❗ Alert!!! scam hack attempt! Honestly one of the best one I have seen
- Verified Twitter Account
- Stolen TG account with TG stories of a real person
-AI generated website
Its all there.
AI is a wonderful tool but its making scams that much easier! Stay safe.
🚨Scam Alert! Scarry scam link passed virus total check.
Someone sent me a malicious link this morning. I ran it through VirusTotal before clicking. 0 out of 95 security vendors flagged it. Every single one came back clean. The link was not clean.
It was a fake Microsoft Teams URL designed to download a trojan on your machine. This matters because most people in crypto treat VirusTotal as the final word. If it passes, they click. That assumption is now being weaponized. Attackers are building malware that specifically evades automated scanning, knowing that is the check most of us run.
The domain was https://t.co/06FaEC3heH. Not https://t.co/5jG3tHZQUe. Close enough to scan past at normal reading speed, clean enough to pass every security tool available to the public. The rest of the setup was standard: Telegram outreach, vague pitch about synergies, a real Calendly booking to build trust, then the payload link sent right at call time when you are expecting to click something.
VirusTotal passing is no longer a green light. Check the actual domain. Real Teams links come from https://t.co/0ENkPHeqyr only. Anything else, regardless of what the scanners say, treat it as hostile. This is being run against people in Web3. Founders, operators, investors. Be careful out there.
hyperliquid's 4-of-5 multisig controls $4b in user deposits with zero timelock. uniswap has 48 hours. aave has variable delays. makerdao has 48 hours. hyperliquid has zero. five anonymous signers can upgrade bridge contracts and drain everything instantly with no review period. closed-source node client means validators can't even verify what they're running. assign a 5% annual probability to multisig compromise and 90% loss severity and you're looking at negative expected value on idle capital. the product is elite. the UX is best in class. the revenue is $600m annualized. but treat it as a trading venue not a vault. trade there, withdraw profits to self-custody, never let capital sit idle on a platform where the entire security model is "trust five people you've never met"
Energy, Risk, and Markets: What Changes Now?
⏰We’re breaking it down on April 1st at 5 PM CEST with our guests:
Paul Lalovich @paullal8
Alex Damsker @AlexDamsker
Harrison Frye @FryeCryptoGuy
Amanda Goodall @thejobchick
Bring your questions and join the conversation 👉https://t.co/GWzdrI0zjs
Advised IDEX on its sale to Katana as principal at https://t.co/JlzXgM3Hwz.
They are now Katana Perps. Native on-chain perps integrated into the Katana App, backed by @GSR_io, @SeliniCapital , and @Auros_global at launch. @katanaperps@katana
We sourced and ran the full process. Good team, right home.
https://t.co/nMeXyZWXgb
https://t.co/1FoBEFiZFQ
Scam Alert!!!
New phishing vector targeting crypto conference organizers and speakers.
The scam:
-Impersonates conference organizers (this one fake ETHCC)
-Uses https://t.co/NO9duXSBd0 to build fake booking pages
-Google domain = instant trust and credibility
-Asks you to "schedule a call" via fake booking link
-Likely harvests calendar access, email, or deploys malware
Red flags:
-Real booking link is a subdomain (https://t.co/HxUW2PuVYh, https://t.co/1xjvGSt0M1)
https://t.co/NO9duXSBd0 is just a webpage builder, not a booking tool
-No legitimate conference uses Google Sites for speaker coordination
-Unprofessional Telegram outreach
The Google brand creates false trust. They're weaponizing it.
Stay sharp.
Our lecturers are almost finalised. We tried our hardest to find the most impactful and knowledgeable people across all startup topics, and are looking forward to joining every lecture to learn the nitty gritty specifics ourselves.
If you haven't been accepted, don't worry - all lectures will be published on our YouTube channel: https://t.co/uAgn9JDBL0.
🆘 Applications close 28 Feb. Apply here: https://t.co/xxnYaQQuWQ
Our lecturers are almost finalised. We tried our hardest to find the most impactful and knowledgeable people across all startup topics, and are looking forward to joining every lecture to learn the nitty gritty specifics ourselves.
If you haven't been accepted, don't worry - all lectures will be published on our YouTube channel: https://t.co/uAgn9JDBL0.
🆘 Applications close 28 Feb. Apply here: https://t.co/xxnYaQQuWQ
SCAM ALERT #2 - ETHDenver
Another sophisticated attack targeting conference attendees.
The Setup:
-Fake "TECHNO NIGHT" party posted on Luma for Feb 18
-Real venue (Club Vinyl) but not actually booked
-Timed perfectly for first night when late-night options were limited
-Professional branding, targeted at degens
The Scam:
-Accepted all registrations
-Sent email requiring NFT mint for entry (Is also on the event flier)
-Fake Moongate site: https://t.co/ZITrNcWcoN (real is https://t.co/YpnEkaAroZ) @Moongate
-AI-generated static HTML, near-perfect spoof
-When you "mint," you sign a transaction that drains your wallet
The Result:
-Dozens of confused attendees outside a closed venue on the cold Denver street
-Empty wallets
-No party vibes
This is the second major scam reported this week at ETHDenver
Protection Basics:
-Never sign transactions for event access - If you do, use a burner wallet
-Verify URLs character by character
-Never click Zoom/meeting links from unverified sources
-Use a burner wallet for any minting
-If it requires a signature to RSVP, it's a scam
These attacks are getting absurdly good. AI makes it trivial to create convincing spoofs in minutes.
The scammers target conference attendees who are mobile, distracted, intoxicated, etc. They know the schedule. They know when people are looking for plans.
Stay paranoid.
Excited to be joining Simplicity Group's accelerator program as a guest speaker for Week 5 on Fundraising.
I'll be covering acquisitions and OTC deals - how to position your project for a successful exit and what buyers are actually looking for in 2025.
Looking forward to sharing what we're seeing across 350+ mandates at @Acquire_Fi with the founders in the cohort.
Thanks to the Simplicity team for having me.
SCAM ALERT!!!!
By far the best phishing attempt I've seen targeting ETHDenver attendees.
Here's the playbook:
Setup:
-Fake "Shorooq Closed-Door Dinner Network" on Luma
-Professional branding, AI-powered screening process
-Registration form harvesting contact and company details
The Hook:
-TG DM asking for Calendly to schedule "screening interview"
-Booked via unmanned Shorooq email ([email protected])
-Premium verified TG account (+1 717-973-0455, @ShorooqCapital)
-Asked specific, pointed interview question (AI-generated)
-Sent fake Streamyard link: https://t.co/mVmR9koLrW (not .com)
-Near-perfect HTML replica, likely built in 60 seconds with AI
Red Flags:
-Domain was .ink not .com
-Deleted chat immediately when confronted
What they wanted: Executable file download to steal wallets, accounts, credentials, etc
The sophistication is insane. Premium TG, AI screening questions, pixel-perfect spoof site, perfect timing.
If you registered:
Don't click any links
Change passwords if you did
Alert your team
The bar for phishing just went up 10x. These are getting harder to catch even for pros.
Stay sharp.
@ShorooqPartners