AI Deepfake Celebrity 'Double Return' Livestream Scam: Hijacking Accounts to Loop Fake CEO Giveaways and Drain Wallets
Victims are primarily retail investors aged 20 to 40 who hold crypto assets but lack strong security awareness. While scrolling through short videos or X (formerly Twitter), they see familiar entrepreneurs or exchange executives 'personally livestreaming giveaways' and naturally trust the visual evidence. Compounded by FOMO (fear of missing out)—fueled by bots in the comments section spamming 'received' or 'spots running out'—victims worry about missing free airdrops. Furthermore, due to a lack of understanding regarding wallet signatures and 'Approve' authorizations, they mistake these for standard claiming procedures. After scanning a QR code or clicking a link, their assets are drained within minutes. Some, hoping to 'test with a small amount,' end up granting full wallet control through a single malicious authorization.
Key Fields
FIELD STAMPSWho Gets Targeted
Victims are primarily retail investors aged 20 to 40 who hold crypto assets but lack strong security awareness. While scrolling through short videos or X (formerly Twitter), they see familiar entrepreneurs or exchange executives 'personally livestreaming giveaways' and naturally trust the visual evidence. Compounded by FOMO (fear of missing out)—fueled by bots in the comments section spamming 'received' or 'spots running out'—victims worry about missing free airdrops. Furthermore, due to a lack of understanding regarding wallet signatures and 'Approve' authorizations, they mistake these for standard claiming procedures. After scanning a QR code or clicking a link, their assets are drained within minutes. Some, hoping to 'test with a small amount,' end up granting full wallet control through a single malicious authorization.
骗局怎么运作
- Step 1: Material Forgery: Syndicates scrape public speeches and interview videos of prominent business leaders and exchange founders, using AI face-swapping and voice cloning to generate hours of fake, realistic, and 24/7 looping livestreams. The lip-syncing and audio are nearly perfect, making it difficult for the average viewer to distinguish from reality.
- Step 2: Channel Hijacking and Ad Injection: Fraudsters steal or purchase YouTube and X accounts with tens of thousands of followers, changing names and avatars to impersonate official accounts. They then run information flow ads to drive traffic, using narratives like 'Anniversary Community Reward' or 'Bitcoin Halving Commemorative Event' to create an aura of official authority.
- Step 3: The 'Double Return' Bait: The fake CEO claims during the stream that 'transferring 0.1 to 10 ETH or BTC to the event address will result in an immediate double return' or 'the first 1,000 people to connect their wallets will receive a free airdrop.' This creates an illusion of scarcity and instant reward, emphasizing that it is 'only available during the livestream.'
- Step 4: Redirecting to Phishing Sites: The livestream displays a QR code or short link, redirecting users to a pixel-perfect replica of an official website. The page contains a malicious smart contract designed to trick victims into connecting Web3 wallets like MetaMask.
- Step 5: Malicious Authorization to Drain Assets: When victims click 'Claim,' they are prompted to sign a 'SetApprovalForAll' or 'Permit' signature. Once confirmed, the thief's script immediately gains transfer permissions for all tokens and NFTs in the wallet, draining assets in bulk within seconds. On-chain transactions are irreversible.
- Step 6: Money Laundering and Evidence Destruction: Stolen funds are moved through cross-chain bridges, mixers, and multiple 'hop' wallets. After the theft, the livestream account is deleted or renamed, and the bot accounts in the comments are abandoned, breaking the chain of evidence and making it nearly impossible for victims to trace the funds.
红旗信号(看到这些快跑)
- 🚩 Any event promising 'transfer first, double return later' does not exist in legitimate financial systems or mainstream exchanges; if you see it, it is almost certainly a scam.
- 🚩 A livestream with a massive audience but no interaction, where the host ignores all comments, or the video loops with slight misalignment between lip movement and audio, is a classic sign of a pre-recorded or AI-generated stream.
- 🚩 The comments section is filled with identical bot messages like 'I received my return' or 'Thanks, CEO,' and the accounts are usually recently registered with no history.
- 🚩 Requests to connect your wallet and click 'Sign' or 'Approve' on an unfamiliar website to claim an airdrop; legitimate airdrops never require granting asset transfer authorization, nor do they ask for seed phrases or private keys.
- 🚩 The event channel is not an official verified account (no blue checkmark, recent registration date, username differs by one or two characters from the official one), and the link domain has subtle spelling differences from the official website.
- 🚩 Deliberate creation of countdowns and limited spots to pressure users into immediate action, leaving no time for verification or critical thinking.
真实案例
- Between 2024 and 2025, deepfake videos of Ripple CEO Brad Garlinghouse circulated on platforms like YouTube. In the fake videos, 'he' announced a 100 million XRP airdrop and directed users to a phishing site to connect their wallets. Ripple officially debunked this multiple times, and the scam was exposed by various international media outlets. (Source: https://coincu.com/news/ripple-ceos-deepfake-xrp-airdrop-scam/)
- In 2025, criminals used AI to forge a livestream of NVIDIA CEO Jensen Huang to conduct a cryptocurrency giveaway scam, inducing viewers to transfer funds to a designated address. Cybersecurity media outlet Cybernews reported on this, noting the rapid spread of deepfake livestreams impersonating tech giants.
- In February 2026, Hong Kong police dismantled a cross-border fraud syndicate that used AI deepfake technology to trick overseas victims into investing in virtual currencies, involving approximately HK$34 million. Nine individuals were charged with conspiracy to defraud and money laundering, with the case brought before the Eastern Magistrates' Court, highlighting the organized and cross-border nature of deepfake crypto scams.
- In March 2026, the Chinese-speaking community exposed a 'Google Coin' imitation scam: a 28-year-old internet professional, after seeing an AI face-swapped celebrity endorsement video on social media, attempted to claim a free airdrop. They fell into a high-fidelity fake wallet and phishing process, losing all assets within 24 hours—a typical case of a hybrid deepfake and phishing scam.
- In February 2026, Hong Kong police dismantled a cross-border fraud syndicate using AI deepfakes to lure overseas victims into virtual currency investments. The group used false statements to induce investments, defrauding over HK$34 million. 14 people were charged, with 9 facing conspiracy to defraud and money laundering charges at the Eastern Magistrates' Court. (Source: https://www.singtaousa.com/2026/02/10/news/china/deepfake-crypto-scam-fraud-charges)
Official Stance
- Since 2025, the China Securities Regulatory Commission (CSRC) and its local branches have issued 'Risk Warnings Regarding New Types of Illegal Securities and Futures Activities,' explicitly naming the new method of using AI technologies like voice and face synthesis to impersonate celebrities for fraud.
- In May 2026, South Korean exchange Bithumb and Ripple CTO David Schwartz publicly warned that AI deepfake and impersonation scams targeting crypto investors are increasing sharply, advising users not to trust any celebrity coin giveaway videos.
- The former CEO of Binance has repeatedly warned the community to be vigilant against deepfake video calls and livestream crypto scams using their likeness, emphasizing that the official team never promises returns on transfers in any form.
- Public security cyber-policing departments, anti-fraud centers, and internet information offices across various regions continue to conduct special crackdowns on the black market industry of AI-enabled telecommunications fraud and virtual currency theft, issuing preventive alerts through official channels.
How to Protect Yourself
- ✅ Verify Channel Authenticity: For any airdrop or livestream claiming to be official, always cross-verify via the exchange's official app and verified social media accounts (with blue checkmarks). Never interact through links provided in a livestream.
- ✅ Maintain Authorization Security: Do not connect your wallet to unfamiliar websites or sign 'Sign/Approve' transactions with unclear meanings. Regularly use tools like Revoke.cash to check and cancel suspicious historical authorizations.
- ✅ Isolate Hot and Cold Wallets: Store large assets in offline hardware or cold wallets. Use a hot wallet with a small balance for daily interactions so that even if an accidental authorization occurs, the loss remains controllable.
- ✅ Beware of Abnormal Promises like 'Double Returns': If you see the 'three elements'—high returns, upfront payment, and limited-time offers—it is a red flag. Pause all operations for at least a day to verify.
- ✅ Preserve Evidence and Seek Help: If you discover you have been scammed, immediately save screen recordings of the livestream, links, and transaction hashes. Report the incident to local police and seek assistance from security agencies for on-chain tracking, while revoking remaining authorizations to prevent secondary losses.
- https://coincu.com/news/ripple-ceos-deepfake-xrp-airdrop-scam/
- https://www.csrc.gov.cn/hainan/c105462/c7611108/content.shtml
- https://www.singtaousa.com/2026/02/10/news/china/deepfake-crypto-scam-fraud-charges
- https://chainplay.gg/blog/binance-ceo-warns-deepfake-crypto-scams/
- https://www.studioglobal.ai/zh-cn/discover/answers/what-recent-warnings-have-bithumb-and-ripple-6a0738c977ab35ad68ba2673