{
  "$schema": "https://degreesofsatoshi.com/encyclopedia/schemas/article-v1.json",
  "schemaVersion": "1.0.0",
  "id": "unsolicited-tokens-and-nfts",
  "canonical": "https://degreesofsatoshi.com/encyclopedia/unsolicited-tokens-and-nfts/",
  "collection": "ethereum",
  "title": "Unexpected tokens and NFTs: what does receiving an airdrop mean?",
  "description": "Understand why an unexpected airdrop can appear without consent and where interacting with its links or permissions creates risk.",
  "aliases": [
    "random NFT in wallet",
    "unexpected token airdrop"
  ],
  "dates": {
    "published": "2026-10-02",
    "modified": "2026-10-02",
    "verified": "2026-10-02T19:27:58.939Z",
    "dataAsOf": "2026-10-02"
  },
  "authorship": {
    "publisher": "Degrees of Satoshi editorial project",
    "process": "AI-assisted research and drafting with a separate automated source-verification pass; no external expert or named human review is implied."
  },
  "quickAnswer": {
    "text": "An unknown token or NFT can be sent to your public address without your consent. Its appearance is not evidence that someone knows your private key or that a reward is legitimate. The danger often begins when its name, image or website persuades you to reveal secrets, sign an authorization or approve access to valuable assets.",
    "claimId": "unsolicited-tokens-and-nfts-quick-answer",
    "sourceIds": [
      "x425-eth-mm-airdrops",
      "x425-eth-eth-security",
      "x425-eth-erc721"
    ]
  },
  "keyFacts": [
    {
      "label": "Receipt",
      "value": "Receiving an unsolicited NFT does not require an ordinary wallet login.",
      "sourceIds": [
        "x425-eth-mm-airdrops",
        "x425-eth-erc721"
      ],
      "id": "receipt",
      "claimId": "unsolicited-tokens-and-nfts-fact-receipt"
    },
    {
      "label": "Bait",
      "value": "Airdrop metadata can direct recipients to phishing sites.",
      "sourceIds": [
        "x425-eth-mm-airdrops"
      ],
      "id": "bait",
      "claimId": "unsolicited-tokens-and-nfts-fact-bait"
    },
    {
      "label": "Hiding",
      "value": "An interface can hide an asset without transferring it.",
      "sourceIds": [
        "x425-eth-mm-tokens"
      ],
      "id": "hiding",
      "claimId": "unsolicited-tokens-and-nfts-fact-hiding"
    }
  ],
  "prerequisites": [
    "ethereum-wallet-requests"
  ],
  "sections": [
    {
      "id": "appearance",
      "heading": "A wallet list is not a list of trusted senders",
      "sourceIds": [
        "x425-eth-mm-airdrops"
      ],
      "paragraphs": [
        "Public addresses can receive unsolicited assets. A token name that claims a prize, a support alert or an expiring reward is information supplied by its creator, not an authenticated message from the wallet provider.",
        "Do not infer value from a displayed price. The scam can rely on getting you to visit a redemption page even when the unexpected item itself is worthless."
      ]
    },
    {
      "id": "example",
      "heading": "The costly step can involve a different collection",
      "sourceIds": [
        "x425-eth-mm-airdrops",
        "x425-eth-erc721"
      ],
      "paragraphs": [
        "Imagine an unsolicited NFT whose image says “claim your reward.” The linked page requests operator approval over a collection you already own. That approval concerns the valuable collection, even though the page introduced itself through the unrelated airdrop.",
        "Read which contract and operator a request affects. The fact that the initial item arrived for free does not make the follow-up authorization harmless."
      ]
    },
    {
      "id": "response",
      "heading": "Ignoring the bait can be enough",
      "sourceIds": [
        "x425-eth-mm-airdrops",
        "x425-eth-mm-tokens",
        "x425-eth-eth-security"
      ],
      "paragraphs": [
        "If you have only received the asset, avoid its links and use supported hide or spam-report controls where available. You do not need to send it to a special cleanup address to regain control of your wallet.",
        "If you already approved or signed something, inspect that specific authorization and affected assets. Merely hiding the original airdrop does not revoke permissions granted to another contract."
      ]
    }
  ],
  "faq": [
    {
      "question": "Does an unexpected NFT prove my wallet was hacked?",
      "answer": "No. Passive receipt is possible at a public address. Investigate outgoing transactions and authorizations separately from the unsolicited item’s presence.",
      "sourceIds": [
        "x425-eth-mm-airdrops"
      ]
    },
    {
      "question": "Should I visit its website to remove it?",
      "answer": "An unsolicited asset’s website is not a trusted cleanup service. Use the wallet’s own display controls and independently verified permission tools when relevant.",
      "sourceIds": [
        "x425-eth-mm-airdrops",
        "x425-eth-eth-security"
      ]
    }
  ],
  "claims": [
    {
      "id": "unsolicited-tokens-and-nfts-quick-answer",
      "articleSlug": "unsolicited-tokens-and-nfts",
      "statement": "An unknown token or NFT can be sent to your public address without your consent. Its appearance is not evidence that someone knows your private key or that a reward is legitimate. The danger often begins when its name, image or website persuades you to reveal secrets, sign an authorization or approve access to valuable assets.",
      "sourceIds": [
        "source-de5bad1c1751e718",
        "source-83ec2d5a18d94ce1",
        "source-b08b9aae11ea4085"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-de5bad1c1751e718",
          "locator": "Airdrop scams; unsolicited tokens"
        },
        {
          "sourceId": "source-83ec2d5a18d94ce1",
          "locator": "Wallet security; common scams; hardware wallets"
        },
        {
          "sourceId": "source-b08b9aae11ea4085",
          "locator": "safeTransferFrom; approve; setApprovalForAll; Transfer; metadata"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Fresh MetaMask airdrop guide confirms unsolicited delivery and malicious metadata links. Source ethereum.org contains an erroneous approval-exposes-private-keys sentence, which the draft correctly does not reproduce. Approval example checked against ERC721 separately; hiding does not revoke a contract permission."
        ]
      }
    },
    {
      "id": "unsolicited-tokens-and-nfts-fact-receipt",
      "articleSlug": "unsolicited-tokens-and-nfts",
      "statement": "Receipt: Receiving an unsolicited NFT does not require an ordinary wallet login.",
      "sourceIds": [
        "source-de5bad1c1751e718",
        "source-b08b9aae11ea4085"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-de5bad1c1751e718",
          "locator": "Airdrop scams; unsolicited tokens"
        },
        {
          "sourceId": "source-b08b9aae11ea4085",
          "locator": "safeTransferFrom; approve; setApprovalForAll; Transfer; metadata"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Fresh MetaMask airdrop guide confirms unsolicited delivery and malicious metadata links. Source ethereum.org contains an erroneous approval-exposes-private-keys sentence, which the draft correctly does not reproduce. Approval example checked against ERC721 separately; hiding does not revoke a contract permission."
        ]
      }
    },
    {
      "id": "unsolicited-tokens-and-nfts-fact-bait",
      "articleSlug": "unsolicited-tokens-and-nfts",
      "statement": "Bait: Airdrop metadata can direct recipients to phishing sites.",
      "sourceIds": [
        "source-de5bad1c1751e718"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-de5bad1c1751e718",
          "locator": "Airdrop scams; unsolicited tokens"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Fresh MetaMask airdrop guide confirms unsolicited delivery and malicious metadata links. Source ethereum.org contains an erroneous approval-exposes-private-keys sentence, which the draft correctly does not reproduce. Approval example checked against ERC721 separately; hiding does not revoke a contract permission."
        ]
      }
    },
    {
      "id": "unsolicited-tokens-and-nfts-fact-hiding",
      "articleSlug": "unsolicited-tokens-and-nfts",
      "statement": "Hiding: An interface can hide an asset without transferring it.",
      "sourceIds": [
        "source-85b8c7c22a802fdd"
      ],
      "sourceLocators": [
        {
          "sourceId": "source-85b8c7c22a802fdd",
          "locator": "Enhanced detection; custom tokens; hiding tokens"
        }
      ],
      "scope": {
        "collection": "ethereum",
        "dataAsOf": "2026-10-02",
        "blockHeight": null
      },
      "qualification": "",
      "evidenceStatus": "documented",
      "verification": {
        "status": "verified",
        "method": "independent automated source review",
        "checkedAt": "2026-10-02T19:27:58.939Z",
        "reviewer": "Independent automated verification agent verify_bitcoin_stablecoins_100",
        "notes": [
          "Fresh MetaMask airdrop guide confirms unsolicited delivery and malicious metadata links. Source ethereum.org contains an erroneous approval-exposes-private-keys sentence, which the draft correctly does not reproduce. Approval example checked against ERC721 separately; hiding does not revoke a contract permission."
        ]
      }
    }
  ],
  "sources": [
    {
      "id": "x425-eth-mm-airdrops",
      "label": "Airdrop phishing scams",
      "publisher": "MetaMask",
      "url": "https://support.metamask.io/stay-safe/protect-yourself/nfts/nft-airdrop-scams/",
      "locator": "Airdrop scams; unsolicited tokens",
      "note": "Unsolicited-token links and permissions create risks distinct from passive receipt.",
      "version": "Documentation snapshot retrieved 2 October 2026; response hash recorded separately",
      "checkedAt": "2026-10-02T18:55:24.143Z",
      "contentSha256": "711a15a9407a15296269b55e24910af7c9f6732a693ae3dcfcad4a1446941997",
      "recordId": "source-de5bad1c1751e718"
    },
    {
      "id": "x425-eth-eth-security",
      "label": "Ethereum security and scam prevention",
      "publisher": "ethereum.org contributors",
      "url": "https://ethereum.org/en/security/",
      "locator": "Wallet security; common scams; hardware wallets",
      "note": "Primary community guidance on wallet secrets, phishing, malicious sites and transaction checking.",
      "version": "Documentation snapshot retrieved 2 October 2026; response hash recorded separately",
      "checkedAt": "2026-10-02T18:55:24.140Z",
      "contentSha256": "1372ff086ae3f53ded99c8dfe308346a457574d41c04dc587de119a64080b448",
      "recordId": "source-83ec2d5a18d94ce1"
    },
    {
      "id": "x425-eth-erc721",
      "label": "ERC-721 NFT standard",
      "publisher": "Ethereum Improvement Proposals",
      "url": "https://eips.ethereum.org/EIPS/eip-721",
      "locator": "safeTransferFrom; approve; setApprovalForAll; Transfer; metadata",
      "note": "Ownership, receiver checks, token-level and operator approvals, mint/burn event semantics.",
      "version": "ERC-721",
      "checkedAt": "2026-10-02T18:55:25.399Z",
      "contentSha256": "bedd672103f3ebb6803ce2bddb33a9ff3d23b08e8e3ae3173b6a5b016f65e2a1",
      "recordId": "source-b08b9aae11ea4085"
    },
    {
      "id": "x425-eth-mm-tokens",
      "label": "Displaying tokens in MetaMask",
      "publisher": "MetaMask",
      "url": "https://support.metamask.io/manage-crypto/tokens/how-to-display-tokens-in-metamask",
      "locator": "Enhanced detection; custom tokens; hiding tokens",
      "note": "Wallet display and token contract identity are separate from onchain holdings.",
      "version": "Documentation snapshot retrieved 2 October 2026; response hash recorded separately",
      "checkedAt": "2026-10-02T18:55:24.137Z",
      "contentSha256": "175816d8d6f117fbbe963b8005cd04b9a2757ed1c45ad4142a88f32bfce31d67",
      "recordId": "source-85b8c7c22a802fdd"
    }
  ],
  "related": {
    "articles": [
      "ethereum-token-approvals",
      "erc-721-nfts",
      "ethereum-wallet-requests",
      "ethereum-tokens-not-showing",
      "wallet-phishing-websites"
    ],
    "dossiers": [],
    "wallets": []
  },
  "revisionHistory": [
    {
      "date": "2026-10-02",
      "kind": "published",
      "summary": "First publication after primary-source research and separate automated verification."
    }
  ],
  "citation": "Degrees of Satoshi editorial project. “Unexpected tokens and NFTs: what does receiving an airdrop mean?.” Published 2026-10-02; updated 2026-10-02. https://degreesofsatoshi.com/encyclopedia/unsolicited-tokens-and-nfts/"
}
