{"investigation":{"slug":"vkevin","entity_name":"Vkevin","trust_score":2,"severity_base":null,"score_modifier":0,"confidence":1,"status":"published","content_type":"investigation","summary":"Vkevin is a pseudonymous threat actor known for operating fake Safeguard Telegram bot phishing campaigns that have allegedly drained seven figures from victims' cryptocurrency wallets. On January 23, 2025, blockchain investigator ZachXBT published a 31-minute video exposing Vkevin in the act of running these scams from what was described as a New York school, and confirmed the individual had been doxxed. Vkevin is additionally alleged to have conducted a 2022 Discord attack against DigikongNFT using a spoofed MEE6 bot, resulting in over $300,000 in NFT losses.","sections":[{"content":"Vkevin operates under a pseudonym and their legal identity was not publicly disclosed in news coverage as of early 2025. Following ZachXBT's January 23, 2025 exposure post on X, a community member asked whether Vkevin had been doxxed; ZachXBT confirmed with a simple 'yes.' At least one user in the thread shared a photo of the alleged individual. ZachXBT's video footage reportedly showed Vkevin operating while enrolled at a school in New York. No formal criminal charges have been confirmed in publicly available sources as of the investigation date, though reports describe Vkevin as 'jailed' — a characterization that may reflect community commentary rather than verified incarceration. Independent verification of the real name or legal status was not available in Tier 1 or Tier 2 sources reviewed.","heading":"Identity and Doxxing","sources":[],"severity":"medium"},{"content":"Vkevin's primary alleged scheme involved impersonating Safeguard, a widely used Telegram verification bot. According to ZachXBT's January 23, 2025 investigation post, Vkevin operated a fake Safeguard bot across multiple Telegram channels, which resulted in seven figures (at minimum $1,000,000 USD) drained from victims' wallets. The attack technique leverages users' trust in Safeguard's legitimate verification flow. Victims who interacted with the fraudulent bot were prompted to complete a 'verification' process; upon compliance, the bot allegedly facilitated unauthorized access to their Telegram accounts and associated trading bot wallets. ZachXBT uploaded a 31-minute video to X secretly recording Vkevin and accomplices executing these phishing operations in real time. The video showed Vkevin collaborating with other unidentified actors during the scheme.","heading":"Fake Safeguard Telegram Bot Scam (2025)","sources":[],"severity":"medium"},{"content":"The Safeguard bot spoofing technique attributed to Vkevin's broader threat group involves delivery of malicious PowerShell payloads. Victims who follow the fake verification steps are reportedly subjected to a malicious remote access Trojan (RAT) agent that executes PowerShell commands on their device. These commands are alleged to compromise security installations, grant the attacker unauthorized system access, expose private keys, and enable drainage of cryptocurrency wallets. This attack pattern — fake Telegram verification leading to clipboard-injected PowerShell — was also documented broadly by security researchers at SlowMist and Scam Sniffer in 2025 as a prevalent technique used by multiple threat actors, not solely Vkevin.","heading":"PowerShell Malware Delivery","sources":[],"severity":"medium"},{"content":"Vkevin is alleged to have conducted an earlier attack on August 14, 2022, targeting DigikongNFT's Discord server. According to reporting corroborated by multiple crypto news outlets, the attacker deployed a webhook impersonating the MEE6 Discord bot — a popular moderation and leveling bot — within the server. A bookmarklet-based technique was used to exfiltrate Discord authentication tokens from users who interacted with the fake bot. The phishing site was hosted at the domain mee6.ca/verify, registered via Namecheap and served from AWS infrastructure at IP address 23.22.5.68. NFT holders lost over $300,000 as a direct result of this breach. This incident establishes a multi-year pattern of bot spoofing attacks by the same alleged operator, spanning both Discord and Telegram platforms.","heading":"2022 Discord Attack: DigikongNFT (MEE6 Spoof)","sources":[],"severity":"medium"},{"content":"On January 23, 2025, blockchain investigator ZachXBT (@zachxbt on X) published a post referencing a 31-minute video recording of Vkevin running fake Safeguard bot phishing operations on Telegram. The post was made to ZachXBT's Investigations Telegram channel (t.me/investigations) and X account. ZachXBT described the footage as a secret recording made while Vkevin was actively scamming victims. The investigator confirmed to community members that Vkevin had been identified (doxxed). A secondary tweet by ZachXBT referenced Vkevin by name in the context of the fake Safeguard scheme. Leviathan News summarized the exposure as: 'ZachXBT exposes phishing scammer vkevin in a 31-minute video, revealing a fake safeguard bot scam draining millions via Telegram.' ZachXBT did not publicly release identifying documents or the real name in sources reviewed.","heading":"ZachXBT Investigation and Exposure","sources":[],"severity":"medium"},{"content":"Vkevin's alleged operational model combines social engineering, bot impersonation, and malware delivery across two major social platforms. On Discord, the MEE6 bot spoof technique leverages server administrators' and users' trust in widely deployed bots, using webhooks to inject fraudulent verification flows. On Telegram, the Safeguard spoof mimics the ubiquitous join-verification pattern used by legitimate crypto project channels. In some variants of this campaign family, attackers create counterfeit accounts impersonating known crypto influencers (KOLs) on X, attach Telegram group links in post comments, and funnel victims into controlled Telegram environments where the fake Safeguard bot is the first touchpoint. Vkevin is alleged to have operated with accomplices, suggesting a coordinated rather than solo operation.","heading":"Operational Profile and Tactics","sources":[],"severity":"medium"}],"timeline":[{"date":"2022-08-14","event":"Vkevin allegedly attacks DigikongNFT's Discord server using a fake MEE6 bot webhook, exfiltrating Discord authentication tokens via a bookmarklet phishing site at mee6.ca/verify. NFT holders lose over $300,000.","source":"","source_url":"https://cryptonews.net/news/security/30413765/"},{"date":"2025-01-23","event":"ZachXBT publishes a 31-minute video on X secretly recording Vkevin running fake Safeguard Telegram bot phishing operations across multiple Telegram channels, with seven figures in victim losses alleged. ZachXBT confirms Vkevin has been doxxed.","source":"","source_url":"https://cryptorank.io/news/feed/733e8-zachxbt-fake-safeguard-telegram-bot-scammer"},{"date":"2025-01-23","event":"Multiple crypto media outlets including Cryptopolitan, CryptoNews.net, and blockchain.news report on ZachXBT's exposure of Vkevin. Leviathan News characterizes losses as 'draining millions via Telegram.'","source":"","source_url":"https://x.com/leviathan_news/status/1882374359869763974"}],"sources_used":[],"source_tags":["zachxbt"],"addresses":[],"reviewed":false,"reviewed_by":null,"model_used":"claude-sonnet","created_at":"2026-05-04T16:05:02.937997+00:00","updated_at":"2026-08-29T01:35:57.893+00:00"}}