how to read what you’re signing.

Why You Were Targeted

If you just created a new crypto-focused account and posted about a specific token, you are on their radar within minutes. Scam bots and human operators monitor token hashtags in real time. A new account posting about a token signals:

  • You hold that token (or are interested in it)
  • You may be newer to the space
  • You have not built up the skepticism that comes with experience

This is not a personal attack – it’s volume farming. They send the same script to as many accounts as they can, hoping a small percentage will follow the link. The same playbook runs in Discord and Telegram too; we cover those versions in our Discord and Telegram social engineering guide.

The 5 Red Flags in This Conversation

Every crypto scam DM shares some version of these signals. Memorize them.

1. Unsolicited outreach about rewards you didn’t claim
Legitimate airdrops are announced publicly. If a “moderator” DMs you personally about unclaimed rewards, it’s a scam. (We track legitimate opportunities, and what’s already ended, on our Active Airdrops page.)

2. A fake technical barrier between you and your money
“In-node string,” “recalibration,” “validation process” – none of these are real. Invented jargon creates urgency and the illusion that you need to fix something.

3. A link to a free or unofficial domain
Real DApps live on their own registered domains (e.g., app.uniswap.org, app.aave.com). A wallet-connect link on netlify.app, vercel.app, github.io, or any similar free subdomain should be treated as a scam.

4. Any instruction to “connect your wallet” outside of a verified official site
If you didn’t navigate to the official site yourself by typing it directly or using a bookmarked URL – do not connect.

5. Pressure and urgency
“Prompt action,” “immediately,” “ensure it’s accurately reflected” – scammers want you to act before you think. In my case, about an hour after the first message, they followed up to ask whether I’d “completed the process” or needed “help.” Real protocols don’t expire your tokens because you took an extra day to verify.

What To Do If This Happens to You

If you haven’t clicked the link yet:
You’re fine. Block and report the account on X. No further action needed.

If you visited the site but didn’t connect your wallet:
Still fine. Browsing a site without connecting causes no harm. Block, report, move on.

If you connected your wallet but didn’t sign anything:
Connecting alone usually doesn’t let anyone move your funds. Disconnect the site from your wallet’s connected-sites settings, close the tab, and don’t sign anything it asks for. If you’re unsure whether you signed something, treat it as the next case.

If you signed a transaction or signature request:
Act immediately:

  1. Transfer any remaining assets to a fresh wallet with a brand-new seed phrase – speed matters more than anything else
  2. On EVM wallets like MetaMask, go to Revoke.cash and revoke all token approvals granted to unknown addresses. On Solana, drainers usually take funds inside the transaction you signed, so moving what’s left is the priority
  3. Consider that compromised wallet burned – do not continue using it as your main wallet
  4. Report the site to Netlify’s abuse team and to the real project team, and if you lost funds and you’re in the US, file a report at ic3.gov
  5. Ignore anyone who contacts you afterward offering to “recover” your funds for a fee – that’s a second scam aimed at fresh victims

Our complete crypto security guide has a fuller recovery checklist.

The Broader Lesson

In crypto, your signature is your authorization. Signing on a malicious site is the equivalent of handing someone a signed blank check. Once you sign, there is no customer service to call, no chargeback, no reversal. The blockchain doesn’t care who tricked you.

The good news: these scams are entirely avoidable once you know the pattern. And now you know it.

About hardware wallets: Keeping your main holdings on a hardware wallet like a Ledger or Trezor is still the best protection you can have – it keeps your private keys offline, so malware and fake sites can’t steal them. But it can’t stop you from approving something malicious yourself. If you connect a hardware wallet to a drainer site and confirm the request on the device, your funds can still be taken. Never connect your main wallet to a site you reached through a DM, and always read what the device screen says before you press confirm.

For more real-world scam breakdowns, see our fake Flare XRPFi airdrop investigation and the full Crypto Security hub.

Frequently Asked Questions

No legitimate project will DM you first about an unclaimed airdrop. Real airdrops are announced publicly on the project’s official website and verified social accounts, and you claim them by going to the official site yourself. A “moderator” or “support agent” messaging you about rewards is a scam every time.

Not by itself. Wallet addresses are public on the blockchain, and nobody can take your funds with just an address. But scammers ask for it to see what you hold and decide whether you’re worth targeting. The real danger starts when they send you a link to connect your wallet and sign something.

Connecting alone usually doesn’t let a site move your funds. The danger is the transaction or signature request that follows, which can authorize a contract to spend your tokens. Some of these look like a harmless message to sign. If you connected to a suspicious site, disconnect it and don’t sign anything it asks for.

Partly. A hardware wallet keeps your private keys offline, so malware and fake sites can’t steal them. But if you connect it to a drainer site and confirm a malicious request on the device, your funds can still be taken. Always read what the device screen shows before confirming, and never connect your main wallet to a site you reached through a DM.

Move any remaining assets to a brand-new wallet with a new seed phrase immediately. On EVM wallets like MetaMask, revoke unknown token approvals using Revoke.cash. Stop using the compromised wallet, report the scam site and account, and if you lost funds in the US, file a report at ic3.gov. Ignore anyone offering to recover your funds for a fee.

Scam bots and operators monitor token hashtags and new posts in real time. A new account posting about a specific token signals that you probably hold it and may be new to crypto. They send the same script to as many accounts as possible, counting on a small percentage to click.

📖 In This Section Wallet Drainer Approvals · Discord & Telegram Scams · Complete Security Guide

← Back to Crypto Security

📬 Want to be notified when new airdrops go live? Join our free Airdrop Alerts list – no spam, unsubscribe anytime.

Real Scam Dissected · Evaluate Projects . Airdrops Guide · Active Airdrops List

Similar Posts