We use technologies like cookies to store and/or access device information. We do this to improve browsing experience and to show (non-) personalized ads. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Техническое хранение или доступ необходимы для законной цели хранения предпочтений, которые не запрошены подписчиком или пользователем.
The technical storage or access that is used exclusively for statistical purposes.
Техническое хранилище или доступ, который используется исключительно для анонимных статистических целей. Без повестки в суд, добровольного согласия со стороны вашего интернет-провайдера или дополнительных записей от третьей стороны информация, хранящаяся или полученная только для этой цели, обычно не может быть использована для вашей идентификации.
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
#Tutorial. An unknown token or NFT appeared in your wallet: what to do
An unknown token or NFT appeared in your wallet with a reward offer or a link to a website? Receiving an asset like this does not usually mean your wallet has been compromised: an incoming transfer does not require your signature and does not give the sender permission to spend other assets from your address.
In short: do not interact with the asset → check it in a blockchain explorer → hide it or mark it as spam → review permissions only if you have already connected your wallet to a suspicious website or signed something.
1. Do not interact with an unknown token or NFT
Do not open links from the asset’s name, description, or image, do not start a claim, and do not try to sell or swap it through a website mentioned in the token or NFT itself.
A spam token or NFT is often designed simply to lead you to a phishing page where an attacker can request a signature, token permission, or your seed phrase. If you have not approved anything, receiving the asset itself does not create an approve, Permit, or Permit2 permission.
2. Check the unknown token or NFT in a blockchain explorer
Open the transaction in the appropriate network explorer and check the sender address, token contract or NFT mint address, transfer time, and any available spam warnings. You do not need to connect your wallet to a third-party website or sign a transaction to do this.
If the asset claims to be associated with a known project or an airdrop, do not use the link embedded in the token itself. Open the project’s official website or documentation independently and verify the contract or mint address. To learn more about how token distributions work and the risks involved in claiming them, see our guide to Perp DEX and airdrops.
3. Hide the asset or report it as spam
Most popular wallets let you hide an unwanted token or NFT or report it as spam. The exact name of the option depends on the wallet and app version.
Hiding an asset only changes what you see in that particular interface. The asset remains on-chain and may still appear in another wallet, blockchain explorer, or portfolio tracker. There is no need to remove it from the blockchain.
4. What to do if you already opened the website or signed something
You only opened the website
If you did not sign anything, enter sensitive information, download files, or install extensions, simply viewing the page does not create permission to spend your funds. Close the tab and do not continue interacting with the website.
You connected your wallet but did not sign anything
Disconnect the website from the wallet’s connected apps list. Connecting a wallet allows the page to see the selected address and send transaction or signature requests, but it does not create a token approval by itself.
You signed a transaction or message you do not understand
In this situation, do not spend too much time investigating before protecting your assets. Move your most valuable funds to another wallet that has never interacted with the suspicious website as quickly as possible, and revoke or cancel any known approvals or orders using a trusted tool.
Do not rely only on what you see in a blockchain explorer. Permit, Permit2, and some other off-chain signatures may leave no on-chain record until they are actually used. The absence of a new transaction therefore does not prove that the signature was safe.
You entered your seed phrase or private key
Treat the old wallet as fully compromised. Create a new wallet with a new seed phrase on a trusted device and move any assets that can still be recovered.
If tokens remain on the old address but there is no ETH, SOL, or other native coin available for transaction fees, do not blindly top it up. A sweeper bot may be monitoring the compromised address and automatically take incoming funds. If a significant amount is at stake, consider professional recovery assistance without sharing your seed phrase with anyone.
The funds have already been sent
Save the TxID, addresses, timestamps, the phishing website domain, and screenshots. If the assets reach a centralized exchange, contact its support team as quickly as possible — in some cases, there may still be a chance to stop the funds before they are withdrawn again.
In Ukraine, you can also file a report through the official Cyberpolice portal. You should not expect the police to recover stolen crypto quickly, but formally documenting the incident and providing TxIDs, addresses, and other evidence can still be useful.
5. If a zero-value or unusual transfer appears in your history
A zero-value or very small transfer involving a similar-looking address may be part of an address poisoning attack. The attacker inserts an address into your transaction history that resembles one you have used before, hoping you will copy the fake address the next time you send funds.
Such an entry does not by itself mean that funds were stolen. Check the actual balance change and the TxID in a blockchain explorer.
Do not use transaction history as the source of a recipient address. For important transfers, obtain the address from a trusted source or saved contact and verify it in full. Even a successful test transfer does not protect you if you copy the address from an already poisoned transaction history before sending the main amount.
6. Should you delete or burn an unknown token?
Usually, no. You cannot remove a past record from the blockchain, and simply hiding an ordinary spam token in your wallet is generally enough.
Sending or burning the token requires an on-chain transaction and a network fee. Doing so does not by itself give the token access to your other assets, but there is usually little practical reason to interact with it just to keep your wallet interface tidy. In particular, avoid third-party “wallet cleaning” services that could replace the expected action with an approval request or another dangerous signature.
FAQ
Can an unknown token or NFT steal funds by itself?
No. Simply receiving the asset does not give the sender permission to spend other funds from your address. The risk begins if you approve a malicious transaction or signature, or expose your seed phrase or private key.
Should I revoke all approvals immediately?
No. Receiving a spam token does not create an approval by itself. Review permissions after a suspicious dApp interaction or periodically if you are an active DeFi user.
If I hide the token, is it gone permanently?
No. Hiding only affects a particular wallet app or profile. The asset remains on-chain and may still appear in other interfaces.
Can a hardware wallet be “infected” by a spam NFT?
No. Simply receiving an NFT does not install code on a hardware wallet or expose its private keys. The risk comes from approving a malicious action or disclosing sensitive recovery information.
How to protect yourself from these scams
Related Posts
#Trezor tutorial. Trezor passphrase wallet is empty: why it happens and how to find your coins
Trezor passphrase wallet: a common situation is that you connect your Trezor, enter the passphrase, and see a zero balance with no transaction history in Trezor Suite. Your first thought may be that the coins have been stolen. In most cases, the funds are still there—you have simply opened a different wallet. Below, we explain …
#Safepal tutorial. SafePal S1 not detecting upgrade.bin: causes and fixes
SafePal S1 not detecting upgrade.bin? You downloaded the firmware, copied the file to the device and selected “Upgrade,” but the S1 says that it cannot find the firmware file. Or the update simply does not start. In most cases, this does not mean that the device is faulty or that the file is corrupted. The …
#Ledger tutorial. How to Use Ledger as a Security Key for Crypto Exchanges
Your Ledger can do more than sign crypto transactions. You can install the dedicated Security Key app and use the device as a physical security key for accounts such as email, GitHub, password managers, and crypto exchanges. In this guide, we’ll show you how to use Ledger as a security key for a crypto exchange, …
#Tutorial. Can’t send USDT from your wallet? What to do
Can’t send USDT from your wallet even though the token is showing in your balance? The problem is usually related to network fees, the address you are sending from, or an earlier transaction that is still pending. Start by checking the blockchain instead of changing wallet settings at random. In short: network and address → …