Turn off DMs from strangers in Discord server settings, enable two-factor authentication everywhere, never click links sent via DM (legitimate projects never DM you first), verify announcements only in official channels, and report/block fake accounts immediately. These five settings changes take two minutes and block 95% of crypto social media scams.

How to Secure Your Discord and Twitter From Crypto Scams

4 min read

The short version

Crypto scammers live on Discord and Twitter/X. They impersonate admins, create fake announcement channels, send phishing links via DM, and run fake giveaways. The attacks work because they look identical to legitimate messages. Your defense is not recognizing every scam (impossible) but configuring your accounts so scam messages never reach you in the first place.

How It Works

Discord security checklist: (1) Server Privacy Settings: for every crypto server you join, go to the server dropdown > Privacy Settings > disable Allow Direct Messages from Server Members. This alone blocks 80% of scam DMs. (2) General Privacy: Settings > Privacy & Safety > set who can send you friend requests to Friends of Friends or Nobody. (3) Two-factor authentication: Settings > My Account > enable 2FA with an authenticator app (not SMS, which is SIM-swappable). (4) Never click links in DMs. Period. Official mints, airdrops, and announcements are posted in public channels, never sent privately. If a mod DMs you a link, it is a scammer impersonating them. (5) Verify official channels: check the channel is listed in the server sidebar (not a lookalike DM or thread), check the poster has the correct role tag (Admin, Mod), and cross-reference with the project official website. Twitter/X security: (1) Enable 2FA (Settings > Security > Two-factor authentication). (2) Use a unique strong password not shared with any other service. (3) Ignore all reply bots under popular tweets (the ones saying claiming at xyz dot com). (4) Verify accounts by checking follower count, account age, and whether they are followed by other known legitimate accounts. (5) Never connect your wallet to a site linked from a tweet without independently verifying the URL matches the official project domain. Common attack patterns: fake admin DMs (you won a prize, click here), impersonated announcement channels (copy of real channel with phishing link), compromised real accounts (hacked admin posting malicious link briefly before recovery), reply-guy bots (under every major project tweet with fake mint links).

A fake support scam and how configured settings block it

You post in a DeFi project Discord: I am having trouble with my transaction. Within 30 seconds, you receive a DM from someone with the same profile picture and name as a moderator: Hi! I can help. Please connect your wallet to our support tool at support-defiproject.com to verify your transaction. This is a scammer. The link is a drainer site that will ask you to sign a malicious approval. With correct settings: you never see this DM because you disabled DMs from server members. The scam message goes to your message requests (which you never check) or is blocked entirely. Without settings: you might click the link, connect your wallet, sign what looks like a verification, and lose everything. The two-minute settings change prevented what could have been a total loss.

What People Get Wrong

  • Official project teams DM users to help

    They do not. Every legitimate crypto project states clearly: we will never DM you first. Support happens in public channels or through official support ticket systems on their website. Anyone DMing you claiming to be from a project is a scammer, regardless of how legitimate their profile looks.

  • Verified accounts cannot be scammers

    On Twitter/X: verified (blue check) accounts get hacked or purchased. Scammers buy aged verified accounts and rename them to impersonate projects. Always verify by checking: account handle (not just display name), follower overlap with known legitimate accounts, and tweet history (recently renamed accounts show gaps).

  • I can recognize scams so I do not need settings changes

    Scam sophistication increases constantly. AI-generated messages, pixel-perfect website clones, and compromised legitimate accounts make visual detection unreliable. The correct defense is structural: prevent exposure to the attack vector entirely (disable DMs) rather than relying on your ability to identify every variant.

Sources & Further Reading

Questions People Also Ask

What if I need to DM a mod for legitimate support?
Initiate the DM yourself (do not respond to unsolicited ones). Find the mod in the server member list, verify their role tag, and message them first. If they cannot help in public channels (rare), this is the safe way to reach them. The rule is: never respond to DMs you did not initiate.
Should I leave servers I do not actively use?
Yes. Every server you are in exposes you to DM scams from members of that server (unless you disabled DMs per-server). Leaving inactive servers reduces your attack surface. Keep only servers you actively participate in.
What about Telegram crypto groups?
Same principles. Disable who can add you to groups (Settings > Privacy > Groups > My Contacts). Disable who can message you (restrict to contacts). Never click links in Telegram group messages or DMs from strangers. Telegram has even less moderation than Discord, so the scam density is higher.

More in Security & Risk

See all →
Was this page helpful?

Page last checked