Skip to content

[Challenge Submission] <"Free Airdrop" Token Trap> #1

Description

@syed-ghufran-hassan

📌 Challenge Overview

Challenge Title:
"Free Airdrop" Token Trap

Difficulty Level:

  • Beginner
  • Intermediate
  • Advanced

Description / Scenario:
The user visits a fake "airdrop claim" site promoted via social media. The site promises free tokens for connecting a wallet and clicking "Claim Airdrop." However, the claim action triggers a malicious contract call requesting unlimited token approvals.

Learning Objective:
Learn to identify suspicious token claim pages, verify token approval requests before signing, and always double-check URLs and contract interactions.

Phishing Technique Used:

  • Approval bait using a fake airdrop dApp

  • Fake token claim with misleading transaction purpose

  • Uses common web3 wallet prompts to build trust (e.g., mimicking real claim flows)

📸 Screenshots / Demo

Image Image

🪙 Reward Wallet Address (USDT - ERC20 Polygon/Arbitrum)

(Required if accepted for the 30 USDT reward)

0x2B602d2f559a0bADf4D5956D03f2b330fBC2e9F9


✅ By submitting this challenge, I agree to open-source it under the project's license and allow the Unphishable team to modify or improve it for consistency.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions