The bait
You notice unfamiliar tokens in your wallet, often named after a real project with a "claim" website in the description. The tokens are worthless — they exist only to lure you to a phishing site.
The trap
The claim site asks you to connect your wallet and sign to "unlock" the airdrop. That signature is an approval or a transfer that hands your real assets to the attacker.
How to protect yourself
Ignore tokens you did not expect. Never interact with a claim link inside a token name or memo. Verify airdrops only through the project official channels, and never sign to "claim" from a site you reached through a random token.