TLDR
An unfamiliar token balance is a reason to pause, not a reason to claim a reward. The immediate task is to establish whether you merely received a token, signed a spending permission or exposed a wallet secret. Those situations need different responses. A familiar ticker or a large displayed balance is not enough evidence to trade or deposit the asset.
Key takeaways
- Receiving an unsolicited token does not, by itself, establish that someone controls your wallet.
- Hiding an asset, disconnecting a website and revoking an approval do different jobs.
- Before any exchange deposit, match the exact token and network to the receiving platform’s instructions.
The security issue: a token balance can be bait
Coinbase’s security series listed “Taking Down Evil Tokens” on September 22, 2026. That provides a timely reason to revisit malicious-token handling; this guide does not claim a newly confirmed breach or a measured rise in losses. Dated coverage listing
Coinbase’s support guidance describes unsolicited dust transfers and tokens whose names contain a website address intended to lure recipients into revealing a recovery phrase. Its fake-stablecoin guide also notes that counterfeit tokens can arrive without consent. A wallet showing an asset is displaying blockchain data, not issuing an endorsement. Dusting guidance; fake-token guidance
Attack flow: from apparent reward to wallet permission
- The lure appears. An unfamiliar token or reward message invites you to investigate a supposed balance.
- The interface redirects attention. A linked site asks you to claim, unlock or exchange it. Navigate independently to the purported issuer instead of following the token’s embedded address.
- The request changes the risk. Connecting a wallet exposes public address information; approving token use can authorize a contract to move specified tokens. Coinbase warns that unlimited allowances can expose the full balance of the affected token. Permissions explained
- The user may miss what persists. Closing the page does not necessarily remove the on-chain spending permission. MetaMask distinguishes disconnection from revocation explicitly. Revocation versus disconnection
This is a general attack pattern drawn from wallet guidance, not a reconstruction of a named victim’s transaction. A request for a recovery phrase is a separate, more serious route to compromise.
User checklist before touching an unfamiliar asset
- Record the network and contract address. Compare them with documentation reached through the issuer’s independently verified website. A copied name or logo is not sufficient.
- Identify the requested action. If you cannot explain what the signature permits, stop. A button labelled “claim” is not an explanation of the transaction.
- Keep wallet secrets out of websites. A token reward is no reason to enter a recovery phrase or private key.
- Check the destination separately. An exchange’s support for a ticker does not establish support for every token using that name or every network carrying it.
- Use the wallet’s own hiding function. Coinbase says hiding assets in the Base app does not require interacting with the underlying token contract. Do not approve a transaction offered by an unfamiliar “cleanup” site merely to remove clutter. Safe display controls
Decision table: what happened, and what comes next?
| Observed situation | First response | What it does not prove |
|---|---|---|
| Unexpected token received; no interaction | Leave it alone and use built-in hide/report controls | Receipt alone does not prove key compromise |
| Website connected; no known approval | Disconnect and review recent wallet activity | Disconnection does not clear earlier allowances |
| Suspicious spending approval signed | Identify the affected token, spender and network; review revocation | Revocation does not reverse completed transfers |
| Recovery phrase exposed | Follow verified guidance for a fresh wallet and asset migration | Changing the app password does not replace exposed keys |
This table is an editorial triage aid. If the action you signed is unclear, preserve its details and consult your wallet provider’s official support before assuming the account is safe.
Response steps after an interaction
1. Stop further signing and preserve evidence. Save the network, transaction hash, contract address and suspicious website address. Keep screenshots private if they contain personal information. Never include a recovery phrase in a support report.
2. Review permissions through a verified route. For a suspicious allowance, follow the wallet provider’s official revocation instructions. MetaMask explains that on-chain revocations require gas. Check the affected chain and spender, then confirm the revocation transaction completed. Removing a browser connection is not a substitute. Allowance review and gas requirements
3. Treat exposed keys differently. MetaMask’s migration guidance calls for a fresh recovery phrase when the old one is compromised. It also warns that automated sweepers can steal gas added to an affected address. If funds are being drained, follow the provider’s incident guidance before depositing more gas; ordinary transfers may not work. Compromised-wallet migration guidance
4. Contact the right service. Use support reached from the installed app or a known official website. If an exchange transfer is involved, provide its transaction reference and ask what action is possible. Avoid unsolicited recovery offers; do not promise yourself a reversal before the service has assessed the facts.
Risk notes: hidden balances and blocked exits
Coinbase’s DEX guidance says flagged tokens may be hidden automatically while remaining in the self-custody wallet on-chain. It identifies risks including contracts that permit buying but prevent selling, and removed liquidity. A missing portfolio row therefore does not necessarily mean a transfer occurred; equally, an impressive displayed value does not demonstrate that a sale can execute. Flagged tokens and DEX risks
Do not attempt a swap or exchange deposit simply to test whether suspicious tokens are “real.” First establish their identity and the relevant platform’s support. A small experiment involving an unsafe signature can still grant a dangerous permission.
CryptoGuide take
The useful security feature is a clear explanation of what the user is authorizing. A trust-focused wallet should make it easy to ignore spam and inspect permissions without turning cleanup into another signing exercise. For exchange users, keep the receiving platform’s asset checks separate from whatever a wallet happens to display.
FAQ
Does an unexpected token mean my wallet has been hacked?
Not by itself. Tokens can arrive without your consent. Review what you signed or disclosed, and check for unauthorized outgoing transactions before deciding how to respond.
Does hiding a token revoke its permissions?
No. Hiding changes the display. Existing token allowances must be reviewed separately; hiding a suspicious asset does not cancel them.
Is disconnecting a website enough after a malicious approval?
No. Disconnecting and revoking an on-chain allowance are different actions. Use verified wallet guidance to review and revoke the affected approval.
Can an exchange recover the value shown for a suspicious token?
Do not assume the displayed value can be realized. Verify the exact asset and network against the exchange’s authenticated deposit instructions; sending an unsupported token does not make it redeemable.
Conclusion
Classify the event before responding: receipt, connection, approval or secret exposure. Then use the corresponding control. That sequence is more useful than rushing to sell an unfamiliar balance or signing a transaction to make it disappear.
Related pages
- Crypto security research
- Wallet comparison and custody checks
- Compare crypto exchanges
- Coinbase security testing and account controls
Sources
Primary sources reviewed September 30, 2026. The dated blog listing establishes the editorial timing only; technical guidance comes from the support documents below. Checklists and conclusions are CryptoGuide’s editorial analysis.
- Coinbase: September 22, 2026 security coverage listing
- Coinbase Help: dusting attacks
- Coinbase Help: fake stablecoins and hiding assets
- Coinbase Help: permissions and token approvals
- MetaMask: revoking allowances
- Coinbase Help: DEX risks and flagged tokens
- MetaMask: migrating to a new wallet
CryptoGuide Exchange is an independent research and comparison platform, not an exchange, broker, custodian, investment adviser or legal adviser. This is educational research, not investment or legal advice.