An airdrop distributes a token to addresses that meet some criterion — having used a protocol, held an asset, bridged funds, or simply existed at a snapshot block. The stated purposes are real ones: putting governance tokens in the hands of actual users, rewarding early adoption, and bootstrapping a distribution that is not entirely insiders. It is also a marketing budget denominated in a token the issuer creates, which is why so many exist.

The mechanics are usually a snapshot followed by a claim. The project fixes a block height, computes eligibility, publishes a Merkle root of the allocations, and opens a contract where an eligible address proves inclusion and claims. Claims typically expire. The snapshot is deliberately unannounced in the better-designed cases, because an announced one is an instruction to manufacture eligibility.

That manufacturing is now an industry. Farming an airdrop means using a protocol in whatever pattern is believed to qualify, often across hundreds of wallets, and it is why eligibility criteria have grown adversarial — minimum durations, weighting by genuine volume, and explicit exclusion of addresses that behave like a single operator. The arms race has a consequence worth noting: much of the activity a protocol reports during an airdrop campaign is the campaign, and it leaves when the tokens do.

Tax is the part that catches people. In many jurisdictions a token received in an airdrop is income at the moment of receipt, valued at its market price then — which can be its highest price ever — and a subsequent decline does not undo the income, it creates a separate capital loss that may not offset it. A holder who claimed at a peak, held, and sold months later at a fraction can owe tax on a value they never realised. The treatment varies and is genuinely unsettled in places, particularly for tokens with no market at receipt, which is exactly why it is worth establishing before claiming rather than after.

Then the security dimension, which is the reason to be careful with tokens you did not expect. Unsolicited tokens appearing in a wallet are frequently bait: they carry a name pointing at a website, and the site's claim flow requests a token approval that hands a contract permission to move real assets. Related patterns include tokens that cannot be sold, and address-poisoning transfers that seed a lookalike address into your history so a future copy-paste sends funds to an attacker.

The habits that cover most of it are unexciting. Never interact with a token you did not expect, and never visit a site because a token's name told you to. Claim only from a link you found yourself through the project's official channels. Use a separate wallet for claiming, so a bad approval cannot reach long-term holdings. Check what a claim transaction is actually approving. And record the date and value at receipt, because that is the number a tax authority will ask for and the one nobody keeps.