Gram Doubts: Scammers Develop Scheme with New Service in Telegram

cryptonews.ruPublié le 2026-08-07Dernière mise à jour le 2026-08-07

Résumé

Cybercriminals are exploiting news surrounding Telegram and its founder Pavel Durov to launch new phishing schemes targeting the Gram cryptocurrency. They create fake websites and Telegram bots, designed to mimic official platforms, to pressure users. Common tactics include urging people to urgently exchange old tokens, withdraw funds ahead of an alleged platform block, or receive free crypto through special services. Experts note a sharp rise in suspicious domain registrations mentioning Telegram, Durov, or Gram, with phishing domains doubling recently. The scams rely not on hacking technology, but on psychological manipulation—leveraging fear of loss, promises of easy profits, and a false sense of urgency. The fraudsters build complex "ecosystems of false trust," guiding victims from search results to channels, bots, and ultimately fake sites to steal seed phrases or authorize transactions. Officials warn that Telegram does not distribute cryptocurrency or conduct token conversions via third-party sites. The primary defense remains user caution: avoid clicking promotional links, never enter seed phrases on external sites, and use only official Telegram services for crypto wallets.

Scammers have begun actively using news surrounding Telegram and Pavel Durov (included in the list of terrorists and extremists in Russia) to spread new phishing schemes related to the Gram cryptocurrency. Users are offered to urgently exchange old tokens, withdraw funds before the alleged upcoming messenger block, or receive free cryptocurrency through special services. According to experts, criminals create fake websites and Telegram bots, designed in the platform's official style. The main tools of influence are the fear of losing funds and promises of easy earnings.

Fake Telegram Services

Following the emergence of news surrounding Telegram, cybersecurity specialists recorded a sharp increase in suspicious activity. According to them, malicious actors began mass-registering domains mentioning Telegram, Pavel Durov, and the Gram cryptocurrency — the native token of the TON blockchain — as well as launching fake services promising users to preserve access to their assets or quickly earn money on the new "coin".

— After July 30th, SBA analysts have recorded increased registration activity around Telegram. Over six days, the number of new domains mentioning Telegram or Durov grew by approximately 18%. At the same time, the number of domains with potential signs of phishing doubled. The batch registration of 11 similar domains at once on August 3rd, masquerading as Telegram verification and protection services, is particularly noticeable, — Sergey Trukhachev, head of the Smart Business Alert service at ESA PRO, told Izvestia.

According to him, scammers actively exploit user concerns related to Telegram's future. People are convinced that services affiliated with the messenger's founder will supposedly soon become unavailable, so it is necessary to transfer funds or use a new crypto service as quickly as possible.

Criminals practically immediately began using the news hook to create new storylines, noted Pavel Kovalenko, director of the fraud counteraction center at Informzashchita. According to him, the launch of the built-in non-custodial Gram wallet opened additional opportunities for malicious actors. Users have not yet had time to understand the new function, which scammers actively exploit by passing off fake services as official Telegram tools.

A similar assessment was given by Fedor Chunizhekov, head of the research group at Positive Technologies. He noted that high-profile events traditionally become the basis for new social engineering scenarios.

— The user is told that it is necessary to "urgently confirm the account," "withdraw assets before the block," "exchange old coins," "get free tokens," or "register in the new service before others." Precisely the feeling of urgency, the promise of free benefit, and the exclusivity of the offer become the main tools of manipulation and psychological pressure, — he explained.

Systemic Approaches of Scammers

The main task of scammers is to convince a person to voluntarily provide access to their crypto wallet. After clicking the link, the user is asked to authorize via Telegram, enter a seed phrase, or confirm a transaction, after which the assets are irrevocably transferred to the criminals, Pavel Kovalenko explained.

In essence, criminals bet not on hacking technologies, but on psychological pressure, added Igor Bederov, chairman of the Council on Countering Technological Offenses of the NSB KS of Russia, founder of Internet-Rozysk.

Scammers don't hack complex blockchain protocols; they hack gullibility and the craving for 'freebies' against the backdrop of panic headlines. Moreover, the number of registrations for phishing domains with words like gram, wallet, convert, and gift in conjunction with Telegram has increased dozens of times, — the expert emphasized.

At the same time, fraudulent campaigns are becoming increasingly complex. Today, malicious actors build entire trust chains, sequentially moving the user from search results to a Telegram channel, then to a bot, and onto a fake website, said Mikhail Shurygin, chairman of the ROCIT commission on cloud technologies, hosting, and information security.

— We can speak of a transition from primitive distribution of malicious links to creating entire "ecosystems of false trust," — he noted.

Quality design, the presence of reviews, support services, and even a secure connection are no longer considered signs of a resource's reliability. It is important for users to remember that Telegram and its official services do not conduct cryptocurrency giveaways or token conversions through third-party websites or bots, the expert reminded.

Malicious actors also actively use phishing pages and cryptodrainers — malicious programs that prompt users to independently connect crypto wallets to fake sites or enter Telegram login credentials under the pretext of receiving free tokens and other bonuses, added Maria Sinitsyna, senior analyst of the digital risk protection department at F6 company.

— The main vulnerability in 99% of such attacks lies at the intersection of technology and human psychology, — noted Igor Bederov.

The interviewed experts agree that the main protection for digital assets remains caution. They recommend not clicking on advertising links, not entering seed phrases and confirmation codes on third-party resources, and using only official Telegram services when working with crypto wallets.

end-content

Cryptos en tendance

Questions liées

QWhat is the main scam method that fraudsters are using around Telegram and the Gram cryptocurrency, according to the article?

AFraudsters are using phishing schemes, creating fake websites and Telegram bots that mimic the official platform's style. They exploit users' fears of losing funds or offer promises of easy profits, convincing people to urgently exchange old tokens, withdraw funds due to an alleged upcoming messenger block, or receive free cryptocurrency through special services.

QWhat specific increase in suspicious domain registration activity was reported following the news about Telegram?

AAnalysts from SBA reported that in the six days after July 30, the number of new domains mentioning Telegram or Durov grew by approximately 18%. The number of domains with potential signs of phishing doubled. There was a notable batch registration of 11 similar domains on August 3, masquerading as Telegram verification and protection services.

QWhat is the primary goal of the scammers when a user clicks their link?

AThe main goal is to convince the person to voluntarily provide access to their crypto wallet. Users are asked to authorize via Telegram, enter their seed phrase, or confirm a transaction, after which their assets are irreversibly transferred to the criminals.

QHow have fraudsters evolved their campaigns beyond simple malicious link distribution, as described in the article?

AThey have moved to building complex 'chains of trust' or entire 'ecosystems of false trust.' This involves guiding a user sequentially from search engine results to a Telegram channel, then to a bot, and finally to a fake website, making the scam appear more legitimate and sophisticated.

QWhat key advice do experts give for protecting digital assets from such scams?

AExperts advise users to be cautious: not to click on advertising links, not to enter seed phrases or confirmation codes on third-party resources, and to use only official Telegram services when working with crypto wallets. They emphasize that a quality design, positive reviews, or a secure connection are no longer reliable signs of a trustworthy resource.

Lectures associées

La tokenisation des RWA passe à l'étape suivante : quel est l'avantage qui prend vraiment du temps à se construire ?

Le jetonnement d'actifs du monde réel (RWA) entre dans une nouvelle phase où l'avantage concurrentiel se déplace de la simple capacité d'émission vers la construction d'un avantage durable par une exécution opérationnelle de long terme. Si l'infrastructure technique pour l'émission de jetons (custodie, conformité, blockchain) est désormais mature, la question clé devient : que se passe-t-il après l'émission ? La pérennité des projets RWA dépendra de leur capacité à créer un « étage de réserve » (Reserve Layer) fiable sur la blockchain, reposant sur deux piliers. Premièrement, l'actif sous-jacent doit être adapté à un rôle de réserve. Cela implique une valeur déterminable, des caractéristiques standardisées et des marchés liquides (ex : obligations d'État à court terme, or physique). Les crédits privés, bien que valorisables, présentent une hétérogénéité qui les rend moins idéaux comme actifs de réserve purs. Deuxièmement, et c'est l'avantage le plus long à construire, la qualité opérationnelle de l'émetteur est cruciale. La sécurité, les audits indépendants réguliers, les mécanismes de rachat éprouvés, la gestion de la liquidité et les intégrations avec l'écosystème DeFi doivent fonctionner de manière fiable, cycle après cycle. C'est l'accumulation de cette « trace » ou preuve opérationnelle sur plusieurs années, dans différentes conditions de marché, qui construit une confiance inaltérable. Cette confiance permet ensuite une adoption institutionnelle plus large, une liquidité plus profonde et une utilité accrue comme collatéral, créant un cercle vertueux. Ainsi, la combinaison gagnante est celle d'un actif de haute qualité intrinsèque (haute « applicabilité de réserve ») soutenu par un émetteur démontrant une discipline opérationnelle élevée et un historique vérifiable. C'est cette fondation qui transforme un jeton RWA en une véritable infrastructure financière durable pour la finance décentralisée.

marsbitIl y a 10 mins

La tokenisation des RWA passe à l'étape suivante : quel est l'avantage qui prend vraiment du temps à se construire ?

marsbitIl y a 10 mins

Claude Code Facilement Piraté avec un Simple Outil Factice

L'outil d'assistance à la programmation Claude Code a été facilement compromis par une attaque en deux étapes exploitant un "mode gap". Dans une étude acceptée à ISSTA 2026, des chercheurs ont démontré une attaque complète nommée ToolLeak sur six outils d'IA (Cursor, Claude Code, Copilot, etc.). Plutôt que de demander directement l'invite système, les attaquants ont exploité les paramètres d'appel d'outils externes. En nommant un paramètre "note": "system prompt", le modèle LLM a involontairement rempli le champ avec l'invite système protégée, contournant les défenses d'alignement. Cette méthode a obtenu une similarité sémantique de 0.891 à 0.958 avec l'invite originale. Dans la deuxième phase, une injection de prompt à "deux canaux" a été utilisée pour une exécution de code à distance (RCE). Un outil malveillant nommé `workspace_manager` a été enregistré. Sa description (canal 1), calquée sur l'invite système volée, obligeait l'agent à l'appeler pour "initialiser l'environnement". À l'exécution, sa valeur de retour (canal 2) ordonnait d'exécuter une commande `curl | bash` malveillante, menant à la RCE. Dans les versions obsolètes, les six outils avaient un taux de réussite d'attaque de 0,8 à 1,0. Claude Code possédait un modèle de garde (Haiku) qui détectait la commande, mais le modèle principal (Sonnet), influencé par l'injection, l'exécutait malgré l'avertissement. Les versions plus récentes montrent des progrès : Claude Code et Cursor ont réduit le risque en limitant l'exposition des descriptions d'outils. Cependant, des outils comme Cline restent vulnérables. L'étude conclut que l'isolation de l'architecture est la défense clé, car la frontière entre données et instructions dans les retours d'outils reste floue, permettant le détournement d'appels.

marsbitIl y a 15 mins

Claude Code Facilement Piraté avec un Simple Outil Factice

marsbitIl y a 15 mins

Trading

Spot

Articles tendance

Comment acheter GRAM

Bienvenue sur HTX.com ! Nous vous permettons d'acheter prev. Toncoin (GRAM) de manière simple et pratique. Suivez notre guide étape par étape pour commencer votre parcours crypto.Étape 1 : Création de votre compte HTXUtilisez votre adresse e-mail ou votre numéro de téléphone pour ouvrir un compte sur HTX gratuitement. L'inscription se fait en toute simplicité et débloque toutes les fonctionnalités.Créer mon compteÉtape 2 : Choix du mode de paiement (rubrique Acheter des cryptosCarte de crédit/débit : utilisez votre carte Visa ou Mastercard pour acheter instantanément prev. Toncoin (GRAM).Solde :utilisez les fonds du solde de votre compte HTX pour trader en toute simplicité.Prestataire tiers :pour accroître la commodité d'utilisation, nous avons ajouté des modes de paiement populaires tels que Google Pay et Apple Pay.P2P :tradez directement avec d'autres utilisateurs sur HTX.OTC (de gré à gré) : nous offrons des services personnalisés et des taux de change compétitifs aux traders.Étape 3 : stockage de vos prev. Toncoin (GRAM)Après avoir acheté vos prev. Toncoin (GRAM), stockez-les sur votre compte HTX. Vous pouvez également les envoyer ailleurs via un transfert sur la blockchain ou les utiliser pour trader d'autres cryptos.Étape 4 : tradez des prev. Toncoin (GRAM)Tradez facilement prev. Toncoin (GRAM) sur le marché Spot de HTX. Il vous suffit d'accéder à votre compte, de sélectionner la paire de trading, d'exécuter vos trades et de les suivre en temps réel. Nous offrons une expérience conviviale aux débutants comme aux traders chevronnés.

264 vues totalesPublié le 2026.06.15Mis à jour le 2026.08.20

Comment acheter GRAM

Discussions

Bienvenue dans la Communauté HTX. Ici, vous pouvez vous tenir informé(e) des derniers développements de la plateforme et accéder à des analyses de marché professionnelles. Les opinions des utilisateurs sur le prix de GRAM (GRAM) sont présentées ci-dessous.

活动图片