so ive been thinking about this airdrop.
seeing as the coin is not a fork. one thing i cannot get my head around is how you are going to prove someone owns a specific address.
seeing as you cant use the private keys and are limited to one address sending any sort of proof is next to impossible.
for example.
someone could claim to own an address that isn't theirs. any sort of screenshot could be faked with Photoshop or clever image manipulation
usually in most decentralised currency's the coins are automatically associated with the corresponding private key. this makes it secure as the person receiving the coins has to own the private key to receive them.
but from what i am reading its looking like you are using another method which could be exploited.