Quick answer: if you post in Discord about a failed claim, a wallet issue, or stuck staking funds and several “support agents” immediately slide into your DMs, treat it as a high-risk scam incident. Do not engage. Freeze the interaction, preserve evidence, reopen support through the project’s official site, and identify whether the wallet prompt is asking for a login, an allowance, or an asset transfer. If you signed an Approval, Permit, Permit2, or setApprovalForAll, disconnecting the dApp is not enough—you need to inspect and revoke the on-chain permission.
During this project’s August 2026 research across Chinese-speaking Web3 Discord communities, one Almanak member reported receiving at least five unsolicited DMs after asking for help. Suspected scammers pushed users to accept private chats almost immediately. This is targeted hunting: scammers monitor phrases such as Claim Failed, Unlock, Wallet Error, Wrong Network, and Lost Access, then impersonate mods or support while the user is stressed about a deadline.
Default rule: it does not matter how convincing the avatar looks. If they DM first, rush you into a link, or ask for a wallet signature, assume scam until the User ID, URL, contract, and process are verified through an official ticket.
The first 60 seconds: contain the incident
- Do not reply: a response confirms that the account is live and gives the scammer room to apply pressure.
- Do not accept the friend request: friendship may bypass some DM filtering.
- Do not open links, files, or QR codes: including anything labeled Ticket, Sync, Verify, Migration, Refund, or Debug Tool.
- Do not connect a wallet: “just connect” still exposes the address and tees up the next signature request.
- Capture the full conversation: username, avatar, timestamps, mutual servers, links, and requested actions.
- Copy the Message Link and User ID: display names can change and are weak evidence.
- Report, then block: report the specific message so Discord receives context before blocking the sender.
- Re-enter through a trusted source: use a saved official website, X profile, or docs—not anything in the DM.
On Discord, right-click a message on desktop or long-press it on mobile to report it. Enable Developer Mode to copy the account’s User ID, which is far more useful than a cloned nickname when escalating to moderators or Discord Support.
Why scammers swarm after one public support post
Your public message reveals the protocol you are farming, the exact failure you are facing, and the fact that you may be panicking about a claim window, snapshot, unlock, or token price. A scammer repackages that information into a personalized pretext: “we found your ticket,” “your wallet session is out of sync,” “the old claim contract migrated,” or “you have two hours left to verify.” It sounds tailored because they copied the diagnosis from your own post.
Identity verification: an avatar and an Admin label prove nothing
Layer 1: Who initiated the conversation?
Check the server Rules, FAQ, and Support channels for “Staff will never DM first.” If that rule exists, an unsolicited support DM fails immediately. If it does not, still refuse to handle wallet actions in private; open your own ticket through the official server.
Be precise: Discord says Discord Staff will not contact users through the app for support. Whether a Web3 project’s team ever sends DMs depends on that project’s own published rules.
Layer 2: Verify Username, Role, and User ID
- open the full profile, not just the name above the DM;
- record Username and Display Name;
- confirm the mutual server is the official server;
- find the same account in the member list;
- verify a server-issued role, not “Admin” typed into a bio;
- enable User Settings → Advanced → Developer Mode;
- right-click or long-press the account and Copy User ID;
- send that ID through an official ticket for confirmation.
A genuine role is still not a safety guarantee—staff accounts can be compromised. The requested URL, contract, signature, and workflow must also match public documentation.
Layer 3: Force the conversation back onto an official rail
- close the DM;
- enter Discord from the project website;
- create your own Ticket or Modmail thread;
- provide only a public address, TxHash, and redacted screenshots;
- ask whether the User ID, domain, and contract are official.
If the sender says “DM only,” “tickets are under maintenance,” or “you will miss the drop if you queue,” you are being pushed off the verifiable path.
15 red flags of fake Web3 support
| DM or behavior | Real objective | Response |
|---|---|---|
| Claims to be support and DMs first | Borrow authority | Verify User ID in a ticket |
| Creates a minutes-long deadline | Stop you cross-checking | Pause and read announcements |
| Sends Sync/Rectify/Validate Wallet | Trigger a connection, signature, or seed entry | Do not open; report and block |
| Sends a short link, QR, ZIP, or executable | Hide the domain or deliver malware | Do not scan, download, or run |
| Asks for seed/private key/keystore | Take the entire wallet | Terminate contact immediately |
| Requests screen share or remote desktop | View secrets or operate the wallet | Never grant access |
| Asks you to paste code into Console or PowerShell | Steal Discord tokens, cookies, or sessions | Never run unknown code |
| Requests gas, deposit, verification, or unfreeze fee | Direct payment | Never send funds to a personal address |
| An airdrop claim requests Token Approval | Obtain an ERC-20 allowance | Reject unnecessary or unlimited access |
| An NFT claim requests setApprovalForAll | Control the whole collection | Reject the request |
| Requests an unreadable Permit/Permit2 | Obtain spending rights by signature | Check spender, amount, token, deadline |
| Uses a one-letter typo or look-alike Unicode domain | Impersonate the official site | Reopen from a bookmark |
| Bio says Admin but there is no server role | Fake identity | Trust server roles and tickets, not bios |
| Tells you to disable wallet security alerts | Bypass simulation and phishing warnings | Stop on a Malicious warning |
| Promises eligibility recovery or early unlock | Run a recovery scam | Follow only protocol rules |
URL checklist: HTTPS does not mean the site is legit
- do not click directly from a DM;
- identify the registrable domain from right to left;
- look for misspellings, hyphens, and Unicode homographs;
- avoid shortened URLs that hide the destination;
- recheck the address bar after every redirect;
- cross-check the website, official X account, and Discord announcement;
- verify the contract and spender—the right domain can still surface the wrong contract;
- bookmark official entry points and avoid search ads.
A QR code is a link in disguise. Discord also recommends avoiding unverified QR codes, unsolicited programs, and code you do not understand.
Wallet prompt risk ladder: Connect, Sign, and Approve are different
| Request | What it can authorize | In a suspicious DM flow |
|---|---|---|
| Connect Wallet | Reveals address, balances, and network; enables follow-up requests | Close and disconnect |
| Login signature / SIWE | Creates a session; domain, URI, nonce, statement, and expiry matter | Reject any mismatch |
| personal_sign | Signs an arbitrary message; not automatically harmless | If you cannot explain it, reject it |
| eth_signTypedData | May sign an order, Permit, Permit2, or structured authorization | Inspect spender, token, amount, deadline |
| ERC-20 Approval | Lets a spender pull tokens through transferFrom | Avoid unnecessary or unlimited allowances |
| Permit / Permit2 | Grants spending rights by signature, sometimes before any tx appears | “Gasless” does not mean safe |
| setApprovalForAll | Lets an operator manage all NFTs from a collection | An NFT claim rarely needs this |
| Transfer / Multicall | Changes on-chain state and may bundle multiple actions | Read the simulation and every call |
| Seed phrase / Private key | Permanently controls the wallet and derived accounts | Never provide it |
MetaMask is explicit: a token approval is not the same as a wallet connection. Disconnecting a dApp does not erase an existing allowance. Permit, Permit2, and setApprovalForAll must be audited as asset permissions.
Four fake-support scripts, decoded
“Your claim session needs wallet rectification”
We found an error in your claim session.
Rectify your wallet within 30 minutes or your allocation expires.The goal is to route you into a wallet drainer. Do not reply. Open the official claim page yourself, check status announcements, and file a ticket.
“Send gas or a verification fee for manual release”
Your claim is frozen. Send 0.02 ETH to activate manual release.Network gas appears in the wallet confirmation; it is not prepaid to a support wallet. Verify the contract, gas estimate, and TxHash.
“Approve all so we can deliver the reward NFT”
Approve the collection so the reward NFT can be delivered.This is often a setApprovalForAll trap designed to sweep NFTs. Receiving an NFT does not justify control over your existing collection.
“Download this debug tool or paste this Console fix”
Your browser cache is blocking the claim. Run this fix script.The target may be your Discord token, cookies, wallet files, clipboard, or entire device. Never download, run, or paste unknown code.
Already interacted? Respond by exposure level
| What happened | Risk | Immediate action |
|---|---|---|
| Read the DM only | Low asset risk | Capture, report, block, disable stranger DMs |
| Opened the link; no download or wallet | Tracking/browser risk | Close it, inspect downloads/extensions, clear that site’s data |
| Downloaded but did not run a file | Accidental execution remains possible | Do not open it; quarantine/delete and scan |
| Ran a file or pasted code | Device, Discord, and wallet may be compromised | Disconnect network; use a clean device to reset credentials, review Authorized Apps, scan/reinstall |
| Connected only; signed nothing | Address and portfolio exposed | Disconnect, close the site, monitor requests |
| Signed a login message | Potential malicious session or broader signature | End the session; review domain, nonce, expiry, and payload |
| Signed Approval/setApprovalForAll | Contract may pull ERC-20s or NFTs | Revoke immediately on the correct chain; gas is required |
| Signed Permit/Permit2 | An off-chain spending authorization may remain usable | Inspect spender and expiry; revoke the relevant permission |
| Signed a transfer or assets moved | Blockchain transactions are irreversible | Save TxHash, audit remaining permissions/assets, report appropriately |
| Entered seed or private key | The wallet is permanently compromised | Create a fresh wallet on a clean device, rescue what remains, retire the old seed |
Do I need to revoke after disconnecting?
If you only connected and never granted asset permissions, disconnecting is the main step. If you signed Approval, Permit, or setApprovalForAll, inspect and revoke them separately. Revocation is on-chain and costs gas.
What if the seed phrase was exposed?
- create a new wallet on a trusted device or fresh browser profile;
- generate a completely new recovery phrase;
- move recoverable tokens, NFTs, and positions;
- check every network;
- retire the old seed and all derived accounts;
- if a sweeper bot is active, do not blindly top up gas—seek specialist incident response.
Harden the Discord account too
- turn off “Allow direct messages from server members” globally or per server;
- enable the DM Spam Filter for non-friends or all DMs;
- restrict friend requests from mutual-server users;
- enable MFA/2FA and store recovery codes safely;
- use a unique password not shared with email or exchanges;
- review Authorized Apps and remove anything unfamiliar;
- if you ran a suspicious file, reset passwords from a clean device and scan the system;
- report the actual message—do not coordinate false mass reports.
Use MostLogin to separate Community, Verification, and Wallet activity
MostLogin cannot certify every URL or reverse a malicious transaction. Its practical role is to separate Discord browsing, link verification, and asset-wallet activity into different browser profiles. MostLogin’s website lists isolated sessions, Extension Integration, Profile Sharing, Role-based Access, and Operation Log Tracking.
Profile A — Discord Community
- Discord, X, and announcements only;
- no funded wallet extension;
- downloads restricted;
- DMs used only for evidence and User IDs;
- never claim or sign here.
Profile B — Official Link Verification
- bookmark the official site, docs, X, announcements, and explorer;
- no Discord DMs or shortened links;
- no wallet by default, or an empty test wallet;
- verify domain, contract, Chain ID, spender, and function;
- record source and verification time.
Profile C — Wallet Transaction
- one verified wallet extension only;
- prefer a hardware wallet;
- open dApps from verified bookmarks;
- check network, contract, spender, amount, and simulation;
- no Discord login or downloads;
- record the TxHash after every action.
Use least privilege for teams: community operators get A, researchers get A/B, and only authorized signers get C. Never share a seed phrase or a funded-wallet profile with someone who does not need signing authority. Operation logs improve accountability but do not replace an on-chain allowance audit.
| MostLogin can reduce | MostLogin cannot do for you |
|---|---|
| Discord sessions mixed with funded wallets | Guarantee that a DM or domain is safe |
| Multiple wallet providers injected together | Interpret every signature or contract |
| Overbroad team access and unclear ownership | Reverse a confirmed transaction |
| Official bookmarks mixed with DM links | Recover an exposed seed phrase |
| Cookie and session contamination during debugging | Bypass eligibility, regional, or identity rules |
Use MostLogin to isolate Discord and Web3 wallet environments

Copyable incident record
Incident: Suspected fake support DM after a public help post
Time (UTC): ...
Project and official server: ...
Public message link: ...
Username / Display Name / User ID: ...
Mutual server: ...
DM Message Link: ...
Original URL/domain: ...
Requested action: Connect / Sign / Approve / Transfer / Download
Wallet address / Network / Chain ID: ...
Connected? ... Signed? ... Signature type: ...
TxHash: ...
Actions taken: Report / Block / Disconnect / Revoke / Password Reset
Evidence: screenshots, signed payload, simulation, explorer record12 questions before trusting any support DM
- Do the rules say Staff Never DM First?
- Who initiated the conversation?
- Do Username, User ID, and role match?
- Did an official ticket confirm the User ID?
- Did the URL come from the website, X, or Announcement?
- Does the root domain exactly match your bookmark?
- Is the sender manufacturing deadline or account-freeze pressure?
- Are they asking for a download, QR scan, code paste, or remote access?
- Is the wallet asking for login, Permit, Approval, or Transfer?
- Are spender, token, amount, deadline, and contract correct?
- Will they let you return to the public ticket?
- If you signed, did you preserve the payload/TxHash and audit allowances?
Frequently asked questions
Will a Discord admin DM first about an airdrop issue?
Discord Staff do not contact users through the app for support. A Web3 project’s policy depends on its server rules, and many say Staff Never DM First. Re-verify any wallet request through an official ticket.
Does an Admin role prove the account is legitimate?
No. A real role is stronger than a bio, but staff accounts can be compromised. Verify User ID, history, ticket confirmation, domain, contract, and requested action.
Can a site drain me if I only connected and signed nothing?
A normal connection does not directly grant token-spending rights, but it exposes your address and portfolio and enables follow-up requests. Disconnect and verify that no permissions were signed previously.
Is disconnecting the same as revoking?
No. Disconnecting does not remove Token Approvals. Approval, Permit, Permit2, and setApprovalForAll permissions must be inspected and revoked separately.
Why would an airdrop claim request Permit or setApprovalForAll?
Receiving assets normally does not require a stranger to pull existing tokens or manage an entire NFT collection. Stop and verify the official contract and business logic.
Can I keep using a wallet after entering its seed on a fake site?
No. Treat the phrase and every derived account as compromised. Create a new wallet on a clean device, move recoverable assets, and retire the old wallet.
Will disabling server-member DMs break official tickets?
Usually not for ticket channels or Modmail, though bot setups vary. Communicate inside the official ticket instead of reopening DMs to everyone.
Can MostLogin automatically identify fake Discord support?
It cannot guarantee that. MostLogin isolates Discord, link verification, and wallet transaction environments and supports extension, access, and operation-log controls. Identity, domains, contracts, and signatures still require verification.
Final takeaway
The most dangerous Discord airdrop scam is not obvious spam. It is the convincing “support agent” who appears moments after you post a claim error and offers the perfect fix. Beat that playbook with a fixed response: do not reply, preserve evidence, copy the User ID, reopen an official ticket, verify the domain and contract, classify the signature, then choose the correct containment action—Disconnect, Revoke, or migrate the wallet.
MostLogin can turn this SOP into three isolated environments—Community, Verification, and Wallet Transaction—to reduce session crossover and team mistakes. It cannot replace reading wallet prompts, checking contracts, or keeping the seed phrase offline.
Official references: Discord scam protection, Discord message reporting, Discord User IDs, MetaMask approval revocation, MetaMask disconnect vs. revoke.
Read next: Wallet connected but unable to claim, Eligible but unable to claim: 12 steps, Staking ended but funds remain locked


