Scam Telegram: Uncovering a network of groups spreading crypto drainers
13 hours ago
- Investigator accidentally discovered a network of hundreds of fake DeFi support Telegram chats spreading phishing sites with wallet stealers and drainers, including Inferno Drainer.
- The fake chats use botted members, cloned bots (JoinHideBot, GroupHelpBot, Rose), and shared admins to appear legitimate and lure victims.
- Data collection via Telethon crawler and Gephi network analysis revealed deep interconnections among chats, admins, and users, indicating a coordinated scam operation.
- Scammers employ various techniques: direct phishing links, DM requests, redirect chains, and fake websites that steal wallet credentials or use Inferno Drainer to drain funds.
- Inferno Drainer code was heavily obfuscated; collaboration with researchers from SEAL and others helped identify it and take down many websites.
- The investigation found over 100 unique phishing websites, some using primitive seed phrase theft and others the sophisticated Inferno Drainer.
- Recommendations for DeFi projects: list all official channels, reserve usernames to prevent impersonation, and proactively report scam chats to protect users.