Phishing on Telegram and Discord: How to Tell a Project Message from a Clone
Scammers copy admin accounts, create channel clones, and lead users to phishing sites.
At first, nothing looks critical. Scammers copy admin accounts, create channel clones, and lead users to phishing sites. The problem becomes obvious only after a signature, a transfer, or an attempted withdrawal.
The main thing to know right away: The key is not to panic and not to try to "fix" the situation with random transfers. First, stop the repeat risk, save the original data, and only then sort out what happened.
How the scheme works
On Telegram and Discord, it is easy to copy an admin's name, avatar, and design. Scammers also create channel clones and buy ads that lead to a phishing domain.
In this situation, it is important to separate two things: the attack mechanism itself and what has already happened to the assets. Scammers copy admin accounts, create channel clones, and lead users to phishing sites. After an incident, a technical review begins not with guesses, but with a specific operation and its continuation on the blockchain.
What to do if this has already happened
Check the username/ID, account history, and go to the project's site only through official sources you already know in advance. Do not trust an incoming direct message just because of a familiar avatar.
- Stop repeating the action that led to the incident: do not sign new requests and do not send additional payments.
- Save the tx hash, full addresses, network, asset, amount, and time of the operation.
- Record the correspondence, domain, profile, app, or signature screen — everything that explains the context of the operation.
- If there is a risk of wallet compromise, move the remaining assets to a new secure wallet without using the exposed seed phrase.
- If the amount is significant, it makes sense to map the further route of the funds and identify service points along the way.
What to save for the review
For this specific topic, it is especially useful to save: the account username/ID, a link to the message/channel, the domain, and screenshots of the correspondence.
For an initial review, prepare the data in one message or file — this reduces the risk of losing an important detail:
- tx hash / txid
- full sender and recipient addresses
- network, asset, amount, and time
- screenshots and correspondence
- domain, profile, or app, if they are related to the incident
What is better not to do
- Do not share your seed phrase and private keys with "helpers" or a "recovery service".
- Do not pay an unknown intermediary a "tax", "insurance", or "unlock fee".
- Do not delete the correspondence and transaction history before everything is saved.
Important: a transaction and an address are verifiable on-chain facts. The owner's identity, motive, and legal status should not be automatically inferred from a single graph.
When it makes sense to bring in a specialist
If the amount is significant, the route has already branched, or exchanges, swap services, bridges, and other services have appeared along it, a manual review helps separate available actions from useless ones. To start, public data is usually enough — private keys are not needed.
Frequently asked questions
Why are a name and a checkmark in the interface not enough?
Visual elements can be copied or imitated. For verification, the exact account, the official communication channel, and the destination domain matter.
Can a confirmed transaction be canceled?
As a rule, no. Further actions depend on the route of the funds and on whether services have appeared along it that can restrict the movement of assets.
Can an address immediately identify a scammer?
No. The blockchain shows addresses and operations. Identity requires additional data: a service's KYC, public sources, case materials, or other confirmations.
In short
Scammers copy admin accounts, create channel clones, and lead users to phishing sites. If this has already happened, first stop the repeat risk and save the original data. Then you can review the route and the real points for further action.
Need to understand what happened and where the funds went?
Send the tx hash, network, and a short description of the situation. A seed phrase and private keys are not needed for an initial assessment.
Submit data for assessment