Airdrops, not dividends
Why bWalletX issuers reward holders with airdrops, not payouts: the returns-wording block, the airdrop inbox, and the security audit behind it (sandboxed NFT content, address poisoning).
Status: built, not released. The airdrop inbox, the airdrop address, the returns-wording filter and the safety changes below are built on a development branch. They are not in the released app (5.1.84) and will ship in a later release.
How do you thank the people who hold your token?
Anyone who launches a token in bWalletX runs into the same question sooner or later: the people holding it backed you early, so how do you thank them? The answer much of crypto reaches for is a share of the money: a cut of fees, a payout per token, “holders earn”. It sounds generous. It is also, in most places, the description of a security. A token that pays holders a share of income looks like a share. Shares are regulated, and selling them to the public without the paperwork is a serious problem for the issuer and for the app that helped.
So we picked a different answer and built the wallet around it: issuers reward holders with airdrops. An airdrop is a gift of tokens or NFTs sent to holders’ wallets. It promises nothing about the future. It is a thing you send, once, that people can keep, use or ignore.
What a token gives you by default
By default, holding a token in bWalletX gives you one thing: entry to that token’s room. That is the only right we describe. If an issuer says their token does more, the wallet shows it as “Issuer says: …” and marks it as not checked by bWalletX. We don’t verify it and we don’t repeat it as our own claim.
The returns-wording block
Most people who write “holders get a share of the profits” aren’t trying to sell securities. They are being enthusiastic. So the wallet helps them before it’s a problem.
When you create a token in bWalletX, the wallet watches the name and description as you type. Words like profit, returns, dividends, yield, APY, ROI, “passive income” and “to the moon” bring up a warning, and the wallet won’t sign while they are there: “Remove wording that promises returns before publishing. Describe airdrops or room access instead.”
It matches whole words and ignores obvious look-alikes such as “free returns” or “profit and loss”. It is a word filter, not legal review. Someone determined can get round it. But it catches the common, careless case, and it points people at the answer we want them to use.
Your airdrop address
Every bWalletX account already has an ordinals address: the address that holds your tokens and NFTs. That is your airdrop address. Receive now has two tabs, Payments and Airdrops, and the Airdrops tab shows that address with a QR code and a copy button. The plan is to show it on your public page as well, so issuers can find it.
The airdrop inbox
If issuers are going to send people things, people need a calm place to receive them. Otherwise every stranger’s token lands in the middle of your wallet. So anything that turns up unasked goes to an inbox.
The rule for “unasked” is strict: a token or NFT paid to one of your addresses by a transaction you didn’t fund and didn’t start. Anything you bought, minted, launched, swapped or recovered leaves a record in your wallet, so it never counts as an airdrop.
A badge on the Wallet’s Airdrops row counts what is new since you last looked. Each item has two buttons. Keep marks it reviewed; it already shows in your normal tokens or NFTs. Hide removes it, and hides everything else from the same issuer. There is also a switch to show airdrops only from issuers you have kept something from before.
We thought about putting the inbox behind the b button at the top of the screen, so it is visible from every tab. We kept the b where it is and put the badge in the Wallet instead. Airdrops are occasional, and the inbox is new. If people come to rely on it daily, we’ll move it.
The security audit
An airdrop is, by definition, something a stranger chose to put in your wallet. Before building an inbox that invites people to look at them, we went through every place the wallet displays inscription content and asked what a hostile one could do.
Malicious NFT content is sandboxed. An NFT can be an HTML page or an SVG with script in it. If the wallet rendered that as part of itself, the script would run with the wallet’s access. It never does. Images are shown as images. Anything that isn’t a plain image shows a “tap to preview” placeholder, and the preview opens in a frame with an empty sandbox on a separate origin: no scripts, and no access to the wallet. The audit found two places to tighten. One inherited component used a sandbox setting that was looser than it looked, and the thumbnail code turned SVGs into wallet-origin images. Both are fixed, with a test.
Address poisoning. This scam is common on every chain. Someone sends you a tiny payment, or a worthless token, from an address that looks like one you really pay: the same first four and last four characters. Weeks later you copy an address from your history and pick theirs by mistake. Now, when you type a recipient, the wallet checks it against addresses that sent you dust or unsolicited tokens. If it matches or looks alike, and you’ve never sent to it, you get a warning showing the address it resembles.
No links from the inbox. A token’s name and picture can say anything, including “claim your reward at this site”. The inbox never shows issuer links. Links only appear on a token’s own page, behind a confirmation. The standing rule is printed in the inbox: never type your 12 words on a site an airdrop points to.
What comes later
Sending airdrops is next: to the followers of an account, to the holders of a token, or to the members of a room, with limits so they can’t be used for spam. Later, airdrops that unlock over time. We have also proposed retiring a TokenBlaster launch option that would pay BSV to holders, which looks too much like a dividend, and replacing it with holder airdrops. No coin uses that option today. Everything we know about the plan is on the Airdrops page.