CAT: Fake Crypto Project · REPORTED 17 September 2026

0x84b730a68098e66A3C1BaD4aD145e6546AcfCfEA scam

A fake crypto project scam report.

Narrative evidence

What happened

A fake crypto project scam involving cryptocurrency was reported on 17 September 2026. I discovered that a public smart contract on BNB Smart Chain is being used as command-and-control (C2) infrastructure for an active malware campaign. The campaign works like this: a fake technical recruiter contacts a target (e.g. via LinkedIn) about a "Blockchain/Backend Engineer" role, arranges a fake interview, and asks the candidate to clone and run a GitHub repository as a "take-home task." That repository contains an obfuscated backdoor in its database-connection code: on startup it decrypts a hardcoded URL, downloads JavaScript from a Vercel-hosted address, and executes it with eval(). That downloaded code drops a persistent Node.js backdoor. Instead of using a hardcoded C2 domain or IP (which could be seized or blocklisted), the backdoor resolves its C2 address by calling the public, unauthenticated get(bytes32) function on this BNB Smart Chain contract, passing a fixed key baked into the malware binary. The contract has no financial function — it exists purely as a key -> URL lookup store, so the operator can redirect every already-deployed implant at once by sending a single set() transaction, with no need to re-compromise victims. Reverse-engineering the contract's bytecode and querying it with several plausible key names (read-only calls, no transaction sent) showed it currently resolves at least three separate, live command-and-control servers under three different keys, all on different hosting providers in different US cities, all running byte-identical server software and serving byte-identical malware payloads for a given session id. This indicates one centrally-managed operation running several parallel "teams," not an isolated one-off. The payload served is a cross-platform (Windows/macOS/Linux) credential and cryptocurrency-wallet stealer that specifically targets MetaMask, Phantom, Exodus, and Atomic Wallet, alongside SSH keys, .env secrets, and browser-stored credentials, disguised as a legitimate Microsoft VS Code extension manifest to evade casual and automated inspection. The contract's owner wallet (confirmed via its own owner() function) is the only address able to update these C2 pointers. It is an actively-used externally-owned account with dozens of prior outgoing transactions — not a disposable, one-time wallet — and is kept funded with just enough BNB to cover the gas cost of updating the C2 records. This is a live, ongoing threat: the loader URL, the contract, and all three C2 servers were confirmed still active and serving the identical malware days after the initial infection this was discovered from. Wallet addresses linked to this report: binance_coin: 0x84b730a68098e66A3C1BaD4aD145e6546AcfCfEA Sei: 0x62306bBaAC0508D3bE1647adeaDc74Ca43cAcb41 Do not send money or cryptocurrency to anyone connected to this report. If you have already paid, contact your bank or exchange and report the incident to your national fraud authority.

Community warning

How to protect yourself from fake crypto project scams

  • Never send money, gift cards or crypto to anyone you have not independently verified.
  • Search the business name, website, email and phone number here before paying.
  • Be wary of urgency, secrecy, upfront fees and “too good to be true” prices.
  • If you have paid, contact your bank or card issuer immediately to dispute the charge.
  • Report to Action Fraud (UK), the FTC (US) or your national authority, and add your occurrence above.

Community comments (0)

Have you dealt with this business? Share what you know to help others.

  • No comments yet. Be the first to add context to this report.

More fake crypto project scams

View category

Seen something suspicious?

REPORT A SCAM

scam-i.uk

A free, public scam intelligence database. Search, browse and report fraud to protect others.

Disclaimer: scam-i.uk is an informational resource that aggregates and republishes user-submitted and publicly available scam reports. Reports reflect the personal experiences and opinions of the individuals who submitted them and have not been independently verified by scam-i.uk. Inclusion of a business, website, email address, phone number or individual in this database does not constitute an accusation, finding or determination of wrongdoing by scam-i.uk. Nothing on this site is legal, financial or professional advice. If you believe you are the victim of fraud, contact your bank, local police and the relevant national reporting body (e.g. Action Fraud in the UK or the FTC in the US). See our full Disclaimer, Terms of Service and Privacy Policy.

© 2026 scam-i.uk · All rights reserved