Skip to content
DnsLister Forum

Where domain hunters compare notes

INVESTIGATIVE ARTICLE (Part 1.)

The Stolen Name

How Crypto Fraud Industrializes the Trust Placed in Creators and Brands

A Seven-Part, Data-Driven Investigation

Written by BlackArgus Research

For Content Creators, Companies, Financial Brands, and Crypto Brands

Sources current as of · August 24, 2026

Research and Publication Edition

Contents

Part 1The Fraud Begins Before the Wallet

Part 2The Borrowed Voice

Part 3The Factory Behind the Profile Picture

Part 4The Brand Foots the Bill

Part 5The Market for Countermeasures

Part 6What Works—and What Merely Reassures

Part 7Defense Before the Transaction

Appendix AEvidence Matrix

Appendix BEditorial and Publication Rules

SourcesSource Register and Disclosure

Editorial Note

This series examines crypto fraud not as an isolated blockchain problem, but as an attack on borrowed trust. It focuses on content creators, companies, financial and crypto brands, and the people who follow them. The texts are designed as publication-ready copy for a corporate website or LinkedIn articles. Each part can be published separately; together, they form a cohesive investigation.

The editorial method follows a document-based, skeptical approach: primary sources before vendor claims, money flows before narrative, and a clear distinction between measurements, vendor statements, and conclusions.

What the Numbers Mean—and What They Do Not

The most important loss figures come from different measurement systems. The FBI counts US-related complaints submitted to IC3. The FTC analyzes consumer reports. Chainalysis attributes known blockchain addresses and transactions and revises estimates when additional addresses are identified. These figures overlap, cover different populations, and must not be added together. All figures are lower bounds or estimates within their respective methodologies—not a complete picture of unreported activity.

Sources current as of: August 24, 2026.

Part 1 – The Fraud Begins Before the Wallet

The Scammer’s Most Valuable Infrastructure Belongs to Someone Else

A crypto fraudster’s first asset is often not a wallet. It is a name.

The name of a creator whose community has listened to them for years. The logo of an exchange a customer already knows. The profile picture of a founder whose posts regularly appear in the feed. The perpetrator does not need to build this trust. They only need to borrow it long enough to draw the victim from a public comment into a private channel.

This explains why crypto fraud and brand protection can no longer be considered separately. The blockchain is often only the final technical layer. Before it come social media, advertising, search engines, messaging services, fake support accounts, copied profile pictures, rigged websites, and fabricated investment groups. Anyone who looks only at the payment sees the attack too late.

The Defensible Orders of Magnitude

Comparison of Reported Losses in 2025

Measurement System Separate Metric Reported Loss in 2025 Visual Scale
FBI IC3 Cryptocurrency-Related Complaints 11,366 billion USD
FBI IC3 Crypto Investment Fraud 7,228 billion USD
FTC Consumer Sentinel Investment Fraud 7,9 billion USD
FTC Consumer Sentinel Social Media as the Starting Point 2,1 billion USD
FTC Consumer Sentinel Imposter Scams 3,5 billion USD

Sources and methodology: FBI IC3 [1] and FTC Consumer Sentinel [2]–[4]. Do not add: the measurement systems, categories, and starting channels partly overlap and cover different populations. The chart shows reported losses in 2025, not a global total.

In 2025, the FBI recorded 181.565 cryptocurrency-related complaints and reported losses of 11,366 billion US dollars. Compared with 2024, complaints rose by 21 percent and losses by 22 percent. Crypto investment fraud alone accounted for 61.559 complaints and 7,228 billion US dollars. In this subcategory, the number of complaints rose by 48 percent and the reported loss amount by 25 percent.\1])

In 2025, the FTC recorded three million fraud reports and 15,9 billion US dollars in reported losses. Investment fraud led at 7,9 billion US dollars. More than one million reports involved identity or authority impersonation, with 3,5 billion US dollars in reported losses.\2][4])

Social media was not a secondary venue. Nearly 30 percent of people who reported a financial fraud loss to the FTC in 2025 identified social media as the starting point. Reported losses reached 2,1 billion US dollars. Of that amount, 1,1 billion US dollars involved investment fraud that began on social media.\3])

For 2025, Chainalysis identified at least 14 billion US dollars in inflows to known scam addresses and projected that the amount could rise above 17 billion US dollars as additional addresses were identified later. The company also reported a sharp increase in attributed impersonation scams. These are vendor analyses based on the company’s own on-chain attribution, not an official census.\5])

No Proof Against Any One Platform—but a Clear Pattern

The figures do not prove that a particular creator, a single network, or a single platform is responsible for these losses. They show something else: fraud is initiated where trust and reach already exist. Social media lowers the cost of first contact; cryptocurrencies often accelerate payment and make recovery more difficult.

A creator can be entirely aboveboard and still become the visual entry point for a scam. A company can operate all of its own systems correctly and still be impersonated through a third-party account, a lookalike domain, or a copied advertisement. The attack surface does not end at the organization’s own login.

This is the decisive shift: brand protection is no longer merely the defense of a name against confusion or counterfeiting. It is part of financial consumer protection.

The Blind Spot in Traditional Security Models

Traditional IT security asks: Was a system compromised? In an impersonation scam, the honest answer may be “no.” The original account is secure, the website is unchanged, and the team has not been hacked. Yet an account with an almost identical name and profile picture replies beneath a video. It recommends a “mentor,” points to Telegram or WhatsApp, and takes control of the conversation there.

From a technical perspective, the attacker may not have breached any of the creator’s systems. From the victim’s perspective, the creator spoke.

That is precisely why password protection, trademark registration, and a verification badge are each insufficient on their own. They protect different parts of the problem. Defense must connect identity, content, behavior, infrastructure, and the payment path.

What This Means for the Target Audience

For content creators, community moderation therefore becomes part of the security architecture. For companies, social media monitoring becomes an extension of brand protection and fraud prevention. For both, the relevant metric is not merely how much harmful content was removed. What matters is how long it remained visible, how many users it reached, how often it returned, and how many harmless posts were mistakenly affected.

The uncomfortable truth is this: no credible system can guarantee that it will stop every scam while never touching a harmless post. Anyone promising both is selling a certainty that does not technically exist. Professional protection begins with measurable tradeoffs—and with an architecture that makes errors visible and as reversible as possible.

Key Finding

Crypto fraud often begins before the wallet: with a borrowed identity in a trusted digital space. Those who defend only at the payment destination leave the entire trust-building phase to the perpetrator.

Sources for this part:\1])through\5]).

Part 2 – The Borrowed Voice

How a Comment Becomes a Payment

The typical comment scam is not a single message. It is a small production.

One account copies the creator’s name or profile picture. A second account asks a seemingly harmless question. Other accounts confirm that a particular “expert” helped them. Sometimes the purported creator account replies directly to a real user. The visible comment is merely the handoff point. The actual transaction then takes place in a messaging service, on a fake trading platform, or in a wallet.

The Seven Stages of the Attack Chain

ATTACK CHAIN AT A GLANCE
PHASE 1 Initial Contact & Identity Cloning 01 Target Selection Identify a Credible Target Identity ↓ 02 Identity Cloning Copy the Name, Handle, and Appearance ↓ 03 Context Insertion Join Existing Conversations ↓ PHASE 2 Migration & Trust 04 Channel Shift Move Contact to a Private Channel ↓ 05 Trust Building Fabricate Evidence and Create Time Pressure ↓ PHASE 3 Transaction & Follow-On Harm 06 Payment or Signature Trigger a Transfer, Purchase, or Wallet Approval ↓ 07 Secondary Exploitation Follow Up with a Fee, Tax, or Recovery Scam

Source and methodology: Editorial synthesis of the attack chain documented in Part 2. The recovery scam figure in stage 7 comes from FBI IC3 [1]; the sequence describes a typical pattern, not a mandatory progression in every case.

  1. Target selection. Attackers seek channels, brands, or leaders with high credibility, an active community, and a thematic connection to money, investments, or crypto.
  2. Identity cloning. The name, handle, logo, profile picture, banner, color palette, or biographical details are copied or altered slightly. Special characters, extra periods, and similar-looking letters make rapid detection more difficult.
  3. Context insertion. The fraudster does not necessarily post an isolated promotional comment. They reply to an existing question, imitate the channel’s tone, or construct a seemingly natural conversation using multiple accounts.
  4. Channel shift. The victim is directed to Telegram, WhatsApp, Signal, a fake support page, or an investment group. The public countervoices and moderation options of the original channel are absent there.
  5. Trust deepening. Fabricated profits, testimonials, group members, support agents, and small successful withdrawals create plausibility. Time pressure often appears only later.
  6. Payment or signature. The victim sends cryptocurrency to an address, buys through a Bitcoin ATM, or approves a malicious wallet transaction or token authorization.
  7. Secondary exploitation. Someone who has lost money is approached again with purported taxes, release fees, or recovery offers. In 2025, the FBI recorded more than 10.500 complaints in the Recovery Scam category, with 1,4 billion US dollars in reported losses; the amount may also include losses from the preceding fraud.\1])

What Research Found in YouTube Comments

YouTube Study: Sample Examined
8,8 million comments examined
about 10.000 unique accounts involved

Source and methodology: NDSS study 2024 [7]; 20 purposefully selected YouTube channels observed for more than six months. The 2,3 percent applies only to the sample examined and is not representative of YouTube as a whole; the filtering methodology affects the number detected.

A study recognized at the 2024 NDSS Symposium collected 8,8 million comments from 20 YouTube channels over six months. The researchers identified 206.000 scam comments from roughly 10.000 unique accounts—about 2,3 percent of the sample examined. They combined textual, visual, and temporal features and documented, among other things, creator impersonation, scripted conversations, and migration to WhatsApp or Telegram. In an approved study, they interacted with 50 scammers; blockchain data showed stolen assets worth millions among this small group.\7])

The 2,3 percent must not be extrapolated to YouTube as a whole. The channels were purposefully selected, and the detection method determined what became visible. The finding is nevertheless important: even in a public, moderatable space, a sufficiently large and coordinated layer of scam activity can persist.

The Problem Is Bigger Than the Comment

A USENIX Security study examined X, Instagram, Telegram, and YouTube. Between May and October 2023, the team captured 1,3 million profiles and 33 million posts. It identified 349.411 accounts with name-based squatting patterns affecting 2.625 of the 2.847 international brands examined. In addition to classic confusion, the researchers documented social engineering, phishing, and copyright abuse. Not every similar account is therefore automatically criminal; the study nevertheless shows the scale of the search space and the limits of purely reactive reporting systems.\8])

Why Simple Word Filters Fail

A rigid filter can block “WhatsApp,” “Telegram,” or a phone number. The attacker inserts spaces, special characters, emojis, spelled-out digits, or an image. A filter can detect promises of high returns. The attacker starts with a neutral question and moves the manipulation into the replies.

The core signal often lies not in a word, but in the relationship among several observations:

  • A new account resembles the channel name and uses the same profile picture.
  • It replies unusually quickly to multiple users.
  • Several accounts recommend the same messaging contact.
  • The thread looks like a conversation but was created within a few seconds.
  • A link passes through redirects to a newly registered or brand-like domain.
  • A wallet address appears in multiple campaigns.

The more of these layers are considered together, the harder they are to evade. This is precisely where contextual and campaign-based detection has an advantage over text classification alone.

AI Changes the Cost, Not the Basic Principle

Generative AI can localize language, vary replies, create profile pictures, and imitate voices and faces. Europol describes how Large Language Models make social engineering more efficient through personalized communication and automation. YouTube now also explicitly identifies AI-generated voices or likenesses as a possible form of prohibited impersonation.\6][10])

But the decisive mechanism predates every language model: the perpetrator assumes a credible role and isolates the victim in a controlled conversation. AI makes this process cheaper, faster, and multilingual. It does not replace the deception; it scales it.

Key Finding

A comment is rarely the entire scam. It is the first visible node in a chain of identity cloning, public staging, a private channel, a payment request, and possible secondary exploitation. Defense must recognize the chain, not just individual words.

Sources for this part:\1]),\6])through\10]).

Part 3 – The Factory Behind the Profile Picture

Why the Adversary Must Not Be Treated Like a Troll

A troll seeks a reaction. A professional scam operation seeks throughput.

It needs accounts, text, images, domains, messaging services, payment addresses, fake platforms, victim data, and money laundering. These tasks no longer need to be handled by a single group. The underground market offers many of them as services: phishing kits, stolen credentials, session cookies, bulk SMS, deepfake software, hosting, and money-laundering networks.

This changes the economics of defense. A creator who blocks every visible comment individually is fighting a supply chain. As long as new accounts and variants can be created more cheaply than they can be detected and removed, the attacker wins through volume.

Crime-as-a-Service

Europol’s IOCTA 2025 describes data as the core commodity of the cybercrime economy. Stolen credentials for email, social media, and financial accounts are traded; phishing kits enable the purchase of imitation websites; Initial Access Brokers sell access to compromised systems. In Europol’s assessment, generative AI increases the effectiveness and scalability of personalized social engineering communications.\6])

This matters to creators and brands for two reasons.

First, attackers can operate an external fake profile without touching the original account. Second, the same criminal ecosystem can try to take over the real account. A stolen session cookie or an infected device can bypass even strong passwords. If a legitimate channel is hijacked, the scam gains not just a similar profile picture but the genuine reach, history, and verification.

Scam Centers and Forced Criminality

The FBI attributes a large share of crypto investment fraud to organized criminal structures in Southeast Asia and notes that scam centers also employ people who have been trafficked and forced to carry out the fraud. UNODC and Europol likewise describe this model as a transnational problem.\1][6])

This distinction matters: the person writing in the chat may both participate in harming the victim and be a victim of coercion. The economic beneficiaries and organizers are often elsewhere. An effective countermodel must therefore disrupt accounts and infrastructure quickly, trace money flows, and preserve evidence in a way that enables investigators to pursue networks rather than merely interchangeable front accounts.

The Role of AI: Defensible Findings and Marketing Overreach

For 2025, Chainalysis reported that scam operations linked to AI providers generated significantly higher average proceeds in its own dataset than other operations. The company reports 4,5 times higher proceeds and strong growth in the impersonation category.\5])

This is a serious signal, but not a universal constant. The attribution depends on which wallets Chainalysis knows, how an operation is bounded, and which on-chain links to AI services are visible. The correct conclusion is not that every AI scam is 4,5 times more successful. It is that, in the observable networks, the use of such tools correlates with greater speed, volume, and proceeds—and merits particular attention.

What Industrialization Means in Practice

  • Variants emerge faster. Text, images, and profile names can be changed automatically.
  • Campaigns become multilingual. Poor grammar becomes less useful as a warning sign.
  • Roles are separated. One account lures, another confirms, and a third takes over support.
  • Infrastructure is replaced. One domain, profile, or wallet is followed by the next.
  • Victim data is reused. Anyone who has already paid is especially valuable for recovery scams.
  • Real and synthetic identities blend together. A stolen photograph can be combined with an artificial voice and genuine public information.

The Necessary Shift: From Content to Campaign

An individual comment may be ambiguous. A campaign often is less so.

When ten accounts recommend the same contact within similar time windows, use the same image components, and lead to related domains, they create a more robust signal than any single keyword. Behavioral, temporal, and relational data increase the chance of detecting new variants of the same operation.

This argues for a technical shift:

  • from word lists to combinations of features,
  • from individual posts to threads and reply patterns,
  • from accounts to clusters,
  • from platform boundaries to infrastructure relationships,
  • from mere deletion to evidence preservation and recurrence detection.

Key Finding

Behind many visible scam profiles is not an improvising individual but a division-of-labor infrastructure. Manual case-by-case moderation remains necessary, but it is economically inferior as a stand-alone strategy. Defenders must detect campaigns faster than perpetrators can deploy new variants.

Sources for this part:\1]),\5])and\6]).

Part 4 – The Brand Foots the Bill

The Harm Does Not End with the Victim

When a user sends money to a fraudster, the immediate financial loss is initially the user’s loss. It would be misleading to attribute every scam figure automatically to the impersonated creator or company. It would be equally misleading to conclude from this that the affected brand suffered no harm.

The fraudster monetizes trust that someone else built. The consequences are then distributed among victims, creators, companies, platforms, payment service providers, and law enforcement agencies.

Consequences for Content Creators

Loss of Trust

At the moment of deception, many users do not clearly distinguish between the original and the copy. After a loss, the question therefore often remains: Why did the creator not prevent this? Legal responsibility and perceived responsibility are not the same. For reputation, perception can be decisive.

A Damaged Community

Scam replies displace genuine conversations, draw users out of the public space, and create distrust of legitimate offers of help. If every contact seems suspicious, the value of the community itself declines.

Operating Costs

Moderation, screenshots, reports, communication with platforms, victim notices, and recurring checks take time. For larger channels, this becomes a permanent security function even if it is still categorized organizationally as “community management.”

Business and Partner Risk

Sponsors, agencies, and platform partners assess not just reach but brand safety. A comment section persistently overrun by fake giveaways, wallet drainers, or bogus investment advisors can hinder partnerships—even if the creator did not cause the fraud.

Risk of Account Takeover

Impersonation and account takeover are different attacks, but they may be connected. Successfully stealing the real channel makes subsequent scams considerably more credible. Google recommends that creators use passkeys or two-step verification, malware scans, and a recovery plan. Role-based channel permissions are safer than shared passwords.\11][12])

Consequences for Companies

Customer Losses and Support Burden

Fake support accounts can capture credentials, payments, or wallet approvals. Victims then often turn to the real company. This creates support cases, escalations, inquiries to compliance and legal teams, and communication needs.

Brand Confusion Across Multiple Channels

An attack can simultaneously use a lookalike domain, a social media profile, an advertisement, an app, and a messaging contact. A team that monitors only trademark registers will not see the comment. A SOC that monitors only its own infrastructure may not see the external domain until someone reports it.

Data and Credential Theft

Europol notes that compromised social media, email, and financial account access enables further attacks. A fake support interaction can lead to credential theft; a genuinely compromised employee account can then spread new, credible fraud messages.\6])

Evidence and Enforcement Costs

Profiles disappear, handles change, content is deleted, and domains change registrars. Without standardized evidence preservation, every incident starts from scratch. Companies therefore need not only a reporting function, but an actionable incident file.

What a Trademark Does—and Does Not Do

A registered trademark creates an enforceable right in a sign for defined goods and services. A German word mark generally protects the sequence of characters regardless of conventional capitalization or typeface; a combined word and figurative mark protects the specific graphic design. Selecting the territory and classes remains a strategic legal question.\17])

Registration, however, does not monitor social media, domains, comments, or wallets. It detects no fake account and files no report. It strengthens the legal position for complaints, injunctions, and certain dispute procedures—it is a foundation, not an operating system.

Domains: A Measurable Part of the Problem

In 2025, WIPO administered a total of 6.282 domain-name disputes filed by trademark owners—a record. The UDRP procedure is relevant to clear cases of bad-faith domain registration. It does not cover social media handles, messaging accounts, or wallet addresses. Even a successful domain transfer often comes only after users have already been exposed.\16][18])

Defensive domain registration can cover obvious variants, but not every combination of misspellings, subdomains, and new top-level domains. Monitoring and rapid response remain necessary.

Platform Rights and the DSA

YouTube, Meta, and X prohibit deceptive impersonation and provide reporting channels. Meta offers eligible brands search and reporting functions for trademark, copyright, counterfeiting, and impersonation cases through Brand Rights Protection. X permits reports concerning individuals and brands; YouTube explicitly includes copied brand features and AI-generated voices or likenesses in its policy.\10][13][14])

In the EU, the Digital Services Act requires reporting channels for illegal content and greater transparency about moderation decisions. According to the European Commission, platforms reported more than nine billion moderation decisions in the first half of 2025 alone; 99 percent were made proactively under their own rules. This shows the scale of automation, but does not prove the detection rate for crypto scams. A DSA notice is also not an automatic deletion order. The legal basis and evidence must be sound.\15])

The Realistic Boundary of Responsibility

Creators and companies cannot prevent every external fraud attempt. They can, however, harden their own accounts, publish official contact rules, monitor comments, preserve evidence, accelerate reports, and recognize recurring campaigns. Organizations that fail to build these processes leave the attacker in possession of the borrowed identity for unnecessarily long.

Key Finding

The victim’s direct financial loss is only part of the bill. Creators and companies also incur trust, operational, security, and enforcement costs. Trademark registration strengthens their ability to act, but does not replace continuous detection and response.

Sources for this part:\6]),\10])through\18]).

Source: r/u/BlackArgus · by /u/BlackArgus

Leave a Reply

Your email address will not be published. Required fields are marked *