In this guide
Scams move through the exact channels Web3 teams use for growth: Telegram messages, fake support accounts, cloned websites, X replies, airdrop forms, and malicious wallet prompts. Koreaβs 2026 legislative work on virtual-asset-related vishing underscores how quickly fraud and money movement are converging.
A project cannot control every impersonator, but it can reduce confusion. Users should know where official information lives, what the team will never request, how to report a suspicious contact, and when the next verified update will appear.
Prepare verified surfaces and emergency access
Maintain an official-links page on the primary domain, pinned channel messages, consistent handles, domain and account ownership records, backup administrators, and multi-factor authentication. List the exact support route and state that staff never request seed phrases or private keys.
Keep emergency access separate from day-to-day shared credentials. Know who can update the website, pause a bot, revoke a compromised token, remove a Telegram administrator, and publish from backup channels.
Triage reports without spreading the attack
Capture the suspicious URL, handle, time, message, wallet, transaction, and screenshot in a controlled incident record. Do not repeatedly open a suspected link from ordinary workstations or repost it without clear warning. Confirm whether the incident affects only an impersonator or an official account, domain, bot, contract, or signer.
Assign a severity and owner. Remove malicious posts where possible, report the impersonator to the platform or host, and contact affected infrastructure providers through verified channels.
- Verified source and incident timestamp
- Affected account, domain, bot, contract, or wallet
- User exposure and known transactions
- Containment owner and platform reports
- Next public update time and evidence custodian
Publish a safe, bounded notice
State what is confirmed, which official surfaces are safe, what users should stop doing, how to revoke or report where appropriate, and when the next update will be issued. Avoid declaring that funds are safe or recoverable before the responsible technical, legal, and provider teams confirm it.
Use the website as the canonical incident notice and link to it from social channels. This reduces contradictory screenshots and lets the team update one controlled source.
Connect community response to technical recovery
BlockPlanet can prepare channel hardening, moderator playbooks, bilingual notice templates, website status components, escalation workflows, and community coverage. Security specialists, exchanges, wallet providers, law enforcement, and counsel may need to handle the underlying investigation and recovery.
After the incident, record the timeline, affected users, root cause, response gaps, and corrective actions. Update onboarding and scam warnings before restarting acquisition campaigns.
Talk to BlockPlanet
Need a community people can trust and use?
We can connect Telegram and X operations, bilingual support, campaign execution, and reporting around one practical member journey.
- Telegram & X
- Bilingual support
- Campaign operations
Frequently asked questions
What should a moderator ask an affected user to provide?
Request only the minimum non-sensitive details needed for triage, such as the suspicious handle or URL and public transaction hash. Never ask for a seed phrase, private key, password, or remote access.
Should the project announce a scam before every fact is known?
If users face an active risk, publish a bounded warning with confirmed facts, safe official links, immediate actions, and the next update time. Clearly mark what remains under investigation.
Can BlockPlanet recover stolen funds?
No recovery can be promised. BlockPlanet can support communications and coordination while qualified security providers, exchanges, wallet services, law enforcement, and counsel assess available actions.
Research
Sources & further reading
Primary references reviewed for this guide. Rules and draft standards can change; confirm the current text before acting.