Home

Phishing & Wallet Drainers

Discord and Telegram Phishing: How Crypto Scammers Exploit Community Platforms

Spot the edge. Swoop in.

Almost every crypto project lives inside a Discord server or Telegram group, and that's exactly why scammers live there too. Fake support accounts, hijacked mod logins, cloned servers, and "verification" bots turn the same channels you use for legitimate project updates into the single largest delivery mechanism for crypto phishing. Here's how the patterns work, a full walkthrough of the most common one, and the checks that actually catch it.

By Swoopr Editorial Team

Published · Updated

AI-assisted content · Swoopr is responsible for the final published article.

Key Takeaways

Discord and Telegram aren't incidentally popular with crypto scammers, they are the dominant channel by structural design. Nearly every serious crypto project maintains an official server or group as its primary support surface, which means a huge share of a project's community is already gathered in one place, already expects to receive announcements and help there, and is already primed to trust a message that looks like it came from staff. That's a target-rich environment an attacker doesn't have to build from scratch; they just have to blend in.

Direct answer: Discord and Telegram dominate crypto phishing because they combine a plausible pretext, official-looking "support," "staff," or "giveaway bot" personas, with a large, pre-gathered pool of targets who already trust the platform. The defense is procedural, not instinctual: verify every invite link and every claimed identity through the project's own official website, and treat any unsolicited DM, regardless of the badge, role, or avatar attached to it, as suspicious until proven otherwise through a channel the sender didn't provide.

Why Discord and Telegram Dominate Crypto Phishing

The uncomfortable truth is that the same features that make Discord and Telegram useful for a legitimate crypto project make them equally useful for an attacker impersonating one. A project's official server is where announcements happen, where support tickets get opened, where governance proposals get discussed, and where a new user is told to go if something goes wrong. That means the server already has thousands, sometimes hundreds of thousands, of members who are pre-qualified as interested, invested, and expecting exactly the kind of contact a scammer wants to fake: a staff reply, an announcement, a giveaway, a "verify your wallet" prompt.

Compare that to email or SMS phishing, where an attacker has to guess whether a target even holds crypto, which wallet they use, or which project they follow. On Discord or Telegram, none of that guessing is necessary. Anyone active in a project's server has, by definition, already told the attacker what they're interested in and, often, roughly how much they might have at stake. The channel also supplies a built-in reason for contact that a cold email doesn't: it's completely normal for a project's Discord to have a support channel, a giveaways channel, and staff who occasionally reach out, so a scam DM doesn't need to invent a pretext from nothing, it just needs to imitate a pattern that already exists.

The last piece is scale and reusability. A single compromised moderator account, a single bot with server-wide messaging permissions, or a single cloned server can be aimed at every member simultaneously, and the scripts, fake ticket sites, and drainer contracts behind these attacks are reused across many different projects' communities with only cosmetic changes. That's why the same handful of patterns, described below, keep showing up nearly identically across completely unrelated tokens, NFT collections, and DeFi protocols: the infrastructure behind the scam is largely interchangeable, only the target community's branding changes.

Attack Patterns You'll Actually See

These aren't hypothetical categories, they're the small set of scripts that account for the overwhelming majority of Discord and Telegram crypto phishing. Knowing the shape of each one in advance is what makes it recognizable in the moment, when a convincing username and a sense of urgency are working against you.

Fake "support" accounts that monitor for help requests

An attacker, or more often an automated script, watches a project's public support or general channel for anyone posting something like "my transaction is stuck," "I can't withdraw," or "is this contract safe?" Within minutes, sometimes seconds, the person who posted receives a direct message from an account with a name like "[ProjectName] Support" and an avatar copied from the real team, offering to help. The DM steers the conversation toward a "ticket system" hosted on a look-alike domain, where connecting a wallet or entering a seed phrase is framed as a normal troubleshooting step.

Compromised legitimate mod or admin accounts

Rather than building a fake identity from scratch, some attacks take over a real moderator or admin account, usually through a phished login, a stolen browser session token, or a malicious bot the mod authorized without realizing what permissions it requested. Once in control, the attacker posts an "announcement" from an account the community has trusted for months or years, often linking a fake mint, airdrop, or emergency migration page. Because the account itself is genuine, this variant defeats almost every "check if the account is real" heuristic; the account is real, only the person controlling it has changed.

Fake giveaway bots requiring "wallet verification"

A bot, sometimes posing as an official project bot, sometimes just dropped into a cloned or compromised server, announces a giveaway or airdrop and instructs users to "verify" their wallet through a linked site to be eligible. The verification step is the entire scam: it's a wallet-drainer page disguised as an eligibility check, and clicking through and signing what looks like a routine verification transaction actually grants the attacker a broad token approval.

Cloned servers with near-identical names and branding

Attackers stand up a Discord server or Telegram group with a name, icon, and channel structure copied closely enough from the real one that a quick search or a stale link shared in a group chat can lead a user straight into the fake. Some cloned servers are seeded with bought bot accounts to inflate the member count so it looks established, and pinned messages inside often include the same fake "verify your wallet" giveaway bot described above.

Malicious Telegram bots requesting connection or seed phrase

Telegram's bot ecosystem is used the same way: a bot messages a user, or is pinned in a group, claiming a wallet connection or a seed phrase entry is required to "activate," "verify," or "sync" an account before a claimed reward can be released. Because Telegram bots can present a polished, official-feeling chat interface with buttons and inline menus, the request can look like a normal app flow rather than an obvious phishing attempt, which is exactly what makes it effective against users who would recognize a sketchy website but trust an in-chat prompt.

Worked Example: The Fake Support DM

Illustrative walkthrough — for education only.

To make the mechanics concrete, here is how the most common pattern, the fake support DM, typically plays out from first message to drained wallet.

Step one: the public post. A user in a project's official Discord posts in the #support channel: "my transaction is stuck, help?" The message is visible to everyone in the channel, including any bot or attacker account passively scanning it for exactly this kind of language.

Step two: the DM arrives. Within a few minutes, the user receives a direct message from an account named something like "Alex | [ProjectName] Support," using the real project's logo as an avatar and a short bio copied from the team page. The message reads warmly and specifically: "Hey, saw your message in #support, sorry you're running into that! I can help you get this sorted, mind if I take a look?"

Step three: the pivot to a ticket site. After a short, plausible back-and-forth, the "support" account sends a link to a "ticket system," something like projectname-support.io or projectname.help-desk.com, framed as the official way tickets are handled since Discord "isn't secure enough for wallet issues." The domain is close enough to the real one that a fast glance doesn't register anything wrong.

Step four: the fake diagnostic. The ticket site asks the user to connect their wallet so it can "check the transaction status" or "diagnose the stuck transaction." This step is designed to feel identical to legitimate diagnostic tools the user may have used before, and connecting a wallet by itself does not yet move any funds, which is precisely why it doesn't trigger alarm.

Step five: the malicious signature. The site then prompts a signature, framed as needed to "refresh the transaction" or "release the stuck funds." What it actually requests is a broad token approval or a signed permit message handing the attacker spending rights over the wallet's tokens. Because the wallet's signing prompt shows technical data most users don't parse, and because the surrounding conversation has already built trust, the signature gets approved.

Step six: the drain. The attacker doesn't need the user present for this step. Using the approval just granted, tokens and approved assets are transferred out, often within minutes, sometimes batched with dozens of other victims caught by the same bot that same day. By the time the user checks their wallet, the "support" account has typically gone silent, blocked them, or deleted its messages.

Every step in that sequence looks individually reasonable in isolation, which is exactly the design. The break point that would have stopped it is step two: legitimate support does not privately message someone who posted in a public channel, no matter how quickly or convincingly it appears to respond.

How to Verify a Server or Account Is Legitimate

Most of these attacks fail against a small number of consistent checks, applied every time rather than only when something already feels off.

Practical checklist

Common mistake

The common mistake is treating a fast, friendly, on-brand-looking response as reassurance rather than as the warning sign it actually is. A scam DM is often more responsive and more polished than real support, precisely because responsiveness is the entire mechanism it depends on.

Misconceptions Versus Reality

MisconceptionReality
A staff role, colored name, or badge on someone's Discord profile proves they're real staffRoles and badges can be spoofed, and the account behind a genuine role can be a compromised real staff account; neither case is distinguishable by the badge alone
A high member count or active-looking server proves it's the official oneCloned servers are routinely seeded with purchased bot accounts and copied message history to look established within hours of creation
Discord and Telegram are inherently less safe than a website, so official support avoids themNearly every legitimate crypto project uses Discord or Telegram as its primary support channel; the platform itself isn't the risk, unverified contact on it is
A quick, helpful reply to a support question is a good signSpeed and helpfulness are exactly what a scam DM is optimized for; genuine support delays are common, near-instant DM outreach is not
Connecting a wallet to a site is harmless as long as you don't send fundsA connected wallet can be prompted to sign an approval that grants spending rights without any separate transfer step, which is how most of these drains actually happen

Common Mistakes That Make This Work

Beyond the specific scam scripts above, a handful of everyday habits are what actually let this category of attack succeed at scale.

Risks, Limitations, and Exceptions

Practical Implementation Checklist

  1. Get every server invite and group link directly from the project's own official website, never from a DM, ad, or forwarded message.
  2. Treat any unsolicited DM offering help, on Discord or Telegram, as a scam by default, regardless of the sender's name, avatar, or role.
  3. Restrict Discord DMs to friends, or at minimum keep "DMs from server members" scrutinized rather than left wide open by default.
  4. Never connect a wallet or sign a transaction from a link sent in a DM, no matter how the request is framed.
  5. Check usernames and domains character-by-character; look-alike Unicode letters and zero-width characters are common and hard to spot at a glance.
  6. Confirm a server carries Discord's verification badge where applicable, and cross-check any bot's legitimacy against the project's own documentation.
  7. Never enter a seed phrase or private key into any bot, "verification" flow, or ticket site, regardless of platform.
  8. Report suspected fake support accounts and cloned servers to both the platform and the real project's official channels.

Tool Opportunity

A lightweight link and domain checker built for exactly this channel, DMs, bot prompts, and group chats, would help readers evaluate a suspicious message before acting on it.

Recommended inputs: the domain or URL sent in the message, the platform where contact occurred (Discord DM, Telegram bot, server announcement), whether the sender claimed to be staff or an official bot, and whether a wallet connection or seed phrase was requested.

Expected outputs: a plain-language flag list of which known red flags matched, a domain similarity check against the project's known official domain where available, and a link back to the relevant pattern on this page.

Validation requirements: never request or store a seed phrase or private key as an input, label every output as a heuristic risk signal rather than a verdict, and direct anything already involving a signed transaction toward the incident-response guidance on the recovery page rather than treating it as resolved.

Sources

Frequently Asked Questions

Why do scammers target Discord and Telegram specifically?

Nearly every crypto project runs an official Discord server or Telegram group as its primary support and community channel, which gives an attacker both a plausible pretext, posing as staff, a bot, or a fellow community member, and a large, ready-made pool of targets who already trust the platform and expect to interact with the project there. That combination is harder to replicate on channels without a built-in reason for a stranger to message you about your wallet.

How can I tell if a Discord server is the official one?

Only trust an invite link posted directly on the project's own verified website or its official, already-verified social media account, never one from a search ad, a DM, or a comment. Established servers for larger projects also carry Discord's server verification badge, visible next to the server name, though smaller or newer projects may not have one yet, so the source of the invite link matters more than the badge alone.

Would real Discord or Telegram support ever message me first?

No. Legitimate staff, moderators, and official bots do not send unsolicited direct messages offering help, and they never ask you to visit an outside website to "verify" your wallet or to type in a seed phrase or private key under any circumstance. Any DM that opens with an offer to help, especially one arriving shortly after you posted in a public channel, should be treated as a scam by default.

Does a role, badge, or colored name prove someone is real staff?

No. A role, colored name, or staff-style badge shown next to a Discord username is not independent proof of identity. It can reflect a genuine staff account that was compromised through a stolen session token or a malicious bot authorization, or in some cases a spoofed display setup designed to imitate the look of a staff role, so the presence of a badge alone should never be the basis for trusting a DM.

What should I do if I already clicked a phishing link but didn't connect a wallet?

If you only visited the site and did not connect a wallet, approve a transaction, or enter a seed phrase, no funds are at risk from that step alone, though you should still close the tab, avoid entering anything on the page, and report the link to the platform and the real project's official channels. If you did connect a wallet or approve anything, treat it as a live incident and move funds from an unaffected wallet immediately.

Is it safe to disable Discord's "DMs from server members only" setting?

Turning that privacy setting off is one of the most common ways users end up exposed to fake support and giveaway bot DMs, since it allows any member of a shared server, including throwaway accounts created specifically for scamming, to message you directly. Keeping direct messages restricted to friends, or to server members only with careful judgment, meaningfully reduces the volume of phishing attempts that reach your inbox in the first place.

Which Swoopr tool supports Discord and Telegram phishing awareness?

A domain and link checker that flags mismatched or look-alike URLs sent through DMs, group chats, or bots, paired with the verification habits and red-flag checklist on this page, is the practical way to evaluate an unsolicited link or "verification" request before acting on it.

Conclusion

Discord and Telegram aren't dangerous platforms, they're simply where crypto communities already live, and that's exactly what scammers rely on. Nearly every pattern here, fake support DMs, hijacked mod accounts, giveaway bots, cloned servers, malicious Telegram bots, collapses against the same short list of habits: get invite links only from official sources, never accept unsolicited help by DM, and never sign a transaction or share a seed phrase because a bot or a "support" account said it was required. Use this page alongside the broader phishing hub for the patterns that extend beyond these two platforms, and the site-verification guide for checking any link before you click it.

Related Reading