Lost a load of ETH after connecting my MetaMask to a fake 'Polygon Airdrop' site, anything I can do?
Hey everyone,
i'm absolutely gutted. Last night, around midnight, I saw a tweet (that looked legit, tbh) about a huge Polygon airdrop for ETH holders. It linked to a site that mimicked the Polygon official page almost perfectly. I was half-asleep, excited, and ngl, greedy. I connected my MetaMask wallet and signed a transaction, thinking I was just confirming my eligibility.
Within minutes, my entire ETH balance was gone. Just... poof. Like 2.5 ETH, which is basically all my savings.
I've checked Etherscan, and I can see the transaction, it went to some random address, which then sent it to another, and so on. It looks like it was immediately swapped for USDT and then likely sent to an exchange.
I feel like such a fool. Has anyone ever experienced anything like this? Is there *any* way to track this, or is my money completely gone? My partner is furious, and I just don't know what to tell her.
10 Answers
Charlie, this is tough but unfortunately, a very common attack vector. What happened is you likely approved a setApprovalForAll or similar infinite approval transaction for the scammer's contract. This allows them to transfer any token from your wallet that falls under that approval.
Tracking the funds on-chain is possible, and you've already started by looking at Etherscan. You'll see the ETH moved through several addresses rapidly. Often, the final destination is a Centralized Exchange (CEX) like Kraken, or a mixer. If it hits a CEX, there's a *slim* chance law enforcement could subpoena them for account details, but for 2.5 ETH, it's highly unlikely they'd dedicate resources.
Key takeaway for everyone: Learn about token approvals. Use services like Revoke.cash or Etherscan's token approval checker to routinely review and revoke unnecessary approvals. Always verify the contract address you're interacting with against official sources. Airdrops are usually claimed *from* a contract, not *by* giving approval *to* a contract.
Oh mate, this is a classic 'wallet drainer' scam, unfortunately. They set up these smart contracts that, once you approve them, give the scammer permission to transfer your tokens out whenever they want. Often, they do it right away. The Etherscan trail you're seeing confirms it – they'll often quickly swap to a stablecoin like USDT and then try to off-ramp it through an exchange.
Immediate steps: First, disconnect that wallet from *everything*. If you have any other assets in that wallet type (e.g., NFTs), move them *immediately* to a fresh, secure wallet. Don't interact with that compromised wallet again unless you really know what you're doing. Filing a report with your local police and the FTC (if you're in the US or can report via their international partners) is crucial for official documentation. For tracing, companies like Chainalysis or TRM Labs do this professionally, but they usually work with law enforcement or large institutions – not typically individual recovery. Be super wary of anyone promising instant crypto recovery; they're almost certainly scams themselves.
Ugh, feel your pain Charlie. Happened to me last year, almost exactly the same way. Mine was a fake UniSwap liquidity pool thing. Signed what I thought was an approval, woke up to an empty wallet. My husband was so mad, too.
I went down the rabbit hole of trying to track it, but it just disappeared into a mixer or something. I reported it to the local police here in Groningen, but they didn't really 'get' crypto, you know? Just gave me a case number. Tbh, it was a really hard lesson learned. Didn't get anything back. Now I double and triple check everything, and I never connect my main wallet to anything even slightly suspicious. Using a hardware wallet for anything serious helps too. So sorry this happened to you.
Another one bites the dust. Look, I hate to be the bearer of bad news but when you 'sign a transaction' like that for an airdrop, especially from a fake site, you've essentially given away the keys, or rather, the permission to drain your wallet. It's not a hack in the traditional sense, it's you authorizing the malicious contract. The crypto is gone, passed through a few addresses, probably converted and cashed out. Police? They won't do much for 2.5 ETH. Recovery services? 99% scams looking to fleece you again. Learn from it, move on. Harsh, but realistic.
This is a prime example of why you MUST be vigilant with crypto transactions. That 'signing a transaction' step is where they get you. It means you're giving a smart contract permission to interact with your assets, often for unlimited amounts or for specific types of tokens. Always, always, ALWAYS read what you're signing in MetaMask. Does it say "Approve spending of 2.5 ETH"? Or "Set approval for all ERC-20 tokens"? If it's not clear, stop. If you're tired, stop. If it's too good to be true, stop. There are no free lunches in crypto, especially not large airdrops for just connecting your wallet. This is a tough lesson, but it's a critical one for staying safe in Web3.
Oh Charlie, I'm so very sorry this happened to you. It's an awful feeling, that sudden gut punch when you realise what's happened. My brother-in-law fell for a similar trick with a phishing site for a fake NFT project last year, lost a chunk of his savings too. He felt so stupid, but honestly, these scammers are so sophisticated now, making sites that look completely legitimate. Don't beat yourself up too much. You're not alone. I know it's not much comfort right now, but please take care of yourself. Report it, learn from it, and maybe take a break from crypto for a bit to clear your head. It stings, I know.
NGL, I got hit by something similar last year. Mine was a fake staking pool, thought I was getting decent returns, ended up losing about 3 ETH. I was devastated, man. Truly. I kept checking block explorers, hoping for some miracle. I even looked into some 'recovery' services but they all felt totally off, asking for upfront fees. Ended up having to just accept it. The worst part was telling my mam, who had given me some money to look after. Felt like a total eejit. It's a cruel world out there for crypto beginners and even seasoned folk getting caught off guard.
Let me guess, the 'airdrop' required you to 'approve token spending' or 'connect wallet'? Yeah, that's almost always a drainer. These guys are getting seriously good at social engineering. The sad reality is that crypto transactions, once confirmed on the blockchain, are irreversible. There's no bank to call and say 'oops, reverse that'. Those funds are gone. You can trace them, sure, but it's like tracing water in a river; you know where it came from, but good luck catching it once it's in the ocean. Any service that tells you they can 'recover' it for a fee after this point is a scam. Period.
Oh god, Charlie, I really feel for you. I was in a similar boat, but with a fake Brave browser update that drained my MetaMask. Like you, I saw the transaction on Etherscan, and it just kept moving to different addresses. It's such a sinking feeling.
I reported it to the police, and also filed a report with something called IC3 online – it's the FBI's Internet Crime Complaint Center. I don't know if anything will come of it, but at least it's documented. One thing I did do, which might not help with recovery but prevented further damage, was revoke all permissions for that wallet. You can use sites like Revoke.cash for that. Also, I created a brand new MetaMask wallet and moved any remaining tiny bits of crypto I had. Live and learn, I guess. It truly sucks though.
This whole scenario sounds like a classic 'permit' or 'approve' function being exploited. When you 'sign' something in MetaMask for an airdrop claim, it should usually be a simple signature request. If it's a request to 'approve unlimited spending' or 'set allowance for a token', that's a massive red flag. Always scrutinise those prompts.
Regarding tracing, even if individuals use Chainalysis or TRM Labs, their services are typically for institutions. However, you can report the scam to the relevant authorities, like the FTC in the US or your local cybercrime unit. They *might* engage these firms for larger cases. Also, you could try reporting the destination address to the exchanges if it can be tracked to one, but without law enforcement involvement, individual reports are often insufficient for action. Most importantly: do not fall for recovery scams now that you're vulnerable. Be safe.

