How @discord is a scammers paradise 🏝

A story /🧵 on how the lack of a trust layer 🤝 for the internet creates a breeding ground for scams / scammers with #red flags 🚩 to watch out for along the way.
1/ First, some team background. A lot of our team have backgrounds in fraud prevention / #investigation 🕵️‍♂️ which we’re extremely lucky to have as it prevents 🛑us falling for what you’re about to read.
2/ Around 2 weeks ago we were approached for a transaction via someone out of the blue on @telegram.

We’ve had plenty of these reach outs be incredible so only a small 🚩 here.
3/ Myself and our excellent CFO, @javkhattak discussed between ourselves whether it made sense and agreed it had upsides for us so pending negotiation would go for it. 👉
4/ After some pretty relaxed negotiations, we reached an agreement and decided to get down to #KYC (know your customer) and paperwork 📝 so we knew who we were dealing with properly, which is when the red flags started to appear.
5/ 🚩1: other party, “let’s just do the transaction then deal with the paperwork afterwards”.



We’ve seen this before but it’s just not the way we do things at @cheqd_io so pressed for KYC docs and a signed agreement before going any further.⏭
6/ 🚩2: whilst the other party’s passport looked legitimate, their proof of address was out of day by a year.

When challenge they were on “holiday” which made for 🚩3.
7/ To feel comfortable with the proof of address, we asked for a selfie of the other party with their passport which they did do.
8/ 🚩4: Whilst we were seeing red flags by now, we sent the agreement over on good faith. When this was signed within a few minutes without negotiation or feedback, we knew where this was going! 🙅
9/ After this we decided to play along to see how they would attempt to scam us. The 🚩s started coming thick and fast. 🚩5 was the request to switch to @discord, aka scammers paradise.

🚩6 was a sudden increase in speed and pressure as we approached close.
10/🚩7: Then appeared a new partner of the other we had never spoken with before in the group chat we had both joined (or so we thought, more on this later!)

🚩8: They proposed one of myself and @javkhattak as an escrow rather than a known independent organisation who we knew.
11/ This is when the fun really started. By now, myself and @javkhattak were on the phone together to see how things worked out.

I volunteered and we started working through the transaction steps.
12/ 🚩9 was more of a 🚨, since myself and @javkhattak were on a call, the only message we needed to share were for the #scammer’s benefit which meant we quickly spotted messages that neither of us would need to write to each other or were factually incorrect.
13/ This was the moment we had been waiting to investigate the #scam process🕵️‍♂️.

Drumroll!🥁



We had been invited to separate chats in discord with a fake Fraser and fake Javed respectively with the username and profile pictures spoofed to look like each of us.
14/ To be thorough we kept going and lo and behold, the wallet addresses I was sending in one chat were not the addresses that Javed received in his chat.🚨🚨

We had our proof! 🔎
15/ I had to leave for an excellent AMA with @CosmosClub_ and left @javkhattak to break the news that they had been rumbled 👀.

They played dumb to the last accusing us of attempting to defraud them, even after myself and Javed invited our real selves into both chats!
16/ Reflecting afterwards, we still had more controls to prevent falling for this, e.g. checking addresses with each other over a channel we trust, e.g. a call, but thoroughly enjoyed playing along 🎭 once we sussed it was a scam and having our gut feelings confirmed!
17/ This is the same modus operandi that targeted @opensea users:



bleepingcomputer.com/news/security/…
18/ Two items before we wrap up:



1. Every so often we have an experience that exemplifies why we do what we do at @cheqd_io, this was a perfect example, we need to enable trust and prevent this happening to others!
2. Would the community be interested in us documenting these flags and the scams to watch out for?

• • •

Missing some Tweet in this thread? You can try to force a refresh
 

Keep Current with Fraser Edwards

Fraser Edwards Profile picture

Stay in touch and get notified when new unrolls are available from this author!

Read all threads

This Thread may be Removed Anytime!

PDF

Twitter may remove this content at anytime! Save it as PDF for later use!

Try unrolling a thread yourself!

how to unroll video
  1. Follow @ThreadReaderApp to mention us!

  2. From a Twitter thread mention us with a keyword "unroll"
@threadreaderapp unroll

Practice here first or read more on our help page!

More from @fraser_again

Jun 11
#web5 is a genius marketing move to capture #SEO for what is mostly self sovereign identity #SSI but the key part is, it's the basis for #decentralised #twitter which we saw the first hints of at internet identity workshop #IIW

Some more thoughts👇

1/ First up, this is exactly the publicity that #SSI has been missing for global adoption!

There has been a great and growing community beavering away on this for years but the dam is finally breaking on awareness and adoption.
2/ @blocks' #web5 project is being built by longstanding leaders in this community like @csuwildcat.

They're also members of both Chain Agnostic Standards Alliance and @DecentralizedID (as is @cheqd_io). This means it's going to be built in the right way

github.com/ChainAgnostic/…
Read 14 tweets
May 25
1/ Soul Bound Tokens (SBTs): verifiable credentials with better branding (?) but much worse privacy behaviour

Strange to see this from @VitalikButerin given he co-authored a paper which forms a component of self-sovereign identity (SSI):
danubetech.com/download/dpki.…
2/ Let’s first take some of the use-cases in the paper:

- University degrees: Already done using VCs by @IdentityRamp
- Certifications: being rolled out for doctors by @truu_id, @CondatisUK & @evernym amongst others

Not soon to come, either done or being productionised Image
3/ Or another:

Issuing credentials to attendees of a conference. This was done around 4 years ago by @esatus_SOWL, @trinsic_id amongst others at #InternetIdentityWorkshop Image
Read 17 tweets
Feb 8
A prime example of the #internet missing a functional “identity layer”

In this case, resulting in a toothless policy publicised on #internetsafetyday

🧵👇
1/ A previous version of this was proposed in 2019 and subsequently dropped as unworkable.

theguardian.com/culture/2019/o…
2/ Little has changed since then and if this statement in the BBC article is true, then these measures will likely be meaningless.
Read 12 tweets
Jan 21
What connects @Apple #Airtags, @ethereum (#Ethereum) naming service (#ENS) and identity using #NFTs?

🧵👇
1/ The law of unintended consequences, specifically unintended tracking.

Read on for the parallels and contrasts
en.wikipedia.org/wiki/Unintende…
2/ Whilst #airtags were designed to track "things" they certainly weren't designed to stalk people as they are.
bbc.co.uk/news/technolog…
Read 9 tweets
Jan 20
1/ 2 members of our team ( one was me) almost missed flights recently and a 3rd actually did. More airlines & airports need to adopt @IATA TravelPass which implements #SSI for aviation.

My (definitely not unique) frustrating story working back from departure (the worst bit) 👇
2/ To return to the UK I needed:
- Passport
- Passenger locator form
- Vaccine certificate
- Antigen or PCR test
Because airlines are fined for allowing people to travel who shouldn’t be, the front desk was checking the details against each other, e.g. passport numbers.
3/ Note, they weren’t checking that the documents were legitimate, just that the name and passport details matched. As if fraudsters are that useless...
Read 10 tweets

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just two indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member ($3/month or $30/year) and get exclusive features!

Become Premium

Don't want to be a Premium member but still want to support us?

Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal

Or Donate anonymously using crypto!

Ethereum

0xfe58350B80634f60Fa6Dc149a72b4DFbc17D341E copy

Bitcoin

3ATGMxNzCUFzxpMCHL5sWSt4DVtS8UqXpi copy

Thank you for your support!

Follow Us on Twitter!

:(