Most crypto losses do not start with a smart contract. They start with a message. A reply on X, a friendly stranger on Telegram, an email that looks like it came from a project you trust. The social engineering layer comes first; the theft comes last.
This guide breaks down the playbook channel by channel — X, Telegram, and email — because each channel has its own script, and the scripts are more standardized than most people think. Once you can name the step you are on, the con stops working.
The X Playbook: Fake Jobs, Fake Airdrops, Real Malware
The most dangerous message on crypto X is not “send me your seed phrase.” Nobody falls for that anymore. The dangerous one offers you something that feels earned.
The fake moderator recruit
It starts with a DM or a reply: “Loved your thread on rollups. We’re recruiting community moderators for [project], paid monthly in USDT. Interested?”
You say yes. There’s a short interview in a Telegram group with other “staff members” who all vouch for each other. Then comes the operational step: “Moderators use our internal dashboard — download it here.” The link points to an installer. Almost always Windows.
That installer is the entire point of the exercise. It is typically a remote access tool or an infostealer — malware that copies browser passwords, session cookies, and wallet extension vaults, or lets the operator watch your screen until you type something worth taking. The moderator job never existed. The interview theater existed to get one executable onto your machine.
The same structure powers the fake airdrop variant: a reply claiming you’re on an eligibility list, a “claim tool” to download, a verification app to run. The bait changes; the deliverable is always software you install yourself.
Rules that hold
- Real projects recruit moderators through public posts and application forms, not cold DMs from accounts created last month.
- No legitimate airdrop requires you to install a desktop program. Claims happen in a browser, against a wallet you connect deliberately.
- If a “staff member” moves the conversation to Telegram within two messages, you are being processed. Speed is a feature of the scam, not of the job.
- On Windows specifically: a random
.exeor.scrfrom a stranger is game over. Malware on that machine owns every wallet extension and saved password in the browser.
If you already ran something suspicious, assume the machine is compromised. Move funds from a clean device, change passwords from a clean device, and revoke approvals — not from the machine that ran the installer.
The Telegram Playbook: The Slow Burn
The X scam takes minutes. The Telegram scam takes weeks. That is its strength.
How the conversation actually goes
It follows a rhythm you can learn to hear:
- Contact. A stranger joins a group, likes your messages, or DMs you with something innocuous. No pitch. Just chat.
- Rapport. They ask how you got into crypto. What you’re holding. Where you’re from — “No way, I’m from there too.” The hometown match is almost never a coincidence; it is a line from the script.
- The shared interest. “You’re in on XX too?” They mirror whatever you already trade. Agreement is the product being sold here.
- The leak. After days or weeks of friendship: “There’s this ground-floor project — local team, launching soon, not public yet. I’m already in.” Sometimes framed as an offline-promotion project, a regional push, a friend’s launch. Urgency is gentle: the launch is “in a few days.”
- The double kill. You buy. The token is a honeypot — you can buy, but a hidden rule in the contract blocks your sell. While you wait for the “launch,” the same friendly stranger may help you “check” a contract or claim a bonus, harvesting a signature that empties the rest of your wallet through a wallet drainer.
Then the account goes quiet. The friendship was the exploit.
The scam has a name in Chinese-speaking circles — 杀猪盘, “pig butchering” — because the mark is fattened before the slaughter. The operators work from prepared dialogue trees. The hometown coincidence, the shared coin, the quiet local project: these are fields in a script, not luck. For a deeper look at the script itself, see the pig butchering breakdown.
What gives it away on-chain
The token itself can be checked before you buy. A honeypot’s sell block lives in the contract — a modified transfer function, a blacklisted address list, an owner-controlled switch. Free honeypot checkers simulate a sell from your address and report whether the transaction would revert. Contract source that is unverified is its own answer: walk away.
The deeper tell is social, not technical. Real opportunities do not arrive through a stranger who spent three weeks agreeing with you. Nobody fattens a friendship to sell you a good trade.
The Email Playbook: The Lookalike Domain
Email survives in crypto because it inherits trust from domain names. The scam is simple: register a domain that looks almost right.
How the domain game works
- Typosquatting: a dropped or doubled letter —
arbirruminstead ofarbitrum,uniswap-clalminstead ofclaim. - Hyphenation and suffixes:
uniswap-airdrop.com,layer2-claims.io— official-sounding words the real project never uses. - Homoglyphs: characters that render identically —
rnlooks likem, a Cyrillicоlooks likeo. The domain in your address bar can be visually perfect and still wrong. - Wrong TLD: the project lives at
.xyzor.org— so the scammer registers the.com.
The email itself announces an airdrop, a token claim, a security update requiring wallet re-verification. The link leads to a pixel-perfect clone of the real site. The clone asks you to connect a wallet and sign, or worse, to enter your seed phrase to “verify ownership.” No real project will ever ask for a seed phrase, by email or anywhere else — that request alone identifies the scam regardless of how good the domain looks.
Rules that hold
- Read the sender’s full email address, not the display name. Display names are free; domains are the tell.
- Reach projects through your own bookmarks, never through links in the email. If the airdrop is real, it will still be real after you type the official URL yourself.
- Claims never require re-entering a seed phrase. Any page that asks is a phishing page, full stop.
- Watch the signature request if you do connect a wallet. A claim should not ask for unlimited token approvals or strange message types. If you don’t understand what you’re signing, don’t sign — see how crypto phishing actually works.
One Chain, Many Doors
The three channels look different but converge on the same goal: either software on your machine, a signature from your wallet, or a token you cannot sell. Understanding the destination makes every route obvious.
- X delivers malware. The tell is the downloadable installer.
- Telegram delivers a fake friendship and a honeypot. The tell is the stranger who agrees with you for weeks.
- Email delivers a cloned domain. The tell is the link you didn’t type yourself.
The defenses stack: keep claiming activity in a browser you can afford to reset; treat every unsolicited installer as hostile; verify tokens on-chain before buying, the same way you’d check any token for rug and honeypot risk; and treat unexpected airdrop claims — on any channel — as a reason to visit the project’s official page directly, not the link you were handed. The general airdrop rules in the crypto airdrop scams guide apply to all three channels here.
Scammers industrialized the scripts. Your defense doesn’t need to be clever — it needs to be boring and consistent: nothing installed from strangers, nothing signed unread, no links trusted from inbound messages.