How Scammers Find You: Targeting Infrastructure
Move from victim-perspective to scammer-perspective. Learn how modern fraud operations actually identify, qualify, and approach targets — public wallet labeling, social-graph scraping, breach-data ingestion, AI scaling, and the trafficked-compound supply chain feeding it all.
27 min · beginner · part of Crypto Scams & How to Stay Safe
What you'll learn
- Why Targeting Mechanics Matter
- On-Chain Reconnaissance: Nansen, Arkham, and Etherscan Tags
- Social Graph Scraping: Twitter, Discord, LinkedIn, Breach Data
- The Pig-Butchering Pipeline From the Operator Side
- AI-Generated Content and the Scaling of Scams
- Exit Scams, Telegram Pumps, and Discord-Specific Patterns
- Digital Hygiene: Address Randomization, Compartmentalization, Awareness
Key terms
- On-chain reconnaissance
- The process of using public blockchain data to identify, label, and qualify wallets as potential scam targets. Tools include Nansen, Arkham, Etherscan tags, and the broader block-explorer ecosystem.
- Nansen
- A paid wallet-analytics product that labels Ethereum and EVM-chain wallets across more than 300 categories. Used legitimately by traders for alpha generation; used adversarially to pre-qualify targets by size, holdings, and activity patterns.
- Arkham Intelligence
- A wallet-attribution platform with a "bounty" program that pays users for linking specific wallet addresses to specific real-world identities. The resulting database is queryable by name or address.
- Have I Been Pwned
- Troy Hunt's breach-data index at haveibeenpwned.com, covering more than 12 billion compromised account records across 700-plus breaches. Lets users check whether their email addresses appear in known breaches and configure alerts.
- Ledger 2020 breach
- A July 2020 e-commerce database breach exposing approximately 270,000 customer records of Ledger hardware-wallet purchasers. Because every record in the dataset is by definition a confirmed crypto user, the data has been particularly fertile for crypto-targeted phishing.
- UNODC compound estimate
- United Nations Office on Drugs and Crime October 2024 assessment of more than 200,000 trafficked workers in scam compounds across Cambodia, Myanmar, and Laos, with expanding networks in the Philippines, Indonesia, Nigeria, and elsewhere.
- Ly Yong Phat designation
- A September 2024 OFAC sanction against a Cambodian senator and businessman, the L.Y.P. Group, and specific facilities including the O-Smach Resort and Garden City Hotel for involvement in industrial-scale fraud and human trafficking.
- Loverboy persona
- A standardized pig-butchering script archetype assigned to female targets — typically a handsome young man in lifted stock photos who builds an online romance arc before introducing investments.
- Investment-guru persona
- A standardized pig-butchering script archetype assigned to male targets — typically a successful-looking professional in luxury settings who introduces "uncle's trading platform" or proprietary strategies.
- Hong Kong deepfake heist (Feb 2024)
- A multinational firm in Hong Kong lost approximately 25 million U.S. dollars (200 million HKD) when a finance worker was tricked into transferring funds during a video conference where every other apparent participant including the CFO was an AI-generated deepfake.
- Address compartmentalization
- A defensive practice of maintaining separate addresses for different categories of activity (savings, trading, public-facing) to limit the visibility into total holdings that a single wallet attribution would otherwise provide.
- Email aliasing
- Using services like Apple Hide My Email, SimpleLogin, or Proton Pass to generate per-service forwarding addresses, so breach data from any single service exposes only that service's alias rather than the master inbox.
Read the full lesson in the CryptoBipto app.
Open lessonEducational only — not financial advice.
