Skip to content Skip to footer

Why Twitter/X Is The Haven Of Crypto Scams?

It is time to talk about the shady part of the crypto industry, where almost everything out there that is not you tries to scam you using the oldest tricks in the book. That mind sound too bearish coming from someone who advocates for a financial paradigm shift, but let’s be honest, the game in its current state has a lot of con artists who are preying on the naive.

There’s no sense to deny this, because every industry that employs people in some capacity will never be free of lies, deceit and fantasy. It’s a dog-eats-dog world where everyone wants to get a good bite. This is exactly why we’re going to become wiser to the tricks the scammers are trying to pull on us, learning how to navigate the muddy waters of crypto con games that are happening on Twitter every minute.

With that out of the way, let’s point out the most common ploys that will help you stay safe.

Lazy Spoofing Works Wonders For Scammers

After spending nearly twenty years in cybersecurity, I can say that some things never change.

No matter how much technological progress we make, how many years we spend on the Internet, and how much people have been defrauded because of spoofing, it is still one of the most effective ways to dupe the users to do all the wrong things. For uninitiated, spoofing is a technique used by cybercrooks to disguise themselves, a website, a profile, a page or whatever else as a known or trusted source.

Spoofing can take a gazillion different forms, but basically it comes down to changing a letter, a number, or a symbol in the name so it looks legit. For example, you could spot a @wcrldcoin username on Twitter and confuse it for the real thing because of the blue checkmark and visual copy of the Worldcoin, ironically a project that aims to distinguish people from bots.

More info about spoofing can be found in my book ‘Art of Email Security’. Back to Twitter…

The ‘verification checkmark’ cash grab from Musk, where anyone with a few dollars in their pocket can get a vanity symbol has spawned many more cases of impersonation online.

The flood of “verified” blue-tick accounts on Twitter already cost some companies a lot of money, as impersonators used the name, logo and a similar-sounding handle to tweet out “decisions” that spooked investors and dumped the stock price.

It takes just a few seconds to pull the company logo and background photo, eight buckaroos to purchase a blue checkmark to appear more legitimate, and just a bit of trickery to manufacture a handle that would resemble the original. @wcrldcoin @WorlIdcoin @woldcoinusa and the likes have been used, but sometimes scammers are so lazy they don’t even bother to craft a lookalike handle.

This is not a real Vitalik, this is his evil clown from the parallel universe who wants you to quickly click on the not-at-all suspicious link to get away with 50 grand of ETH. Please hurry.

It may look comically obvious for most of us, but sadly, this scheme still works as intended. Because if it didn’t, the crooks would try to do a better job next time, which is not the case. Once upon a time I even suggested that scammers make their phishing messages intentionally ludicrous to ‘weed out’ people who wouldn’t buy into their more elaborate ploy. You can check that post on my blog!

But this impersonation craze is not the only scam that people have observed online…

“You Scratch My Back, I Scratch Yours!”

Remember the ‘Twitter hack’ of 2020, where a lot of high-profile accounts were compromised to push out a ‘crypto giveaway’ scam? Pepperidge Farm remembers.

A bunch of teens gained access to Twitter’s administrative tools, which gave them the power to alter accounts and post the tweets directly from celebrities. Kim Kardashian, Jeff Bezos, Bill Gates, Barack Obama, Wiz Khalifa, Warren Buffett, YouTuber MrBeast, Wendy’s, Uber, CashApp, and Mike Bloomberg are some of those who were compromised.

And all those accounts basically parroted the same message. “I’m giving back to the community in Bitcoin, send $100 here and you’ll get $200 in return, pinky promise!

The handle looks good here because it was the real thing, and some people really thought the biggest accounts of the Twitterverse would combine forces to do some social media charity. Imagine Warren Buffett actually posting that, going against his very own rule of never losing money.

That rang more alarm bells than him sharing the same wallet with Kim, or Wiz Khalifa.

There was also a low key viral scam campaign where scammers sent out mass DMs with login credentials for some cryptocurrency account asking for help to withdraw money.

This Mahdie guy with 0 followers is sharing creds to an account that belongs to a person with different name, on an unknown exchange, ‘loaded’ with USDT, and protected by a password with negative entropy. So many red flags there you can almost hear the Soviet anthem.

I can’t imagine anyone with a functional brain taking this bait, but according to security researchers, the link led to a phishing site where to withdraw ‘the funds’, the victims were offered a way to transfer funds directly within the system by creating a VIP account, which costs a bit of money.

“So I pay 50 bucks to get a part of that 750000 balance? DAMN GOOD DEAL!!”

As soon as the victim registers in the system and enters their crypto wallet data to pay for VIP status, the funds are stolen from their account by a bunch of inglourious basterds. A ‘Nigerian Prince email scam’ with a twist, one could say.

The Most Keen Tech Support In The World

Finally, let’s end this blog post with something truly annoying that was happening on Twitter not called Elon Musk.

Talking about the bots that are summoned by a mumble jumble prayer that goes like ‘I lost my Metamask trust wallet coinbase hacked NFTs stolen hacked coinbase instagram hacked i need a sugar daddy I got scammed my wallet has been stolen i need a logo my instagram got hacked.’

Once you bash that atrocity into your timeline, give it a few minutes to get some of that sweet-sweet engagement in likes, retweets, and most importantly, replies with concerned tech support guys and girls.

Actually, just posting ‘Metamask’ can summon them all the same, resulting in messages like this one:

Lesson to carry out from this? Never trust someone with the name ‘Libbie’.

With that, we have just scratched the surface of the most com
mon Twitter scams that have some relation to cryptocurrencies. Scammers adore this platform because it allows them to access wider audiences that can be easily found via search. Secondly, it is hard to find a big company without a Twitter account these days, so it opens up a lot of impersonation opportunities unlike, let’s say, Telegram.

Finally, this checkmark shebang is an icing on top of this turd sandwich that shows the platform’s stance on security of its users. The mastermind would rather engage in stupid rebranding campaigns, signal boost his tweets, or promote memecoins for quick gains rather than do something useful.

In 2022 he famously said ‘“A top priority I would have is eliminating the spam and scam bots and the bot armies that are on Twitter”. Welp, it’s 2023 and things haven’t budged an inch.

So, is Twitter/X is trash? Always has been.