WATS Wallet logoWATS Wallet
Guide6 min read

Random Tokens Appeared in Your Wallet? Scam Airdrops, Dust and What Not to Do (EVM, Solana, TON)

A token you never bought just appeared in your wallet. It can't move your funds by sitting there; the danger starts when you sell, approve, sign or follow its link. Here is what to do on EVM, Solana and TON, and how dust and address poisoning differ.

By Alltoscan LLC, the company behind WATS Wallet Editorial policy

Published Updated

As of October 2026: a token you never bought cannot move your funds just by sitting in your wallet. Anyone can send tokens to any public address without your permission. The danger starts only when you interact with it: trying to sell, swap or send it, approving or signing anything it asks for, or visiting a website named in the token's name, NFT description or a TON transfer comment. Leave it alone, check it on a block explorer without connecting your wallet, and hide it from your wallet view.

Can a token you never bought steal your crypto?

No: holding an unsolicited token is harmless, because a token balance cannot reach your other assets. An ERC-20 transfer needs no consent from the recipient, and Solana SPL tokens and TON jettons work the same way. Your address is public, so receiving a token says nothing about your seed phrase.

Only your private key can authorize moving your assets, through a signature or through a spending approval or delegate you granted earlier (an ERC-20 approval on EVM, a token delegate on Solana). MetaMask's support documentation says no one can get access to your funds simply by depositing tokens into your wallet; harm happens when you try to interact with them.

For how a malicious signature empties a wallet, see what a wallet drainer is.

Why do random tokens show up in your wallet?

Most unsolicited tokens are spam or bait, because sending them costs the sender very little. The common types are:

  • Scam airdrops: worthless tokens or NFTs with a URL or "claim your reward" message in the name, symbol or description, built to pull you onto a phishing or drainer site.
  • Fake look-alikes: a token called USDT or TON that is not the real contract.
  • Dusting: tiny amounts sent to many addresses to link them to one owner, covered below.
  • Address poisoning: tiny or zero-value transfers from look-alike addresses that plant a fake entry in your history; see how address poisoning works.
  • A legitimate airdrop: occasionally real. Confirm it only through the project's official channels, never a link in the token.

What should you do about a token you did not buy?

Leave the token alone and verify it from the outside. In order:

  1. Do not sell, swap, send or approve the token.
  2. Do not visit any URL in the token name, NFT description or transfer comment.
  3. Check it on a block explorer without connecting your wallet.
  4. Work out whether it is dust, a zero-value entry or a real outgoing transfer.
  5. Hide the token from your wallet view.
  6. On Solana, optionally clean up with your wallet's own tools.
  7. If you already signed or approved something, revoke it and follow the first-hour checklist.

For the explorer step, open Etherscan, Solscan or Tonviewer in a fresh tab by typing the address yourself, paste your address and read the token contract. It is read-only, and you never click "connect wallet". See how to read a block explorer.

Most wallets let you hide a token. MetaMask's support pages state that hiding does not change the on-chain balance or token allowances, so it does not undo an approval you already granted.

If you already interacted, revoke any approval you granted. If you entered a seed phrase or funds moved, follow what to do in the first hour after a wallet is drained.

EVM chains: how do honeypots and approvals work?

On Ethereum, BNB Chain, Base, Arbitrum and other EVM chains, the trap starts when you try to sell. A honeypot is a token built so you can receive it but not sell it, often paired with a fake claim or approval step that is the real trap. MetaMask's support documentation describes the lure: an error message shown when you view the token on an explorer or try to trade it sends you to a fraudulent site that says you must approve a transaction or token access, or give your Secret Recovery Phrase, to sell or redeem it. See how to check if a token is a scam.

A price shown for an unknown token does not mean you can sell it. Trust Wallet's help center advises against selling, swapping or sending tokens you did not request, because doing so may trigger a malicious smart contract, and says hiding the token is safe. If you have already granted an approval, revoke it.

Solana: should you burn spam tokens and NFTs?

Spam on Solana is harmless to hold, and burning it is optional cleanup that can also return a small rent deposit. Spam often arrives as NFTs or tokens promising a free mint or reward behind a link; in an August 2022 post, Phantom said such links push you to claim something or ask for your seed phrase.

Each token you hold sits in its own token account, which carries a rent deposit. Per Solana's documentation, a token account must have a zero balance before it can be closed, and closing it sends its lamports, including that deposit, to a destination the owner chooses. So spam is burned first, then the account is closed. In the same post, Phantom said spam NFTs "are never dangerous to burn" and that burning returns a small SOL deposit; that is its statement about its own in-wallet feature, not about third-party burn sites.

Use a burn or close feature only if your wallet offers one; otherwise leave the spam hidden. Never use a "reclaim SOL" or "incinerator" link from a token, a DM or an ad. Each burn or close is a transaction that costs a small SOL fee. See how Solana rent and empty token accounts work.

TON: how do you spot spam jettons and comment scams?

On TON, the label proves nothing: anyone can deploy a jetton with any name, symbol and image, including copies of USDT or NOT. TON's developer documentation says to never trust metadata for authentication and to verify the jetton master contract address instead. Keeper (formerly Tonkeeper) says genuine TON, USDT and NOT never carry its "Unverified token" label.

TON transfers can also carry a text comment. Keeper's help center describes scammers sending a small amount with a message such as "Your wallet has been suspended. Verify your identity to restore access". Keeper adds that no one can freeze a non-custodial wallet. Treat any comment with a link or an urgent warning as phishing and ignore it.

A missing "Unverified" label is not proof that a token is genuine. Fees on TON are paid in GRAM (formerly Toncoin).

Dust, zero-value transfers and address poisoning: what's different?

They are three different things, and none is a theft by itself. Dust is a tiny amount of crypto sent to your address without your request.

  • Dusting sends tiny amounts to many addresses to trace and link their owners. Binance Academy says it targets privacy, not your keys or funds, though it can lead to targeted phishing. Do not move or consolidate unexpected dust; see what your address reveals.
  • Zero-value "outgoing" transfers on EVM: Cointelegraph reported in February 2023 that, in some token contracts, attackers can trigger a transferFrom of 0 tokens that appears to come from your address without your signature. Nothing left your wallet; check the amount.
  • Address poisoning plants look-alike addresses in your history so you copy the wrong one later. Copy addresses from a saved source and check every character; see the address poisoning guide.

Decision rule: if real value left your wallet and you did not sign it, this is not spam: a stolen key or an approval you granted earlier is being used. Go straight to the first-hour checklist.

How does this apply in WATS Wallet?

Every rule above applies unchanged, because WATS Wallet (by Alltoscan LLC) is non-custodial on EVM networks, Solana and TON, available as a Chrome extension and an iOS/Android app. You hold your own keys and recovery phrase, WATS never holds a key, and a token that lands in your address cannot move anything unless you sign.

Cleanup and recovery actions are signed transactions. On EVM networks WATS Wallet charges every action in ATS from one ATS balance on BNB Chain via an ERC-4337 paymaster, tracking the live network cost, so a transaction such as revoking an approval does not need a fee token on each chain. On Solana and TON every transaction is paid in the chain's own coin, SOL or GRAM, including closing a Solana token account. See how ATS fees work.

Frequently asked questions

Should I sell an airdropped token I didn't buy?

Usually no. Unsolicited tokens are often honeypots or bait: the sale fails or sends you to a swap or claim site that asks for an approval or signature, and that is where drains happen. If you think it may be a real airdrop, confirm it through the project's official site or channels you find yourself, never through a link in the token. See <a href="/blog/how-to-check-if-a-token-is-a-scam">how to check if a token is a scam</a>.

Does a spam token in my wallet mean my wallet or seed phrase was hacked?

No. Addresses are public and anyone can send tokens to them, so receiving spam reveals nothing about your keys. Do check the explorer for real value leaving your wallet: zero-value outgoing entries on EVM can be faked without your signature, but real value leaving that you did not sign means a stolen key or an approval you granted earlier is being used, and then you should follow <a href="/blog/crypto-wallet-hacked-what-to-do-first-hour">the first-hour checklist</a>.

Can I just burn or send the spam token away to get rid of it?

You don't need to. Hiding it in your wallet view is enough and changes nothing on-chain, while on EVM, sending or burning means calling the scam token's own contract and paying a fee for no benefit. On Solana, burning the spam and closing the empty token account returns the rent deposit to an account you choose, but use only your wallet's built-in burn and close feature if it has one; otherwise leave the spam hidden. Never use a reclaim link from a token, a DM or an ad. Each step is a transaction with a small SOL fee.