A new phishing campaign is spreading on TRON by sending so-called “FBI tokens” directly into user wallets. These assets are not legitimate notices from law enforcement. They are part of a token airdrop, or dusting-style scam, and authorities including the Federal Bureau of Investigation have warned that the tokens are tied to a broader phishing operation.
Fake law enforcement alerts sent straight to wallets
The method is simple. Scammers push counterfeit tokens into wallets without permission and make them look like official warnings. The message may claim the wallet is tied to anti-money laundering violations or that funds have been frozen, using fear to pressure the holder into taking immediate action.
The main danger appears in the token description. Victims may see links or instructions urging them to respond at once, and that is where the phishing attempt begins. Users can be pushed toward malicious sites, asked to submit sensitive information, or tricked into revealing private keys or seed phrases. The attack relies on social engineering, not on breaking the chain itself.
Open token transfers on TRON make bulk distribution easy
This tactic works in part because of how blockchain transfers operate. On networks such as TRON, anyone can send assets to any wallet address. No approval is needed from the receiving side. That same open structure allows fraudulent tokens to be distributed at scale.
According to the report, scammers are sending these fake assets to large batches of addresses at once to trigger panic and force interaction. Recent findings show that around 728 wallets have already been targeted, and some of them hold more than $1 million in stablecoins. The numbers show how quickly such campaigns can spread across a public network.
Confirmed losses are still limited, but the threat is real
So far, confirmed financial damage appears limited. The campaign is still new, and it only succeeds if users make a mistake, such as clicking a malicious link or handing over sensitive wallet credentials. Early warnings may also have reduced the immediate impact.
That said, the low level of confirmed losses does not make the campaign minor. The source notes that similar phishing attacks on other networks have caused losses in the millions of dollars, while crypto fraud keeps growing in scale and complexity. In this case, the use of fake authority messaging, including intimidation or extortion-style language, shows a more aggressive form of impersonation.
What wallet holders should avoid doing
The safest response is to ignore unknown tokens and avoid interacting with unexpected assets. Users should not trust a token because its name or description mentions a regulator or a law enforcement agency. They also should never click links embedded in a token description.
Other protections are basic but important: do not connect wallets to unverified platforms; use trusted services such as Binance or Coinbase; and hide or blacklist suspicious tokens in wallet settings. Private data remains the key target, and seed phrases should never be shared under any circumstances. The source also stresses that no legitimate authority, including the FBI, will ask for that information.
For larger holdings, a hardware wallet can add an offline layer of protection. That does not remove every risk, but it can reduce exposure if a user accidentally interacts with a malicious prompt or site.

