The Crypto Community Anti-Scam Playbook: Protecting Your Members in 2026
The Crypto Community Anti-Scam Playbook: Protecting Your Members in 2026

The Crypto Community Anti-Scam Playbook: Protecting Your Members in 2026

S

Sandy

Head of Content · Block AI

Quick Answer

Every crypto community with more than a few hundred members is a target for scammers. This playbook covers every scam vector hitting crypto communities in 2026, the infrastructure setup for Telegram and Discord, and exactly how to respond when a scam gets through.

If you run a crypto community and you have not been targeted by scammers yet, you will be. Every community with more than a few hundred members - especially any community associated with a live or upcoming token - is a target. The larger you grow, the more attractive the attack surface.

This guide is not about growth tactics or engagement strategies. It is specifically about protecting your members from the scam vectors that hit crypto communities daily in 2026, and building the infrastructure to catch and respond to them before the damage is done.


Why Community Scams Hurt More Than You Think

The immediate harm of a community scam is obvious: members lose money or get their wallets drained. But the secondary damage is often worse for the project itself.

When a scam hits your community, several things happen in parallel:

  • Members who were not targeted still lose trust. If the community allowed a scam to operate, what does that say about how the project is managed?
  • Screenshots circulate on X (Twitter), Reddit, and crypto forums. "Scam in [project name] Telegram" is exactly the kind of headline that gets shared, whether or not the project was responsible.
  • FUD amplifies. Bad actors who want to suppress the project's price will amplify scam incidents, sometimes even staging them for that purpose.
  • Journalists and influencers who cover crypto scams may pick it up.

The reputational cost far exceeds the monetary value of what members lost. A project that lets a scam run in its Telegram for 20 minutes while no moderator is active will be dealing with the aftermath for weeks.


The Scam Types Targeting Crypto Communities in 2026

Understanding what you are defending against is the first step. Here are the primary attack vectors:

Admin Impersonation

The most common scam across both Telegram and Discord. An attacker creates an account with a username nearly identical to a real admin - replacing a lowercase "l" with a "1", adding an underscore, or slightly misspelling the name - and contacts members directly claiming to be support. The message is always some variant of: "I've noticed an issue with your wallet/account. I can help you resolve it privately."

The goal is to get the victim to share their seed phrase, connect their wallet to a malicious site, or send crypto to a "verification address."

Fake Support Bots

Attackers deploy bots that mimic official support experiences. These bots respond to members who post a complaint or question in the public chat, offering to help via DM or through a link. The link leads to a wallet connection page that drains assets.

Wallet Drainer Links

Links posted in chat - often disguised as airdrop claim pages, staking portals, or official announcements - that, when a wallet is connected, execute malicious transactions draining NFTs and tokens. These links are increasingly sophisticated: they mimic the project's official website design almost perfectly.

Fake Airdrop DMs

Unsolicited DMs to community members announcing an exclusive airdrop, early access event, or reward. The DM includes a link that either collects credentials or drains wallets on connection.

Honeypot Token Promotions

Messages promoting a new token or trading opportunity posted by newly joined accounts. The promoted token is a honeypot: buyers can acquire it but cannot sell it.

Fake Partnership Announcements

Impersonators who claim to represent major projects - Binance, Coinbase, large protocols - and reach out to your team or announce fake partnerships in your community. The goal is to create fake credibility for a scam project, or to extract money from your team for "listing fees" or "integration costs" that do not exist.

QUICK WIN: Create a pinned message in every community you run that explicitly states: "Our admins will never DM you first. We will never ask for your seed phrase, private key, or wallet connection to solve a support issue. If anyone contacts you claiming to be from [project], it is a scam." Repeat this message at least once per week. Members forget. New members never saw it.


Telegram-Specific Anti-Scam Setup

Telegram requires deliberate configuration to be defensible. Here is the full setup:

Bot Configuration for Entry Control

Use Combot or Rose Bot to add captcha-style verification for new members. Members who join must complete a simple verification step before they can post or see full history. This immediately filters out most bot waves and spam accounts.

Combot specifically provides:

  • New member captcha (image-based or simple math verification)
  • Anti-flood controls (limit on messages per minute per user)
  • Detailed moderation logs accessible to admins
  • Analytics on member join rates, which helps spot coordinated join waves (a warning signal before a scam attack)

Rose Bot provides:

  • Welcome message system with rules acknowledgement
  • Warns system: track warnings per user across incidents
  • Federation banning: if you run multiple regional Telegram groups, a ban in one propagates across all linked groups. One confirmed scammer cannot simply move to your Korean language group after being banned from the English group.

No-DM Policy (Enforced and Communicated)

Establish and actively enforce a no-DM policy. This means:

  • All admins have their DMs turned off or set to "contacts only"
  • The project's policy is that no team member or admin will ever initiate a DM with a member for support purposes
  • This policy is pinned and repeated in the community regularly

Verified Admin List

Maintain a pinned message listing the exact usernames of all current admins, with clear instructions that anyone not on this list claiming to be an admin is not legitimate. Update this list immediately when admin personnel changes.

Slow Mode for High-Risk Periods

During major announcements, token launches, or price volatility events, enable Telegram's slow mode to limit how frequently individual members can post. This reduces the window for scammers to flood the chat with links during moments when members are excited and less cautious.

New Member Posting Restrictions

Consider restricting new members from posting links for their first 24-48 hours in the group. Rose Bot and Combot both support this configuration. The majority of scam posts come from freshly created accounts that join specifically to spam a link before being banned.


Discord-Specific Anti-Scam Setup

Discord's layered permission system allows more sophisticated protection than Telegram, but only if it is set up correctly.

Server Verification Levels

Discord has native verification levels accessible in Server Settings:

  • Medium: members must have a verified email on their Discord account
  • High: members must also be registered on Discord for more than 5 minutes
  • Very High: members must have a verified phone number on their account

For crypto projects, setting verification to at least "Medium" and preferably "High" is standard practice.

Role-Gating for Key Channels

Use role-gating to prevent unverified members from seeing or posting in high-value channels. Collab.Land for token holder verification, and welcome channel gate entry with rules acknowledgement enforced via a reaction role.

Ticket Systems Instead of DMs

One of the most effective structural changes you can make to a Discord server is replacing direct admin DMs for support with a ticket system. Bots like Ticket Tool allow members to open a private support thread visible only to them and the moderation team. This eliminates the surface area for impersonators to operate - members know real support happens in tickets, not DMs.

Bot Permission Hardening

Review which bots have admin-level permissions on your server. Many bots are granted administrator roles during setup out of convenience and are never downgraded. A compromised bot with admin permissions can mass-ban members, delete channels, or post malicious messages. Audit bot permissions quarterly.

QUICK WIN: Set up a private admin-only channel called "security-alerts" where your moderation bots log suspicious events in real time: new accounts posting links within minutes of joining, accounts with similar names to admins, rapid join waves from new accounts. This gives your mod team a single view of security events without having to monitor every channel simultaneously.


How to Respond When a Scam Has Already Hit Your Community

Even with all the right infrastructure, scams will occasionally get through. Your response speed and quality determine how much damage follows.

Immediate Steps (First 10 Minutes)

  1. Remove the scam content from the community immediately. Delete the message or post.
  2. Ban or mute the account responsible. Do not just mute - ban.
  3. Post a community warning immediately, in plain language: "A scam link was posted in this group [X minutes ago]. Do not click it. It has been removed. Your admins are the only ones authorised to communicate official information. If you clicked the link, do not connect your wallet further."
  4. If the scam involved a wallet drainer: direct members to revoke wallet approvals at revoke.cash or a similar approval revocation tool.

Within the Hour

Coordinate a statement from the core team. Pin this statement. Alert your moderation team across all platforms immediately - coordinated scam attacks often hit multiple platforms simultaneously.

Within 24 Hours

Conduct a post-incident review: how did the scam get through? Was it because moderation coverage was thin? Was the bot configuration insufficient? Identify the gap and fix it.


Staff Security Hygiene

2FA Requirements

Require all admins and moderators to have two-factor authentication enabled on every account: Telegram, Discord, email. Authenticator app 2FA is significantly more secure than SMS-based 2FA.

SIM Swap Protection

SIM swap attacks, where an attacker transfers a target's phone number to a SIM they control to bypass SMS 2FA, are a known vector in crypto. Staff should use authenticator apps rather than SMS for all security-critical accounts.

No Third-Party Admin Tools

Prohibit moderators from using third-party "admin helper" tools that request access to their Telegram or Discord accounts. Many of these tools are credential harvesters.

Wallet Separation

Any moderator or admin who also holds project tokens should keep those tokens in a separate wallet that is not connected to any admin-related device or account.