This guide is educational, not financial advice. An airdrop is not guaranteed, and a token may have no market or utility. Verify every claim step through the project’s current first-party documentation.
An airdrop is a distribution defined by a particular project. The project decides who qualifies, what is distributed, when a claim opens, and which network or contract is used. “Farming” activity—using an app, completing tasks, providing liquidity, or referring users—does not create a right to receive anything unless the project explicitly says so.
What eligibility means
Eligibility can be based on a snapshot, an on-chain action, a Telegram account event, a points record, or a combination of rules. A project can exclude duplicate, automated, sanctioned, or suspicious activity. It may change criteria before a claim if its published terms allow that.
Do not infer eligibility from a points balance, a channel post, a wallet connection, or another user’s result. A claim page should identify the project, the network, the distribution contract, the claim window, and any required transaction. If those details are missing, wait.
The verification workflow
1. Verify the announcement
Start from the project’s official website or documentation and follow its Telegram channel or bot link. Compare the exact username and domain. A forwarded message, search result, copied logo, or directory listing is not a first-party announcement.
Open the same announcement through more than one official route when possible. Check publication time, edits, linked documents, and whether the instructions describe the same network and contract. Do not rely on an image capture.
2. Verify the domain
Read the address bar character by character. Watch for look-alike domains, shortened links, unexpected redirects, and a page that asks you to log in again. If a claim site is not linked from the project’s official documentation, do not connect a wallet.
Telegram Mini Apps are web applications, not a guarantee of publisher identity. Read the official Mini Apps documentation and use the internal Mini Apps guide for the domain and permission checklist.
3. Verify the contract and network
Copy the token or claim contract from the project’s first-party documentation. Compare it with an independent explorer and the wallet prompt. Confirm network, contract address, token standard, claim method, and administrator controls where available. A token name or ticker is not a unique identifier.
For TON, inspect the address and resulting messages in Tonviewer. A claim transaction may call more than one contract. Read the destination, payload, attached TON, and any token transfer in the wallet before signing.
4. Separate connection, signature, and transaction
These are different events:
- Wallet connection: the app learns a public address and may request account context.
- Signature: the wallet authorizes a message or typed data.
- Transaction: the network records a state change, such as a transfer or contract call.
A connection does not grant an app permission to spend funds. A signature can authorize an unsafe action, and a successful transaction can still be the wrong transaction. Reject an unrelated NFT transfer, unlimited approval, or a request for a recovery phrase.
The TON Connect documentation explains wallet connections. Its presence does not certify the claim site.
Use a separate wallet
Create a separate wallet for unfamiliar claims and keep only what is needed for network fees. Do not connect a wallet that stores long-term assets or valuable NFTs. Keep the recovery phrase offline and never enter it into a claim page, bot, support chat, or browser extension.
After the claim attempt, disconnect the app and review active connections and permissions. If the wallet supports revocation, remove permissions you no longer need. A disconnect may not undo a transaction already signed; inspect the transaction in an explorer.
For custody and recovery practices, see the TON wallet setup guide.
Assess time, cost, and privacy
Before completing tasks, write down what data and permissions are required. Consider the time spent, network fees, platform fees, lockups, and opportunity cost without assuming that any token will be received or retain value. Do not deposit funds solely to “unlock” eligibility.
Read the project’s terms and privacy policy. A task may require a Telegram username, wallet address, referral activity, device data, or interaction with a third-party service. Understand whether the data is public, retained, shared, or used to exclude participants.
Sybil and anti-abuse rules
Projects may use anti-Sybil analysis to remove wallets that appear coordinated or automated. Do not create multiple accounts to bypass rules, buy an identity, or use scripts that violate the terms. Such activity can expose more wallets and personal data while still producing no allocation.
Terms can distinguish genuine usage from repetitive low-value actions. If the project does not publish how eligibility is determined, treat all “farming strategy” claims as speculation.
Claim safely
When an official claim window opens:
- verify the URL and contract again;
- connect the separate wallet only if the app needs it;
- read the full wallet request, including destination, asset, value, payload, and deadline;
- reject any request unrelated to the stated claim;
- save the transaction hash and inspect the result in an independent explorer;
- disconnect the app after the task.
A legitimate claim may require a network fee, but a fee request does not prove legitimacy. Never send funds to a private address to “activate,” “verify,” or “release” a reward. Never pay a recovery service to reverse a failed claim.
Phishing and fake support
Fake airdrops often use urgency, celebrity endorsements, copied branding, or an apparent support account. A support agent will not need your recovery phrase or one-time Telegram code. Close unsolicited chats and open support through the project’s official website.
The Telegram scam verification guide explains identity, domain, contract, and evidence checks. The FTC cryptocurrency scam guidance covers common consumer fraud patterns.
Revoke and respond to compromise
If you connected to a suspicious site, disconnect it and review permissions. If you signed an unexpected transaction, save the hash, inspect the result, and move remaining assets to a new wallet if the signing device or recovery phrase may be exposed.
If the recovery phrase was entered anywhere, treat the wallet as compromised. Create a new wallet from a clean environment and do not reuse the exposed phrase. Secure the Telegram account, terminate unknown sessions, and enable two-step verification.
Preserve the bot username, channel link, claim URL, original message link, timestamps, contract address, wallet addresses, and transaction hashes. Keep original exports unchanged and redact secrets from copies. Report suspicious messages through Telegram’s in-app controls and to the relevant service or authority.
What an airdrop does not promise
Eligibility does not promise a particular amount, token value, listing, liquidity, or future distribution. A project can stop a campaign, change its terms, or discover that a contract has a vulnerability. Treat an airdrop as an optional verification exercise, not as income.