Free tokens are the trap.
Scammers airdrop tokens and NFTs with a web address in the name: "claim at…", "airdrop reward…". The site drains whoever connects. Paste a wallet to see which bait is sitting in it.
Paste a wallet above. We list every token account it holds, read each token's on-chain name, and check it against Jupiter's market data.
Holding spam is harmless. Touching it isn't.
A token sitting in your wallet cannot move your funds. The danger starts when you visit the site in its name, connect your wallet and sign.
Don't visit the URL
No real project airdrops a token whose name is a website. Treat every web address in a token or NFT name as a phishing site.
Don't try to sell it
Spam tokens often have no market, or a rigged one. "Swap" pages linked from them ask you to approve a drain.
Never sign to "claim"
A signature request from an unknown site can transfer everything. Close the tab instead.
Hide, then clean up
Use your wallet's "hide" or "report spam". Burning and closing the accounts later returns about 0.002 SOL each; RentBack shows what you can reclaim.
Images can track you
Spam NFTs load images from the sender's server, which sees your IP. DustAlert never loads images for unknown tokens.
Check before you trust
Look up a token on Jupiter or a scanner before buying. Verified tokens show a badge and real liquidity.