Massive Discord-Based Phishing Scam Hits 30,000 Users Around the World

Massive Discord-Based Phishing Scam Hits 30,000 Users Around the World

Crypto Users Hit by Advanced Discord Scam: Over $9M Lost in Global Fraud Scheme

Cybercriminals have launched an elaborate phishing operation tailored to exploit cryptocurrency holders via Discord. Over the past six months, more than 30,000 victims have been deceived, resulting in collective losses that exceed $9 million. Despite claims of its 2023 shutdown, the infamous Inferno Drainer toolkit appears to be powering the scheme, still very much active in the threat landscape.

Experts at CheckPoint uncovered that attackers are leveraging Discord’s built-in functionalities and combining them with refined social engineering techniques to execute their ploy. By mimicking legitimate processes and tools familiar to the crypto space, these actors build trust before stealing funds.

In January 2025, researchers identified that individuals from a well-known crypto community were being duped while seeking help on Discord. When accessing links to support through trusted Web3 platforms, users were instead funneled into fraudulent servers featuring counterfeit Collab.Land bots—a tool normally used to verify wallet ownership and grant community access. These imposters turned a common trust signal into a gateway for exploitation.

Fake Crypto Verification Bots Lure Users Into Sophisticated Discord Trap

Security analysts have uncovered a dangerous new scam exploiting the trust crypto communities place in automated verification tools. Impostor bots posing as Collab.Land—the widely trusted service used to verify wallets and grant access to exclusive channels—are duping even seasoned users into handing over control of their digital assets.

A Digital Sleight of Hand

Victims are funneled through a convincingly forged Collab.Land flow. Once they connect their wallets on a cloned website, they’re prompted to sign deceptive transactions. These aren’t harmless confirmations; they’re silent authorizations that hand attackers the keys to their crypto holdings.

What makes this threat especially alarming is its connection to Inferno Drainer—a powerful malware suite thought to be defunct since late 2023. Contrary to public claims, the toolkit is not only active but operating with a new level of stealth and resilience.

Evasion at the Cutting Edge

This campaign employs a layered strategy that sidesteps detection and makes dismantling operations extremely difficult. Among its evasive methods:

  • Self-destructing smart contracts designed for one-time use, bypassing wallet alerts
  • Encrypted payloads on-chain to mask control infrastructure
  • Proxy-based communication for anonymized attacker access
  • Rotating phishing domains and redirect rules to slip past security filters

“Even if a domain is flagged or taken down, attackers simply shift to another in hours,” say Check Point researchers. “It’s a moving target by design.”

Vanity URL Hijacking: An Underrated Weapon

A particularly insidious tactic involves sniping expired Discord vanity URLs—the custom links like discord.gg/projectname. If a server loses its premium status, its custom link can be reclaimed. Threat actors monitor these drop-offs, swiftly registering lapsed URLs to lure users into clone communities. Many victims follow these links from old announcements, tweets, or websites, unaware they’re stepping into a trap.

Defense Tips From the Front Lines

To avoid falling victim to these advanced threats, researchers urge users to adopt a proactive security posture:

  • Only trust bots with official “Verified App” status on Discord
  • Avoid clicking random links—use saved bookmarks for key crypto tools
  • Review every wallet transaction prompt carefully—never sign in haste
  • Use “burner wallets” when exploring new projects or airdrops
  • Stay alert by following security updates from project teams

This blend of authentic-looking lures and technically advanced malware shows how phishing attacks are evolving. Even in a world of hardened wallets and smarter users, trust remains the most dangerous vulnerability.

More Articles & Posts