What to Do If You Receive Unknown Small Tokens in Your Wallet
If you receive unknown small tokens, just leave them alone. The core principle is "look but don't interact" — don't transfer, don't authorize, and don't click any links in the token's information. As long as you don't take any action, your assets are safe.
The world's largest cryptocurrency exchange by trading volume,leading in security and liquidity.
New user benefit: Enjoy 20% off trading fees upon registration!
These unsolicited tokens usually hide dusting attacks or malicious authorization traps behind them. The attacker isn't trying to hack your wallet directly; they're waiting for you to get curious and interact with the token, or they use it to contaminate your transaction history so you copy the wrong address the next time you send a transfer.
Below are specific handling methods for different scenarios.
Prerequisites
You open your wallet (e.g., TokenPocket, MetaMask, etc.) and find a token in your asset list that you never bought.
The token usually has a very low value, or it's a counterfeit token that appears to have a high value.
You haven't clicked any links or "Claim" buttons in the token's details.
Step 1: Confirm You Have Received an "Unknown Token"
On your wallet's asset page, check the transaction history or token list.
Scenario A: A deposit you have absolutely no memory of appears in the records, with a very small amount, and the token name is completely unfamiliar or imitates a mainstream cryptocurrency (e.g., "fake USDT")
What it is: You've been selected. This is a typical dusting attack or token airdrop. Attackers use scripts to send tiny amounts of tokens (dust) to a large number of addresses to get your attention.
What to do: Ignore it. Don't click on the token, don't try to send it, and don't click any "Claim Airdrop" buttons.
Completion standard: You haven't performed any operations on the token.
Scenario B: The token shows a very high value (e.g., tens of thousands of dollars), but you never bought it
What it is: This is bait. Malicious contracts can fake high values specifically to lure greedy people into trading or authorizing.
What to do: Be alert, don't sell. Don't try to sell it on a DEX (decentralized exchange). Once you authorize the transaction, the malicious contract can transfer your real valuable assets out of your wallet.
Completion standard: You haven't made any authorization or trading attempt.
Step 2: Handling "Links" or "Memos" Attached to Token Details
Many scam tokens embed phishing URLs in the transaction memo of block explorers or in the token name.
What to do: Absolutely do not copy or visit these links. These websites pretend to be official airdrop pages, tricking you into connecting your wallet and signing malicious authorizations, which can empty your assets.
Completion standard: You haven't clicked any unfamiliar links.
Step 3 (Optional): "Hide" the Token in Your Wallet
If this unknown token keeps appearing in your asset list and is an eyesore, you can use your wallet's built-in feature to hide it — out of sight, out of mind.
What to do: Most wallets (e.g., TokenPocket, imToken) support a hide token feature. Find the token in your asset list, long-press or tap settings, and choose "Hide" or "Remove".
Completion standard: The token disappears from your main asset screen and no longer distracts you.
Common Causes of Failure
Misconception: Trying to sell it because you see "high value"
This is the most dangerous thought. Many scam tokens have fake "value" and their contract code includes restrictions: when you try to sell, it triggers an "authorization" request. Once you sign it, the attacker can access the mainstream assets in your wallet (e.g., USDT, ETH). The imToken security team has repeatedly reported such "energy leasing" scams, which essentially trick users into signing malicious authorizations.
Risk Warnings
"Authorization" is the key: What you sign is not a transfer, but permission for "the other party to take a certain type of token from your wallet." If you authorize "unlimited amount," the attacker can transfer all of that type of token from your wallet.
Dust can expose your identity: If you accidentally transfer this "dust" along with your other assets, attackers can use on-chain analysis to link your multiple addresses, possibly even infer your real identity and asset scale, preparing for future targeted phishing.
Severity: According to Chainalysis, crypto scam revenue could reach as high as $17 billion in 2025 alone, with "approval phishing" (tricking users into authorizing malicious contracts) being one of the main methods. Recently, a user lost nearly $1 million in USDT after approving a phishing token.
The world's largest cryptocurrency exchange by trading volume,leading in security and liquidity.
New user benefit: Enjoy 20% off trading fees upon registration!
How to Confirm You've Completed the Steps
The confirmation standard is simple: you did nothing except look. The token still sits quietly in your wallet, and your mainstream assets (ETH, USDT, etc.) haven't decreased by a single cent. You have successfully avoided the trap.
