Cointime

Download App
iOS & Android

Scammers are using Telegram verification bots to inject crypto-stealing malware

Cointime Official

From cointelegraph by Stephen Katte

Scammers are combining social engineering with phony Telegram verification bots that inject crypto-stealing malware into systems to raid crypto wallets, blockchain security firm Scam Sniffer said. 

In a Dec. 10 X post, the security firm said scammers are creating fake X accounts impersonating popular crypto influencers, then inviting users to Telegram groups with promises of investment insights.

Once in the Telegram group, users are asked to verify through “OfficiaISafeguardBot,” a fake verification bot that “creates artificial urgency” with short verification windows, the firm said.

  Scammers impersonate popular crypto influencers on X and then invite users to malicious Telegram groups. Source: Scam Sniffer

The bot then injects a malicious PowerShell code that downloads and runs malware to compromise computer systems and crypto wallets. Scam Sniffer said it has noted “numerous cases” where similar malware led to the theft of private keys.

Scam Sniffer told Cointelegraph that the recent known cases of this type of scam were all caused by the fake verification bot.

“It’s currently unclear if there are other malicious bots. However, it’s obviously simple for them to impersonate others as well,” the firm said. 

According to Scam Sniffer, malware that targets regular users has “existed for a long time,” but the infrastructure behind such malicious software is “developing rapidly” and becoming “quite sophisticated.”

It explained that when scammers have successful heists and demand grows, they evolve into a scam-as-a-service, similar to crypto wallet-draining software makers hiring out their tools to phishing scammers.

Scam Sniffer added while it had seen malware distributed through Telegram and instances of scammers impersonating others to trick run malicious code, “this is the first time we’re seeing this specific combination of fake X accounts, fake Telegram channels and malicious Telegram bots.”

  The fake Safeguard bot caused all recent and known cases of this scam type. Source: Scam Sniffer

Meanwhile, the security firm said it has noted a surge in scammers impersonating others on X and shilling sham links and tokens. 

On average, Scam Sniffer’s monitoring system has found 300 X impersonators a day so far this month, compared with the November average of 160.

At least two victims have lost over $3 million from clicking malicious links and signing transactions from some of these fake accounts, it added.

Related: Misspelling Soneium on Google could drain your crypto wallet: Scam Sniffer

Cado Security Labs also sounded the alarm that Web3 workers are being targeted by a campaign using fake meeting apps to inject malware and steal credentials to websites, apps and crypto wallets. 

Web3 security platform Cyvers similarly warned this month that phishing attacks may surge in December as hackers attempt to exploit the growth in online transactions ahead of the holiday season.

Comments

All Comments

Recommended for you

  • Berkshire Hathaway Releases Q1 Report

    On May 2, Berkshire Hathaway A (BRK.A.N) reported Q1 2026 revenue of $93.675 billion, up from $89.725 billion in the same period last year, exceeding market expectations of $89.274 billion. The net profit was $10.106 billion, compared to $4.603 billion in the same period last year, while market expectations were $11.762 billion. (Jin Shi)

  • U.S. Government: $40 Billion Earned from 10% Stake in Intel (INTC.US)

    On May 2, the U.S. government announced that its 10% stake in Intel (INTC.US) has generated $40 billion in earnings. (Dongxin News Agency)

  • Bitcoin risks extended retreat as April rally was futures-driven: CryptoQuant

    Futures drove up Bitcoin's price in April while spot demand declined, which CryptoQuant warned has historically preceded extended price declines.

  • Tokenized RWA market grows 420% since 2025 on regulatory clarity, access

    Tokenized US Treasurys were one of the biggest growth areas of the RWA market, rising from a market capitalization of $3.9 billion at the start of 2025 to more than $15 billion.

  • BTC Falls Below $78,000

    Market data shows that BTC has fallen below $78,000, currently priced at $77,977.99, with a 24-hour increase of 1.9%. The market is experiencing significant volatility, so please ensure proper risk management.

  • Trump States the U.S. Will Not Leave the Strait of Hormuz

    On May 2, U.S. President Trump stated that the United States will currently "not leave" the Strait of Hormuz. He defended the U.S. blockade actions, describing them as "very strong." Trump claimed that the blockade measures are effective and asserted that once the war is over, energy prices will significantly drop. "After this war ends, the prices of oil, gas, and everything will plummet," he said. He also praised the U.S. stock market for reaching historic highs and noted that projects during his administration are being completed "on time" and "on budget." (Jinshi)

  • Trump: Personally Inclined Not to Restart Bombing Operations Against Iran

    On May 2, U.S. President Trump stated that he ultimately has two options regarding Iran: either escalate military action significantly or reach an agreement. 'There are indeed options. Do we want to go in and blow them to smithereens to solve the problem once and for all? Or do we want to try to reach an agreement? Those are the options on the table,' Trump said. He also confirmed that he had just received the latest briefing on military options from the U.S. Central Command the previous night. Trump expressed his personal inclination not to restart bombing operations. 'From a humanitarian standpoint, I prefer not to do that,' he said at the White House. (CNN)

  • Trump: Unsatisfied with Iran's Latest Proposal

    On May 2, U.S. President Trump stated: 'Regarding Iran, I am not satisfied with the latest proposal. We are negotiating over the phone, and I am not sure if we can reach an agreement.' (Jinshi)

  • Benset: The Blockade Will Continue Until Iran Restores Pre-War Freedom of Navigation

    On May 1, U.S. Treasury Secretary Benset posted on the X platform, stating that it is difficult for a mouse in a sewer pipe to know what is happening in the outside world. Here are some 'realistic scenarios' for the Iranian leadership—after all, they are indeed in a dark state of information isolation: 1. The U.S. has complete control over the Strait of Hormuz. 2. There is a shortage of hard currency (i.e., U.S. dollars). 3. Rationing of food and gasoline has been implemented. 4. The entire international community has turned against you. 5. The blockade will continue until freedom of navigation is restored to what it was before February 27.

  • BTC Surpasses $78,000

    Market data shows that BTC has surpassed $78,000, currently priced at $78,016.69, with a 24-hour increase of 2.13%. The market is experiencing significant volatility, so please ensure proper risk management.