Skip to main content
Important: We do not provide financial advice or custody funds. All transactions occur on third-party platforms.

How Scammers Find You: Targeting Infrastructure

Move from victim-perspective to scammer-perspective. Learn how modern fraud operations actually identify, qualify, and approach targets — public wallet labeling, social-graph scraping, breach-data ingestion, AI scaling, and the trafficked-compound supply chain feeding it all.

27 min · beginner · part of Crypto Scams & How to Stay Safe

Why Targeting Mechanics Matter

Earlier lessons in this module covered scams from the victim side — what BitConnect promised, what a pig-butchering script feels like, how a wallet drainer works. This lesson inverts the lens. You will see how scammers identify, prioritize, and approach targets. You will see what the inside of an industrial-scale fraud factory looks like. And you will see why, in 2026, the question is not whether you will be approached but how often and how well-tailored the approach will be. The shift in perspective matters because most consumer crypto-security advice is reactive. It teaches you to recognize a scam after the contact has already arrived. That is necessary, but it is not sufficient. If you understand how the targeting works, you can take steps that reduce the volume and quality of approaches you receive in the first place. You can also calibrate your skepticism more accurately: if you know that a particular dataset about you was breached three years ago and is now being sold on a Telegram channel for fifty dollars, you should treat any unsolicited contact that references that dataset's contents as adversarial by default. The targeting infrastructure of 2026 has four layers stacked on top of each other. The first is on-chain reconnaissance — the wallet-labeling tools, transaction analytics, and surveillance dashboards that turn pseudonymous addresses into actionable intelligence. The second is social-graph scraping — Twitter, LinkedIn, Discord, Telegram, and breach-data aggregators that turn names and email addresses into rich profiles. The third is the operational layer where intelligence is converted into outreach: trafficked-worker compounds in Cambodia, Myanmar, and Laos that run the human side at industrial scale, and AI tooling that scales each operator's reach and quality. The fourth is the cash-out and laundering layer that closes the loop. This lesson focuses on the first three — the funnel that ends with a victim receiving a message — because that is where defense is possible.

Also in this lesson

  • On-Chain Reconnaissance: Nansen, Arkham, and Etherscan Tags
  • Social Graph Scraping: Twitter, Discord, LinkedIn, Breach Data
  • The Pig-Butchering Pipeline From the Operator Side
  • AI-Generated Content and the Scaling of Scams
  • Exit Scams, Telegram Pumps, and Discord-Specific Patterns
  • Digital Hygiene: Address Randomization, Compartmentalization, Awareness

Key terms

On-chain reconnaissance
The process of using public blockchain data to identify, label, and qualify wallets as potential scam targets. Tools include Nansen, Arkham, Etherscan tags, and the broader block-explorer ecosystem.
Nansen
A paid wallet-analytics product that labels Ethereum and EVM-chain wallets across more than 300 categories. Used legitimately by traders for alpha generation; used adversarially to pre-qualify targets by size, holdings, and activity patterns.
Arkham Intelligence
A wallet-attribution platform with a "bounty" program that pays users for linking specific wallet addresses to specific real-world identities. The resulting database is queryable by name or address.
Have I Been Pwned
Troy Hunt's breach-data index at haveibeenpwned.com, covering more than 12 billion compromised account records across 700-plus breaches. Lets users check whether their email addresses appear in known breaches and configure alerts.
Ledger 2020 breach
A July 2020 e-commerce database breach exposing approximately 270,000 customer records of Ledger hardware-wallet purchasers. Because every record in the dataset is by definition a confirmed crypto user, the data has been particularly fertile for crypto-targeted phishing.
UNODC compound estimate
United Nations Office on Drugs and Crime October 2024 assessment of more than 200,000 trafficked workers in scam compounds across Cambodia, Myanmar, and Laos, with expanding networks in the Philippines, Indonesia, Nigeria, and elsewhere.
Ly Yong Phat designation
A September 2024 OFAC sanction against a Cambodian senator and businessman, the L.Y.P. Group, and specific facilities including the O-Smach Resort and Garden City Hotel for involvement in industrial-scale fraud and human trafficking.
Loverboy persona
A standardized pig-butchering script archetype assigned to female targets — typically a handsome young man in lifted stock photos who builds an online romance arc before introducing investments.
Investment-guru persona
A standardized pig-butchering script archetype assigned to male targets — typically a successful-looking professional in luxury settings who introduces "uncle's trading platform" or proprietary strategies.
Hong Kong deepfake heist (Feb 2024)
A multinational firm in Hong Kong lost approximately 25 million U.S. dollars (200 million HKD) when a finance worker was tricked into transferring funds during a video conference where every other apparent participant including the CFO was an AI-generated deepfake.
Address compartmentalization
A defensive practice of maintaining separate addresses for different categories of activity (savings, trading, public-facing) to limit the visibility into total holdings that a single wallet attribution would otherwise provide.
Email aliasing
Using services like Apple Hide My Email, SimpleLogin, or Proton Pass to generate per-service forwarding addresses, so breach data from any single service exposes only that service's alias rather than the master inbox.

Continue this lesson — 6 more sections in the CryptoBipto app.

Open lesson

Educational only — not financial advice.