On 14 February 2025 a token called LIBRA launched on Solana. The same day, Argentina's president posted about it from his own verified account. Market capitalisation reportedly reached somewhere around $4.5B, then fell roughly 95 percent. The post was deleted about five hours later, with a statement that he had no connection to the project and had not known its details.
Nansen's analysis of the wallets: about 86 percent of participants lost money. Roughly 114,410 wallets carried combined losses estimated at $251M or more. Thirty-six wallets each cleared over $1M. Insiders pulled more than $107M of liquidity out during the collapse.
Now the part that makes this lesson different from the two before it.
Nothing here was fake. The account was real. The verification badge was real. It belonged to precisely the person it claimed to belong to, and none of the AI-era detection skills from F111-01 and F111-02 would have helped at all.
The decision point is that participants verified identity, which was true, and treated it as verification of merit, which was never on offer.
This lesson covers three attacks that look unrelated and share one root: fake support, fake profiles, and endorsements. The root is that we use who appears to be speaking as a proxy for whether to act. AI made the first two cheap. The third never needed AI at all.
Fake support, which is the one that will actually happen to you
Here is a sequence that plays out thousands of times a day. Someone has a wallet problem. They post about it publicly: a reply to the project, a forum thread, a comment under a video. Within minutes a friendly account replies. Right logo, right name, the calm competent register of a real help desk. It offers to walk them through a fix.
It is not the help desk. It is an operator who was watching for exactly that post, now writing fluent support English with a model's help. By the end of the conversation the funds are gone.
This is the most common way self-custody users get drained right now. Not a sophisticated exploit. A conversation.
Two things made it explode. AI removed the language tell, so fake support no longer reads like a scam but like an agent who genuinely wants to help. And first contact became instant and tireless: bots watch public channels for "stuck", "pending", "lost", "help", and reply faster than any real team could. The speed feels like good service. It is a trap that was waiting.
A fake-support conversation can wander for a long time building trust, but it has to arrive at one of two destinations, and both are absolute.
Any request for your seed phrase, recovery phrase or private key. There is no legitimate version of this request, for any wallet, anywhere. The moment you see it, the conversation is over and the account is a thief. This is not a judgment call.
Any instruction to connect, sync, validate or restore on a page they sent you. The site will look official. Entering your phrase hands over the keys. Approving the transaction hands over the tokens directly, which is the machinery you took apart in F105.
Real support almost never reaches out first, and it never appears seconds after a public post about a problem. If help arrives unsolicited and fast, read the speed as a warning rather than a kindness.
A move to direct messages is part of the play, not a security improvement. It removes the bystanders who might have warned you. Private is not safer here. It is more isolated, which is the point.
Reading an account in under a minute
Fake accounts are cheap to make and easy to dress. Four checks catch most of them.
Account age and history. New, or almost no real history, is a strong signal. Operators churn accounts as they get reported.
The handle, character by character. Lookalikes are everywhere: an extra letter, a zero for an o, an underscore, "support" or "helpdesk" bolted onto a real project name. Compare against the official handle published on the project's own site, not against your memory of it.
Direction of contact. If they messaged you first, especially right after you posted a problem, the burden of proof is entirely theirs. Badges and matching avatars prove nothing on their own.
Pressure. Real help is relaxed about timing. Fake help nudges toward a link, a phrase, or a quick action.
These are a fast filter, not a green light. Passing them is never permission to share anything sensitive.
Four messages. Some are safe, some are phishing. Mark each one before you submit. We grade them all at once and explain why.
- Emailsupport@xcoldpro-account.comAction required: verify your XColdPro device
Your XColdPro Frost firmware is out of date. Click below within 24 hours to keep your funds safe.
- DM@xdrip_support
Hi, this is XDRIP Support. We saw a failed transaction and need to verify your seed phrase to fix it.
- Emailnewsletter@xdripacademy.comLesson 3 is live: Hardware vs software wallets
Following on from last week, the next lesson in your Freshman track is now live on your account. No action required from you.
- SMS+1 (415) 555-0142
URGENT: your XECHO release was paused. Reply YES to authorize.
The sourcing rule
The durable defence is not detection skill. It is a rule about where help comes from.
You reach support through doors you open yourself. Navigate from the project's verified site or the app you already installed. Not a link someone sent. Not whoever replied to your post. You go to support; support does not come to you.
Then bring the fundamentals with you. If your seed phrase is something that never gets typed, spoken, photographed or shared, a flawless fake-support agent has nothing to take. The conversation can be as convincing as it likes and it runs into a wall you built in advance.
Endorsements, where none of the above applies
Now the harder half, because here the account is genuine and every detection skill in this course returns "authentic".
An endorsement tells you one thing: that this person said this. It does not tell you what they were paid, what they hold, when they can sell, whether they read anything, or whether the thing is any good. Those are separate questions and the endorsement answers none of them.
Take the LIBRA wallet data at face value and ask what an average participant should have expected going in.
About 86 percent of roughly 114,410 wallets lost money. So the chance of ending up on the profitable side was about 14 percent, and that is measured after the fact, which flatters it.
Average loss across the losing side, using the $251M lower estimate spread over 114,410 wallets:
$251,000,000 / 114,410 = about $2,194 per wallet
Now the shape of the winning side. Thirty-six wallets cleared over $1M each, out of 114,410 participants:
36 / 114,410 = about 0.03 percent
That is the structure to carry forward. It is not a coin flip with a slight edge against you. It is a distribution where the upside is concentrated in a group roughly three in ten thousand strong, several of whom had information you did not, while insiders removed more than $107M of liquidity on the way down.
We are not telling you what to buy or avoid. We are telling you that "a famous person posted about it" moves none of these numbers, because the numbers were determined by who held what before the post existed.
If the endorser turns out to be legitimate, the endorsement was worth something.
Take the HAWK token from December 2024. It reached a reported market capitalisation of around $490M and fell roughly 95 percent within minutes. The SEC later closed its investigation into the promoter without charges or sanctions.
That closure is widely reported as a clearing. A former SEC lawyer publicly pointed out that it reflected the agency's jurisdiction over memecoins rather than a finding that nothing wrong had occurred, and separate civil litigation against other parties continued.
Notice that none of this changes the position of someone who bought. Whether the endorser was innocent, negligent or otherwise is a question for courts, and it has no bearing on the outcome that was already determined by the token's distribution before anyone posted anything. An endorsement being sincere does not make it informative.
Two habits follow. Treat any promotion as a paid placement until you see a disclosure proving otherwise, because in this market that is the base rate. And when a launch is being promoted hard, the question worth asking is not whether the promoter is real but who already holds the supply and when they are able to sell. S202 gives you the tools to answer that from the vesting schedule and the distribution. Until then, the correct action when you cannot answer it is to not participate.
Fake support is the most common drain in self-custody and it dies to one rule: you reach support through a door you opened yourself, and any request for a seed phrase or any page asking you to validate a wallet ends the conversation. Fake profiles die to four checks: age, handle, who contacted whom, and pressure. Endorsements survive all of that, because they are usually genuine, and genuine is not the same as informative. Verifying identity is not diligence, and in LIBRA a real post from a real verified account preceded about 86 percent of wallets losing money.