DeFi Teddy|Sep 27, 2026 11:58
"Personal experience: Almost got hacked just now!
There have been so many hacking incidents recently, from fomopeek to bitget. Let me share a detailed account of my own experience with social engineering.
1️⃣ The hacker first contacted me via Telegram (TG), claiming to be an investment manager from a certain institution interested in investing in xhunt. They shared their institution's website and Twitter account. I checked the website, which had investment cases, and their Twitter had a long history with some mutual connections following them.
2️⃣ I asked them to verify their identity, and they sent me an email from an official-looking address, which seemed pretty legit.
3️⃣ Then the hacker added me to a group chat, where their "CEO" and another "BD" (Business Development) were present. In the group, the BD asked a few seemingly professional questions, like how we plan to expand into international markets and how we attract non-crypto users to our product.
4️⃣ They scheduled an online meeting using a legit platform, Calendly, and sent a Google Meet invitation link before the meeting started.
5️⃣ During the meeting, the BD appeared on video and said their investment manager and CEO would join later. We started chatting, and they asked about our business model and valuation—everything seemed normal.
7️⃣ Then things got weird. About 10 minutes in, the investment manager and CEO claimed they couldn’t connect to the Google Meet link and sent a screenshot of a network error. They suggested switching to another meeting link, and the BD sent a new Google Meet link, but the others still couldn’t connect.
8️⃣ They then proposed switching platforms. I suggested Zoom, but they recommended using Kaokao, saying it’s a well-known platform. They sent me a link with a Kaokao domain, which immediately raised my suspicions. I refused to use other platforms and said we could discuss further via email. They said they’d send me a draft collaboration proposal later, and the meeting ended early.
9️⃣ After the meeting, I used Grok’s web tool to check the link they sent, and sure enough, it flagged the site as a phishing website!
Lessons learned:
1️⃣ Before engaging in detailed discussions, conduct deeper due diligence (DD). For example, you could contact the projects listed on their website to verify if the institution is legitimate.
2️⃣ Use Grok to check if a Twitter account might be a scam.
3️⃣ Never click on suspicious links, download any software, or open documents sent by strangers.
4️⃣ Assume any Telegram account that proactively DMs you is a scam until proven otherwise.
#CyberSecurity #CryptoSafety #PhishingAlert #StaySafe
Share To
Timeline
HotFlash
APP
X
Telegram
CopyLink