These days you should be VERY carefull with coins that promise an airdrop. It could happen that the fake dev tries to get you into download virus infected wallet software.
Good point, If they are asking me to download something I just stay away unless I know someone in the development team. I stick to only those airdrops that drop to my ethereum address.
Alternate solution is to build sandbox virtual machine to keep all wallets separated from main machine.
Once tokens are received send them to exchange address and that's it
