Article
Risk & Failure Modes

Airdrops and Forks: The Compliance Risk Institutions Ignore

Sagar Prasad
Portfolio Manager
In This Article
Share
Questions? Speak to our Team

On March 19, 2026, the FBI issued an alert about a counterfeit "FBI Token" distributed on Tron: unsolicited tokens pushed into wallets, followed by a spoofed claim site that drained any wallet connecting to it. The scam is ordinary. What makes it structurally interesting is the part nobody chose — the tokens arrived without permission, and no recipient could have prevented it. That is the compliance problem hiding underneath airdrops and forks. Under Revenue Ruling 2019-24, airdropped and forked tokens are ordinary income at fair market value the moment the holder has dominion and control, with basis equal to the amount recognized. An institution can therefore acquire a taxable position, a sanctions-screening obligation, and a valuation problem in a single unsolicited transaction it never agreed to receive.

The Primitives and Why Receipt Is Not Consent

Four primitives define the exposure. First, transfers are push-based: a sender credits a recipient address without the recipient taking any action or granting any approval. Second, there is no refusal primitive — an address cannot decline an incoming transfer, because the token standards were designed for a world where receiving value is unambiguously good. Third, for a custodied institution, dominion and control is determined by the custodian's support decision rather than by the chain: the tokens may exist at the address, but if the custodian does not support the asset, the holder cannot transfer, sell, or exchange it, and income recognition is deferred until support arrives. Fourth, income recognition requires a fair market value at the moment of receipt, which for a newly issued token with no active market is an estimate rather than an observation.

The trust assumption underneath is the one every traditional finance control inherits: that nothing appears in an account without an agreement. Custody agreements, account opening, and onboarding all encode consent before value arrives. On-chain, that sequence is inverted. Value arrives first, and every obligation attaches afterward.

Where the Losses Land

Four exposures follow. Tax and reporting: unsolicited tokens the holder can transfer create ordinary income even where nobody wanted them, and from 2026 exchanges may report received airdrops as income on Form 1099-DA — so the institution's records must reconcile against a broker's characterization it did not control. Valuation: an illiquid airdropped token has a reporting obligation and no reliable price, which is an audit finding waiting to happen, and the guidance remains a documented gray area rather than a settled rule. Sanctions: screening requires identifying direct or indirect exposure to sanctioned addresses several hops removed, and an unsolicited deposit inserts a counterparty of unknown provenance into the transaction history of an address the institution controls. Security: the most damaging vector is not the token but the claim — a fake claim page requesting an approval that grants a contract unlimited, indefinite permission to spend a token class, disguised as a button that says claim.

What to Watch and What Actually Defends

Watch for tokens appearing at institutional addresses with no corresponding entitlement in the position-keeping system; any custodian communication about fork support or non-support, since that decision sets the tax date; a rising count of unidentified assets at controlled addresses, which is both a reconciliation gap and a screening backlog; and any pressure to act quickly on a claim window, because urgency is the mechanism.

The strongest real defense is also the simplest, and every serious security advisory converges on it: do not interact with unsolicited tokens. Not approve, not transfer, not swap, not attempt to consolidate or dispose of them without a considered decision. Leaving them untouched is the correct default, because interaction is what converts an inert ledger entry into an approval, a claim, or a disposal. Beyond that: a written fork and airdrop policy specifying who evaluates an event and on what criteria; custodian selection that includes reading the fork and airdrop policy before signing, since serious custodians publish one and reserve the right to decline support where an asset creates AML, licensing, or security risk; screening any unsolicited receipt through blockchain analytics before it is treated as an asset; and documenting the circumstances of dust and spam receipts, since tokens with no fair market value are generally not taxable but the reasoning needs to exist in writing before an examiner asks.

Fake defenses are the ones institutions default to. Ignoring unidentified tokens is not a policy — it is the absence of one, and produces the same reconciliation gap either way. Assuming the custodian handles it is unsafe when the custodian's own policy reserves discretion to decline. And treating "we did not ask for this" as a defense misreads the rule, since dominion and control turns on capability, not intent.

The Playbook, Residual Risk, and What Is Improving

The playbook is short: publish the policy, name an owner, screen on receipt, book nothing until the custodian's support position is known, value with documented methodology, and reconcile against 1099-DA reporting. The residual risk is irreducible: as long as transfers are push-based and addresses cannot refuse, an institution's compliance perimeter includes assets other parties place inside it unilaterally. What has improved is the surrounding infrastructure — custodians now publish formal fork and airdrop policies with explicit legal and AML evaluation criteria, institutional wallet infrastructure enforces whitelists and sanctions screening at the transfer layer, analytics providers screen indirect exposure as standard, and 1099-DA reporting, whatever reconciliation work it creates, replaces silence with a record. The asymmetry remains, but it is now an operational process rather than a surprise.

For informational purposes only. Not an offer to buy or sell any security. Available only to accredited investors who meet regulatory requirements.

Recommended blog posts