Fake mint sites remain one of the most effective wallet-draining methods, especially around popular NFT launches.
Attack Sequence
1. Scammers register look-alike domains and clone the legitimate project’s mint page.
2. They promote the fake site via Google ads, compromised social accounts, Discord, or search results.
3. Victims connect their wallet and click “Mint.”
4. The transaction they sign is often not a simple mint—it grants setApprovalForAll or other broad permissions, or directly transfers assets.
5. The drainer contract empties NFTs, tokens, and ETH from the wallet, sometimes within seconds.
Urgency (limited supply, countdown timers) and pixel-perfect visual clones reduce user caution. Many people focus on the gas fee rather than the actual contract interaction being requested.
How to Protect Yourself
Always obtain the mint link from the project’s official verified channels—not from search ads or direct messages. Double-check the domain character-by-character. Review the exact contract and function being called in your wallet. Consider using a separate “burner” wallet with limited funds for experimental mints. Immediately revoke any unexpected approvals.
Frequently asked questions
Some continue operating for months after the real mint ends, catching users who search for the project later.
Sources and further reading
- Security analyses of Google-ads mint phishing · U.S. Securities and Exchange Commission (SEC)