Skip to blog content

    Quality Crypto Reporting · Primary Sources Researched

    CryptoWorkPro

    Market context

    Powered by CoinStats APIUpdated 2:49 AM

    BTC-0.27%
    $84,677
    ETH-1.00%
    $2,682
    XRP-0.45%
    $1.49
    SOL-0.38%
    $119.07
    BNB-0.44%
    $768.82
    HBAR-1.38%
    $0.1014
    QNT+1.94%
    $256.79
    TRX-0.20%
    $0.3336
    LINK-2.58%
    $13.93
    XLM-1.52%
    $0.2157
    Back to Blog
    NFTs

    A Free NFT Just Appeared in Your Wallet. Do Not Click It.

    Published September 20, 2026

    An unsolicited NFT can be bait. Official FBI, MetaMask, Magic Eden, and OpenSea pages say not to follow its links or sign anything.

    A Free NFT Just Appeared in Your Wallet. Do Not Click It.

    You open your wallet and a new NFT is sitting there. You never bought it. You never asked for it. The picture or the text on the token tells you to visit a site, claim a reward, or sign a message.

    That token can be bait. Official pages from the FBI, MetaMask, Magic Eden, and OpenSea all say the same core thing: do not follow unsolicited NFT links, and do not sign anything those links ask you to sign.

    What an unsolicited NFT is

    An NFT is a unique token on a blockchain. Anyone who knows a public wallet address can send one there. Receiving it does not mean you asked for it, and it does not mean a marketplace or a wallet company sent it.

    The risk is not the token sitting in the list. The risk is what happens if you click the link, connect your wallet, share a seed phrase, or approve a transaction.

    What the official pages say

    On June 3, 2025, the FBI's Internet Crime Complaint Center posted public service announcement PSA250603. The notice is written for people using non-custodial wallets on the Hedera Hashgraph network. It says criminals exploit an airdrop feature that was built for marketing, disguising the send as a free reward.

    The FBI describes a Hedera-specific method: after an unsolicited token arrives, a plaintext memo can include a URL. That URL may lead to a third-party site or decentralized app that asks for login details or a seed phrase. The same notice also describes phishing on social media, third-party websites, and emails that offer fake airdrop tokens. If you click and connect, the criminal can move crypto out of the wallet.

    The FBI's Hedera memo method is not a claim about every blockchain. The phishing-URL pattern is. Treat the Hedera section as Hedera, and treat the social, website, and email section as the wider warning the notice actually gives.

    MetaMask's NFT airdrop scam page describes the same bait in wallet terms. A scammer sends one or more NFTs. The image or the metadata points you to a malicious site. On that site, the usual asks are your Secret Recovery Phrase or private key, or a signature that can drain the wallet or selected assets. MetaMask's test is simple: if you did not expect the NFT, do not interact with it and do not follow its instructions. The company also says scam NFTs can look convincing, so design quality is not a safety test.

    Magic Eden published How to Spot Fake NFT Airdrops and Protect Your Wallet on July 28, 2025. It says fake airdrops may impersonate the marketplace, including a "Magic Eden" Mystery Box or similar token. Magic Eden states it will never randomly distribute a Mystery Box or any similar NFT through an airdrop. The page says clicking the description link and connecting a wallet can drain assets, and that blockchain transfers are permanent.

    OpenSea's stay-safe guide, dated April 23, 2025, tells users never to share a secret recovery phrase. OpenSea says it is not a wallet provider and will never ask for that phrase. It also says not to click unknown or broken links, to treat unexpected Instagram or Twitter direct messages as possible scams, to expect authentic OpenSea email only from the opensea.io domain, and never to sign a wallet transaction prompted from an email.

    What to do if one shows up

    Leave the token alone. Do not tap the picture, do not visit the URL in the description, and do not connect your wallet to "claim" anything.

    If you already clicked and approved a request, Magic Eden says the wallet is likely compromised, recovery is usually not possible, and you should revoke app permissions and consider moving remaining assets to a new wallet. The FBI says to contact account providers, change passwords, be wary of people who claim they can recover stolen funds, and file a report at www.ic3.gov with addresses, amounts, dates, and transaction IDs. OpenSea points MetaMask users to that wallet's own guide for reviewing smart contract approvals.

    Magic Eden notes that Phantom users can burn scam NFTs from the token menu. Burning a token is not the same as undoing a drain. Do not burn or transfer anything until you are sure you are not signing a new malicious request.

    What these pages do not settle

    Not every unexpected token is proven to be a scam. Some projects do send real airdrops. The official test is still whether you expected it and whether you can confirm it on the provider's own site, without using the token's link.

    The FBI notice does not inventory every chain or every marketplace. Wallet hide or flag tools can miss tokens. None of these pages promise that stolen assets will come back.

    What to watch next

    Watch the wallet or marketplace's own help pages, not a direct message, for any claim you did sign up for. If you think you were hit, use IC3 and the provider's official support channel. This article does not forecast scam volume or name collections.

    Sources

    1. FBI Internet Crime Complaint Center, public service announcement PSA250603, June 3, 2025: https://www.ic3.gov/PSA/2025/PSA250603
    2. MetaMask Help Center, "NFT airdrop scams": https://support.metamask.io/stay-safe/protect-yourself/nfts/nft-airdrop-scams
    3. Magic Eden Help Center, "How to Spot Fake NFT Airdrops and Protect Your Wallet," July 28, 2025: https://help.magiceden.io/en/articles/6509737-how-to-spot-fake-nft-airdrops-and-protect-your-wallet
    4. OpenSea Help Center, "How can I stay safe and protect my NFTs," April 23, 2025: https://support.opensea.io/en/articles/8867129-how-can-i-stay-safe-and-protect-my-nfts
    5. FBI Internet Crime Complaint Center, complaint intake: https://www.ic3.gov/

    Disclosure: This article describes documented airdrop-phishing methods from named official pages. It is not a complete security audit of any wallet or marketplace, and it is not a guide for recovering stolen funds. The FBI notice is focused on Hedera Hashgraph airdrop abuse and related phishing URLs; it does not catalog every chain. The featured image is a generated illustration, not a photograph of a wallet or an FBI notice. This article is not financial, legal, or investment advice. AI-assisted research and writing. Cited sources, not AI alone, support the claims.