XDRIPACADEMY
Sign in

Curriculum·F111 AI-Era Threats and Verification·60 min

Fake support, fake profiles, fake KOLs

By the end of this lesson you can

  • Apply the sourcing rule that ends fake support, and name the two requests that terminate any conversation
  • Read an account in under a minute using age, handle, direction of contact, and pressure
  • Explain why a verified, authentic endorsement carries almost no information about an asset
  • Compute the outcome distribution of an endorsed launch and state what an average participant should expect
AutopsyLIBRA, February 2025around $251M across roughly 114,410 wallets

On 14 February 2025 a token called LIBRA launched on Solana. The same day, Argentina's president posted about it from his own verified account. Market capitalisation reportedly reached somewhere around $4.5B, then fell roughly 95 percent. The post was deleted about five hours later, with a statement that he had no connection to the project and had not known its details.

Nansen's analysis of the wallets: about 86 percent of participants lost money. Roughly 114,410 wallets carried combined losses estimated at $251M or more. Thirty-six wallets each cleared over $1M. Insiders pulled more than $107M of liquidity out during the collapse.

Now the part that makes this lesson different from the two before it.

Nothing here was fake. The account was real. The verification badge was real. It belonged to precisely the person it claimed to belong to, and none of the AI-era detection skills from F111-01 and F111-02 would have helped at all.

The decision point is that participants verified identity, which was true, and treated it as verification of merit, which was never on offer.

Primary source

This lesson covers three attacks that look unrelated and share one root: fake support, fake profiles, and endorsements. The root is that we use who appears to be speaking as a proxy for whether to act. AI made the first two cheap. The third never needed AI at all.

Fake support, which is the one that will actually happen to you

Here is a sequence that plays out thousands of times a day. Someone has a wallet problem. They post about it publicly: a reply to the project, a forum thread, a comment under a video. Within minutes a friendly account replies. Right logo, right name, the calm competent register of a real help desk. It offers to walk them through a fix.

It is not the help desk. It is an operator who was watching for exactly that post, now writing fluent support English with a model's help. By the end of the conversation the funds are gone.

This is the most common way self-custody users get drained right now. Not a sophisticated exploit. A conversation.

Two things made it explode. AI removed the language tell, so fake support no longer reads like a scam but like an agent who genuinely wants to help. And first contact became instant and tireless: bots watch public channels for "stuck", "pending", "lost", "help", and reply faster than any real team could. The speed feels like good service. It is a trap that was waiting.

The two requests that end it

A fake-support conversation can wander for a long time building trust, but it has to arrive at one of two destinations, and both are absolute.

Any request for your seed phrase, recovery phrase or private key. There is no legitimate version of this request, for any wallet, anywhere. The moment you see it, the conversation is over and the account is a thief. This is not a judgment call.

Any instruction to connect, sync, validate or restore on a page they sent you. The site will look official. Entering your phrase hands over the keys. Approving the transaction hands over the tokens directly, which is the machinery you took apart in F105.

Real support almost never reaches out first, and it never appears seconds after a public post about a problem. If help arrives unsolicited and fast, read the speed as a warning rather than a kindness.

A move to direct messages is part of the play, not a security improvement. It removes the bystanders who might have warned you. Private is not safer here. It is more isolated, which is the point.

Reading an account in under a minute

Fake accounts are cheap to make and easy to dress. Four checks catch most of them.

Account age and history. New, or almost no real history, is a strong signal. Operators churn accounts as they get reported.

The handle, character by character. Lookalikes are everywhere: an extra letter, a zero for an o, an underscore, "support" or "helpdesk" bolted onto a real project name. Compare against the official handle published on the project's own site, not against your memory of it.

Direction of contact. If they messaged you first, especially right after you posted a problem, the burden of proof is entirely theirs. Badges and matching avatars prove nothing on their own.

Pressure. Real help is relaxed about timing. Fake help nudges toward a link, a phrase, or a quick action.

These are a fast filter, not a green light. Passing them is never permission to share anything sensitive.

Drill · Phishing triage
Mark each message

Four messages. Some are safe, some are phishing. Mark each one before you submit. We grade them all at once and explain why.

  • Emailsupport@xcoldpro-account.com
    Action required: verify your XColdPro device

    Your XColdPro Frost firmware is out of date. Click below within 24 hours to keep your funds safe.

  • DM@xdrip_support

    Hi, this is XDRIP Support. We saw a failed transaction and need to verify your seed phrase to fix it.

  • Emailnewsletter@xdripacademy.com
    Lesson 3 is live: Hardware vs software wallets

    Following on from last week, the next lesson in your Freshman track is now live on your account. No action required from you.

  • SMS+1 (415) 555-0142

    URGENT: your XECHO release was paused. Reply YES to authorize.

The sourcing rule

The durable defence is not detection skill. It is a rule about where help comes from.

You reach support through doors you open yourself. Navigate from the project's verified site or the app you already installed. Not a link someone sent. Not whoever replied to your post. You go to support; support does not come to you.

Then bring the fundamentals with you. If your seed phrase is something that never gets typed, spoken, photographed or shared, a flawless fake-support agent has nothing to take. The conversation can be as convincing as it likes and it runs into a wall you built in advance.

Endorsements, where none of the above applies

Now the harder half, because here the account is genuine and every detection skill in this course returns "authentic".

An endorsement tells you one thing: that this person said this. It does not tell you what they were paid, what they hold, when they can sell, whether they read anything, or whether the thing is any good. Those are separate questions and the endorsement answers none of them.

Worked example
What the average participant should have expected

Take the LIBRA wallet data at face value and ask what an average participant should have expected going in.

About 86 percent of roughly 114,410 wallets lost money. So the chance of ending up on the profitable side was about 14 percent, and that is measured after the fact, which flatters it.

Average loss across the losing side, using the $251M lower estimate spread over 114,410 wallets:

$251,000,000 / 114,410 = about $2,194 per wallet

Now the shape of the winning side. Thirty-six wallets cleared over $1M each, out of 114,410 participants:

36 / 114,410 = about 0.03 percent

That is the structure to carry forward. It is not a coin flip with a slight edge against you. It is a distribution where the upside is concentrated in a group roughly three in ten thousand strong, several of whom had information you did not, while insiders removed more than $107M of liquidity on the way down.

We are not telling you what to buy or avoid. We are telling you that "a famous person posted about it" moves none of these numbers, because the numbers were determined by who held what before the post existed.

Common misconception

If the endorser turns out to be legitimate, the endorsement was worth something.

Take the HAWK token from December 2024. It reached a reported market capitalisation of around $490M and fell roughly 95 percent within minutes. The SEC later closed its investigation into the promoter without charges or sanctions.

That closure is widely reported as a clearing. A former SEC lawyer publicly pointed out that it reflected the agency's jurisdiction over memecoins rather than a finding that nothing wrong had occurred, and separate civil litigation against other parties continued.

Notice that none of this changes the position of someone who bought. Whether the endorser was innocent, negligent or otherwise is a question for courts, and it has no bearing on the outcome that was already determined by the token's distribution before anyone posted anything. An endorsement being sincere does not make it informative.

Two habits follow. Treat any promotion as a paid placement until you see a disclosure proving otherwise, because in this market that is the base rate. And when a launch is being promoted hard, the question worth asking is not whether the promoter is real but who already holds the supply and when they are able to sell. S202 gives you the tools to answer that from the vesting schedule and the distribution. Until then, the correct action when you cannot answer it is to not participate.

Key takeaway

Fake support is the most common drain in self-custody and it dies to one rule: you reach support through a door you opened yourself, and any request for a seed phrase or any page asking you to validate a wallet ends the conversation. Fake profiles die to four checks: age, handle, who contacted whom, and pressure. Endorsements survive all of that, because they are usually genuine, and genuine is not the same as informative. Verifying identity is not diligence, and in LIBRA a real post from a real verified account preceded about 86 percent of wallets losing money.

These come back later

What is the sourcing rule for support?
You go to support, through the official site or the app you already installed. Support never comes to you. Anyone who replies to your public post or messages you first is carrying the entire burden of proof.
Name the two requests that end a support conversation immediately.
Any request for a seed phrase or private key, and any instruction to connect, sync, validate or restore a wallet on a page they sent you. Neither has a legitimate version. These are not judgment calls.
What does a verified endorsement tell you about an asset?
That the account is who it says it is. Nothing else. Identity is not diligence, and in the LIBRA case a genuine head-of-state post preceded roughly 86 percent of wallets losing money.

Sources and review

Confidence medium·Volatility high·Reviewed 2026-08-05·Owner unassigned

Contested

Loss estimates for LIBRA range from about $251M to $400M depending on methodology and the window measured, and the $4B figure widely quoted is destroyed market capitalisation, which is not the same as money lost. Quote the wallet-level figure with its source, and never quote market cap loss as investor loss.

Legal proceedings arising from LIBRA were still open at the time of writing and no finding of wrongdoing against any individual is asserted here. The lesson does not depend on the outcome. Teach the structure, not the culpability, and check the status before any update.

The HAWK matter is frequently reported as the SEC clearing the promoter. The SEC closed its investigation without charges; a former SEC lawyer publicly noted that closure reflected jurisdiction over memecoins rather than a finding of no wrongdoing. State both halves or neither.

Track your progress

Create a free account to mark lessons complete and pick up where you left off.