Gunjo · Business Intelligence for the AI Era
← Sticker Wall SCAM · DETAIL

Deepfake CEO Internal Leak Airdrop Double Harvest: Impersonating executives via forged private chat videos for inside tips, fake KYC for identity theft, and chained wallet phishing

Primary victims are cryptocurrency investors and Web3 practitioners aged 25 to 45, especially intermediate users holding moderate amounts of mainstream tokens who lack sufficient security awareness. Highly sensitive to airdrop opportunities due to tracking project updates long-term, they embrace a shortcut mentality toward insider information while fearing missing out on early dividends, leading them to voluntarily lower verification thresholds. The visual impact of deepfake videos breaks through the final psychological defense of seeing is believing, causing them to abandon cross-verification under the dual pressure of urgency and exclusivity, voluntarily uploading ID documents and connecting wallets for signature, ultimately suffering simultaneous losses of personal identity leakage and on-chain asset theft.

SCAM

Key Fields

FIELD STAMPS
IndustryFintech
RegionGlobal
ScaleGray Market
ChannelOther
⚠️ This entry compiles scam tactics and public reporting; it is not investment or legal advice. Content is organized from public reporting and third-party complaint platforms; this site does not make any finding of illegality against the parties involved, who may contact us for correction if they object. If you encounter fraud, report it to the police immediately (110 / anti-fraud hotline 96110 in mainland China; local police overseas).

Who Gets Targeted

Primary victims are cryptocurrency investors and Web3 practitioners aged 25 to 45, especially intermediate users holding moderate amounts of mainstream tokens who lack sufficient security awareness. Highly sensitive to airdrop opportunities due to tracking project updates long-term, they embrace a shortcut mentality toward insider information while fearing missing out on early dividends, leading them to voluntarily lower verification thresholds. The visual impact of deepfake videos breaks through the final psychological defense of seeing is believing, causing them to abandon cross-verification under the dual pressure of urgency and exclusivity, voluntarily uploading ID documents and connecting wallets for signature, ultimately suffering simultaneous losses of personal identity leakage and on-chain asset theft.

骗局怎么运作

  • Step 1: Information Gathering and Target Profiling. Scammers collect public speech videos, podcast audio, and social media updates of target project executives through public channels on X, Discord, and Telegram, training real-time drivable facial and voiceprint cloning models using deep learning algorithms. Simultaneously, they sort public on-chain token holder lists and active airdrop participation addresses, filtering intermediate investors holding moderate mainstream tokens and frequently interacting with the community as precision-targeted victims.
  • Step 2: Private Domain Penetration and Identity Masquerade. Scammers create Telegram accounts disguised as core community contributors, infiltrating target user private groups using usernames and avatars highly similar to genuine community admins. Establishing initial trust as community operators or early investors, they privately add high-value targets as contacts and engage in weeks of daily interaction, gradually building trust capital and a sense of intimacy.
  • Step 3: Deploying Deepfake Videos to Create Urgency. Scammers send a deepfaked CEO video clip in private chats, claiming it is an internally leaked unreleased announcement. In the video, the forged CEO uses a natural tone to announce an upcoming limited-time airdrop with limited slots, implying only those with inside information can participate, creating a strong sense of exclusivity and time pressure. A shortened link closely mimicking the official domain is attached at the end to guide clicks.
  • Step 4: Fake KYC for Identity Harvesting. After clicking the short link, victims are redirected to a highly simulated airdrop claim page whose design style is almost identical to the project's official website, requiring users to complete KYC verification before claiming tokens. Victims upload ID documents, handheld selfie videos, and proof of address. These data are intercepted in real-time by scammers and resold to dark web identity trading markets, or used to open shell bank accounts and evade real-name verification later.
  • Step 5: Wallet Connection and Asset Drainage. Upon completing the fake KYC, the page prompts users to connect their wallets to receive airdrop tokens. After clicking connect, victims are guided to a malicious smart contract interaction page. Disguised as a normal token claim operation, it actually triggers a batch transfer authorization contract. Once the victim signs and confirms, scammers immediately invoke the contract to transfer all tokens and native assets from the wallet to a controlled address for rapid cross-chain laundering.
  • Step 6: Multi-Tier Laundering and Trace Removal. Scammers use cross-chain bridges and mixers to rapidly launder stolen assets while deleting Telegram accounts and counterfeit websites. After all chat logs and page caches are cleared, they register new identities to enter the next target group and cycle the crime, forming a sustainable industrialized fraud assembly line.

红旗信号(看到这些快跑)

  • 🚩 CEO internal leak videos are disseminated exclusively through private chat channels rather than official project announcement channels. Any legitimate airdrop is publicized synchronously via official X accounts, official websites, and GitHub repositories, never relying on private messaging links to transmit critical information. Any airdrop claiming to be restricted to insiders should immediately raise high suspicion.
  • 🚩 Claiming the airdrop requires completing KYC verification and uploading ID documents. Legitimate crypto airdrops typically only require wallet signature verification of address ownership and rarely demand sensitive personal information such as ID documents and handheld selfies. If the verification process differs from official project announcements, it is a high-risk signal.
  • 🚩 The target domain of the short link redirection has subtle differences from the project's official domain. Scammers often use zero-width character insertions, homoglyph substitutions, or additional subdomain prefixes to spoof official domains. Character-by-character comparison of domain spelling can reveal inconsistencies.
  • 🚩 Micro-expressions of the CEO in the deepfake video exhibit unnatural traits. These include abnormally low blink rates, slight mismatches between lip movements and audio tracks, and gradient artifacts or blurred edges around the face during head turns. Professional deepfake detection tools or frame-by-frame slow-motion analysis can identify these flaws.
  • 🚩 Strangers in the community proactively initiate private chats offering exclusive investment opportunities. Genuine project community operations personnel follow strict communication protocols and identity verification procedures, never delivering unannounced airdrop information via private chats. Any new contact proactively private messaging investment recommendations should be treated as high risk.

真实案例

  • In August 2026, according to China Economic Net, an anti-fraud center disclosed an AI-synthesized video call fraud case where criminals used deepfake technology to conduct real-time video calls with a victim, impersonating an acquaintance and swindling 1.86 million RMB under the pretext of an emergency investment remittance. This case demonstrated that real-time deepfake video calls have reached a realism level capable of deceiving ordinary users, prompting anti-fraud centers to classify such cases as a high-incidence emerging fraud type and issue special alerts.
  • In 2026, The Beijing News exposed a case where a college student used AI facial forgery video technology to impersonate others and fraudulently swipe over 50,000 RMB. The report revealed that AI face-swapping technology has achieved large-scale circulation within black and grey industrial chains, with extremely low costs across the entire process from model training to video generation, and related technical services are priced openly on underground forums. Similar technologies have been employed by fraud syndicates to forge corporate executive videos for airdrop and investment scams.
  • In 2026, Moonshot AI (Kimi) issued a solemn police report stating that bad actors impersonated the company to fabricate internal funds and old stock quota information for fraud, leveraging the brand reputation of an AI unicorn enterprise as a fake financing traffic entry point to divert potential investors to counterfeit platforms and execute financial scams. This case indicates that fraud models utilizing well-known corporate brands for deepfake endorsement are rapidly spreading.
  • In August 2026, according to Project Home, a Ponzi scheme impersonating VAST.AI spread across multiple regions. Overseas syndicates used the name of an AI unicorn enterprise that had just raised 1 billion RMB to build a multi-level marketing fund scheme, utilizing deepfaked corporate executive endorsement videos to enhance credibility and induce users to participate in fake token airdrops and investment plans, with victims reporting cases in multiple regions.
  • In August 2026, citing Jinwan Bao via China Economic Net, the anti-fraud center dissected deepfake tactics: criminals swindled 1.86 million RMB using AI-synthesized video calls. (Source: [http://fashion.ce.cn/tjyd/202608/t20260817_3150236.shtml](http://fashion.ce.cn/tjyd/202608/t20260817_3150236.shtml))
  • In August 2026, citing CCTV News via The Beijing News, the People's Court of Yuhua District, Changsha City, Hunan Province tried a case involving criminals using AI-generated facial forgery videos to illegally swipe bank cards, where a college student purchased AI facial forgery video technology to illegally swipe over 50,000 RMB. (Source: [https://www.bjnews.com.cn/detail/1786880055129313.html](https://www.bjnews.com.cn/detail/1786880055129313.html))

Official Stance

  • In August 2026, the anti-fraud center issued a specialized early warning on deepfake fraud, dissecting the complete routine of an AI-synthesized video call swindling 1.86 million RMB, reminding the public to maintain high vigilance against transfer requests and investment opportunities in video calls, and recommending multi-channel cross-verification of identity before making financial decisions.
  • In August 2026, Lianhe Zaobao reported that relevant authorities in Singapore issued preventive guidelines against lifelike deepfake technology, reminding the public to exercise caution and verification when facing video information involving capital flows, and to maintain skepticism toward airdrops and investment opportunities unconfirmed by official channels.
  • In 2026, ATFX issued an investor warning announcement reminding vigilance against AI-forged friend and relative video scams, pointing out that deepfake technology has been widely used to impersonate acquaintances or authority figures for fraud, and investors should not make financial transfer or digital asset operation decisions based solely on video content.

How to Protect Yourself

  • ✅ Before participating in any cryptocurrency airdrop, verify the authenticity of airdrop announcements exclusively through the project's official website, official X/Twitter account, and GitHub repository. Never jump directly to claim pages via short links in private messages, and always manually type the official domain to visit.
  • ✅ Maintain a zero-trust attitude toward any airdrop activity requesting sensitive personal information uploads, such as ID documents and handheld selfie videos. Legitimate airdrops typically require only wallet signature verification; if KYC is strictly necessary, confirm it separately via links in official project announcements before proceeding.
  • ✅ Use hardware wallets to isolate large assets, carefully review smart contract interaction details item by item when connecting wallets, immediately terminate operations if a token claim prompts an authorization-type transaction request, and never sign and confirm without verifying contract security using security tools.
  • ✅ Upon receiving private messages claiming internal news or time-limited airdrops, immediately capture and save screenshots of all chat records, video files, and link addresses as evidence, verify with official project verification channels, and submit clue reports to local anti-fraud centers or the 12321 cyber illicit information reporting platform.