Impersonated Project Founders
A direct message from someone who appears to run a project you use. The account is convincing and the request is always the same shape.
Priya Raman · 2 min read
Anyone who participates in a project’s community will eventually receive a direct message from an account resembling someone who works on it.
The setup
The account copies a real person’s name, profile picture and biography. The handle differs by a character or uses a different platform suffix. Follower counts are purchased.
The message is friendly and specific. It references something you actually posted, which is how it establishes that a human is involved rather than a bulk campaign.
The asks, in order of frequency
Testing an early version. You are invited to try something before public release. The link runs a drainer.
Resolving your reported issue. If you posted a problem, they offer to help, which leads to a validation site or a screen sharing session.
An early allocation. An opportunity to participate in something before it is announced, requiring a transfer.
Helping with a compromise. They claim the project has been attacked and users must move funds to a safe address. There is no such thing as a safe address.
The structural tell
Real founders do not send the first direct message.
They post publicly, they respond in channels, and they do not individually approach users with links or requests. The volume alone makes it implausible.
Every project of any size states this somewhere in its documentation, and almost nobody reads it before receiving the message.
Verification that works
Check the handle character by character against the one linked from the project’s own website.
Ask in the public channel. Real team members are visible there and will confirm or deny in minutes. Fraudulent accounts cannot survive this.
Never follow a link from a direct message. Navigate to the project’s site yourself and find the same information there. If it does not exist there, it does not exist.
Treat urgency as disqualifying. A genuine early access opportunity survives an hour of verification.
The version that catches experienced people
An account that participates helpfully in a community for weeks or months before approaching anyone. The history is real, the contributions were genuine, and the eventual message arrives with accumulated credibility.
Against this, verification of identity does not help, because the person is who they appear to be. What helps is the same structural defence as everywhere else: a separate wallet for connecting, so that whatever the message persuades you to do is bounded by a small balance.
For project teams
Publish a policy stating you never send first direct messages, and pin it. Disable direct messages from non-members where the platform allows. Report impersonating accounts continuously, because they reappear.
None of that stops the attack and all of it reduces the volume.
For the rest of us
The working balance at a licensed exchange with a published address is unreachable by any message, because no signature can move it and a withdrawal allowlist adds a delay to anything new.
Move any remaining funds to a wallet with a newly generated seed phrase before anything else. Then revoke token approvals, and report the incident to your local authorities and the exchange involved. Do not pay anyone who promises to "recover" your coins. That is a second scam, aimed at victims of the first.