15 Tweets 2 reads Oct 31, 2022
Hey @elonmusk, here's the first order of business:
PLEASE REMOVE THE SCAM CRYPTO BOTS
Someone has been impersonating me (@OlimpioCrypto) and stole +290 ETH (450,000 USD) from 5000 people
@verified rejected my blue check application. This not reason enough?
How the scam works:
1/12
These are highly sophisticated actors. How they operate:
โ€ข Access to hundreds of thousands of bots
โ€ข Knowledge of domains, web development, and smart contracts
โ€ข Imitate my style of writing
โ€ข Use a fake PNG image to impersonate my NFT profile picture
โ€ข +50K followers
2/12
MONEY STOLEN
This is one of the Smart Contracts: etherscan.io
@nansen_ai is telling us it received 423 ETH. This is over 670,000 USD of stolen money
3/12
MONEY STOLEN
Since the scammers started impersonating me, they've stolen 291 ETH (450,000 USD) of the total mentioned 423 ETH.
Someone lost 100 ETH in one transaction:
etherscan.io
4/12
How does it work?
You connect your wallet and when you interact with the contract it drains your ETH to "claim the airdrop"
It takes all the ETH you have. It can be cents, or it can be thousands.
5328 users scammed so far
5/12
How do they get people to see their tweets? And click the scam links?
With MORE scam bot accounts.
Bots (or hacked accounts) quote the phishing tweet and tag crypto Twitter users for vibility
6/12
EXAMPLES
Take a look at the fake domain, the "L" in "blur" is not really an L
7/12
EXAMPLES
Domain is fake. Look at the special character they are using instead of an "o": ล
8/12
EXAMPLES
Same with zksync, instead of an "s" they are using: ลก
9/12
NFT PFP
I advised people to check that the account has an Olimpio NFT as the profile picture. Later on, they added a hexagonal PNG image to their profile picture.
I'm sure they will eventually deploy their own Olimpio NFT and link it to Twitter, so don't trust this either
10/12
DOMAIN
Of course, you can't know each protocol's domain from memory. Some of those are new, like blur's
They created a fake domain: blurdrops io. How to tell the difference between the real one, blur.io, if you don't know it beforehand?
Almost impossible
11/12
Only interact with links from accounts you trust. Verify each account individually
Check the MetaMask prompt. The user that lost 100 ETH would have seen it there
Extensions like @_joinfire will become popular in the future, but until they do, it's up to us
12/12
The accounts:
Have been reported HUNDREDS of times, but @Twitter fails to take the down. I'm starting to think that the scammer is a Twitter insider, otherwise how can they not remove it?
Literally, HUNDREDS of reports
This is a scam that's difficult to notice, especially if you are on a mobile phone
I'm terribly sorry, but there is not a straightforward way to immediately spot these.
You need to stay alert and notice the little stuff. Like the domains, the # of tweets, the accounts in common
These people are not only damaging my name but most importantly stealing funds from thousands of people.
I contacted @Twitter to verify my account (@verified) and they rejected me.
Please help spread the word by RT/โค๏ธ with the 1st Tweet below
Stay safe

Loading suggestions...