Threat Overview
The WalletConnect Token (WCT) Airdrop Scam is a phishing attack posing as a legitimate WalletConnect and Web3Inbox giveaway. It lures users into connecting their crypto wallets, then silently drains all funds via an automatic smart-contract transaction once the wallet is connected.
Threat Details at a Glance
Item | Details |
---|---|
Threat type | Cryptocurrency drainer / Phishing / Scam |
Disguise | Fake WalletConnect & Web3Inbox airdrop site |
Detection names | Emsisoft (Phishing), Ermes (Phishing), Certego (Suspicious), Fortinet (Spam) |
Associated domain | airdrop.wallet‑connect[.]io |
Symptoms | Wallet prompt appears; funds disappear after connecting |
Damage & distribution | Full loss of crypto funds; distributed via spam emails, pop-ups, rogue sites |
Danger level | Very high – irreversible monetary loss |
Removal tool | SpyHunter – Download SpyHunter |
Scam Workflow & Evidence
How I got infected
Users often receive this scam via spam emails or pop-up ads claiming they’re invited to a special airdrop. The email typically contains enticing language, such as:
“We hope this email finds you well… exclusive celebration… team at WalletConnect, in collaboration with Web3Inbox…”
Clicking “Join & Claim!” brings users to a realistic-looking site prompting wallet connection.
What exactly it does
Once a user approves the wallet connection, the site executes a draining script, automatically transferring all assets out of the wallet. Cryptocurrency transactions are irreversible—funds are lost permanently.
Should you be worried?
Yes. This scam can wipe out entire crypto holdings in seconds. Even experienced users can fall for it if they are not cautious during the wallet connection process.
Fake Site Text
The fraudulent site displays the following message:
Welcome to the Web3Inbox Airdrop
Connect your wallet to receive the exclusive Airdrop brought to you by – WalletConnect and Web3Inbox.
Connect Wallet
These messages are carefully crafted to appear legitimate and to pressure users into connecting their wallet quickly without checking authenticity.
Threat Evaluation
This phishing scam is especially dangerous due to its use of familiar branding and seamless imitation of legitimate WalletConnect interfaces. It preys on users’ trust and excitement over crypto giveaways. A single click on “Connect Wallet” is all it takes for a smart contract to initiate and transfer funds out of your wallet.
Removing any browser extensions or scripts used to distribute this scam and scanning the system with SpyHunter is strongly advised. If you connected your wallet, transfer assets to a new wallet, revoke approvals, and monitor transactions closely.
Dealign with Crypto Scams – Method 1: Manual Removal Guide
Follow these steps to manually remove crypto scams and protect your system.
Step 1: Identify the Crypto Scam Source
- Check if you’ve been contacted by a scammer through email, Telegram, Discord, WhatsApp, or social media.
- Identify any malicious software installed on your system, such as fake wallet apps or browser extensions.
- Scan your browser history and emails for phishing links.
Step 2: Report and Freeze Crypto Transactions (If Possible)
- Contact your crypto exchange immediately if you suspect fraud.
- Check if your transaction is pending (some blockchains allow canceling or replacing a transaction).
- Report the scam to authorities such as:
Step 3: Remove Malicious Software and Fake Wallet Apps
- Windows Users:
- Open Control Panel > Programs and Features
- Look for unknown apps related to crypto wallets or trading bots.
- Click Uninstall.
- Mac Users:
- Open Finder > Applications
- Locate suspicious apps and drag them to the Trash.
- On Mobile (Android & iOS):
- Go to Settings > Apps (Android) or General > iPhone Storage (iOS).
- Uninstall any unrecognized crypto wallet apps.
Step 4: Clear Browser Data and Remove Malicious Extensions
- Google Chrome:
- Go to chrome://extensions/
- Remove unfamiliar or suspicious extensions.
- Firefox, Edge, Safari:
- Open settings and remove unauthorized extensions.
- Clear Cache & Cookies:
- Open browser settings → Privacy → Clear browsing data
Step 5: Reset Passwords & Enable Two-Factor Authentication (2FA)
- Change passwords for your crypto exchanges, wallets, and emails.
- Use a strong, unique password for each account.
- Enable 2FA on all critical accounts (Google Authenticator or YubiKey recommended).
Step 6: Scan for Malware and Keyloggers
Even if you removed software manually, some malware can still lurk in your system. Use a security tool to perform a deep scan (see SpyHunter method below for an automatic removal process).
Step 7: Monitor Your Accounts & Funds
- Track your crypto wallet transactions using Etherscan or Blockchain Explorer.
- Keep an eye on email login alerts from suspicious locations.
- Use a hardware wallet (Ledger, Trezor) for better security.
Method 2: Automatic Removal Using SpyHunter
For a fast and reliable way to remove crypto scam-related malware, use SpyHunter.
Step 1: Download SpyHunter
Step 2: Install SpyHunter
- Run the SpyHunter setup file.
- Follow the on-screen installation steps.
- Open SpyHunter once installed.
Step 3: Perform a Full System Scan
- Click on "Start Scan Now" to analyze your system.
- Wait for the scan to detect crypto scam malware, spyware, keyloggers, and phishing trojans.
Step 4: Remove Threats Automatically
- Click "Fix Threats" after the scan completes.
- SpyHunter will eliminate malware, fake apps, and browser hijackers.
Step 5: Protect Your System from Future Crypto Scams
- Enable SpyHunter's Real-Time Protection to block phishing sites and prevent future infections.
- Regularly scan your system for new threats.
Prevention Tips: How to Avoid Crypto Scams in the Future
- Always verify website URLs before logging into exchanges or wallets.
- Avoid unsolicited investment offers on Telegram, Discord, and email.
- Never share your private keys or recovery phrases with anyone.
- Use a hardware wallet instead of online wallets.
- Regularly update your antivirus and anti-malware software.
- Be skeptical of high-return crypto investment schemes.
Conclusion
The WalletConnect Token (WCT) Airdrop Scam is a dangerous phishing scheme targeting cryptocurrency users. It exploits the trust built around WalletConnect and airdrops to lure users into connecting their wallets to a malicious smart contract. Victims lose their funds instantly, and recovery is virtually impossible. Protect yourself by verifying URLs, never trusting unsolicited airdrop claims, and using cybersecurity tools like SpyHunter for ongoing system protection.