A user received a free airdrop NFT, got curious, and visited the official website—which drained their wallet through a malicious authorization. The hacker used a 'blind box' gimmick to lure clicks and swept 500 people's assets in one day.