Skip to main content
Sign in

Audit log

Every state-changing event for FBI Fake Token Tron Impersonation Wallet Freeze Extortion Scam (March 2026): moderation decisions on community submissions, plus corrections and updates from the news pipeline. URL-based decisions are designed to carry three independent witnesses — the original source, an Internet Archive snapshot, and a Solana memo signed by our publicly-disclosed publisher key. Archive coverage is still being backfilled, so each decision below reports its own snapshot status rather than assuming one exists.

  1. #1publishby system:backfill
    2026-08-15 23:29:58Z
    Score: ?? (no score change)
    anchorpending
    chain
    hash
    B1qPqmEaTSer…PyM7T8oRsha256 → base58
    verifying row…
    canonical bytes (15249 B) ▸
    {"actor":"system:backfill","investigation_id":"23a61c72-de8d-43be-b9fc-8b59115ae7bf","kind":"publish","page_slug":"fbi-fake-token-tron-impersonation-wallet-freeze-extortion-scam-march-2026","published_at":"2026-08-15T23:29:58.932Z","sequence_num":1,"snapshot":{"content_type":"investigation","entity_name":"FBI Fake Token Tron Impersonation Wallet Freeze Extortion Scam (March 2026)","sections":[{"content":"On March 19, 2026, the Federal Bureau of Investigation's New York Field Office issued a public warning via its official X account (@NewYorkFBI) alerting Tron blockchain users to a live social engineering campaign deploying counterfeit TRC-20 tokens impersonating the FBI. The tokens were airdropped without solicitation into victim wallets and displayed fabricated notices claiming the recipient's assets were frozen pending an anti-money laundering investigation. According to reporting by Decrypt and Yahoo Finance, the tokens threatened 'a total block on your assets' if the holder failed to complete a sham verification process through an external link. The FBI explicitly stated that it does not distribute tokens, send blockchain messages, or request AML verification through wallets of any kind.","heading":"Campaign Overview","severity":"critical","sources":[{"credibility":1,"name":"FBI New York on X — official warning post, March 19, 2026","type":"official","url":"https://x.com/NewYorkFBI/status/2034676756469154236"},{"credibility":2,"name":"Decrypt — Fake FBI Crypto Tokens Are Being Used to Threaten Tron Users, Authorities Warn","type":"news_article","url":"https://decrypt.co/361819/fake-fbi-crypto-tokens-used-threaten-tron-users-authorities-warn"},{"credibility":2,"name":"Yahoo Finance / CryptoNews — FBI Warns of Fake Crypto Tokens Impersonating the Agency on Tron Network","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/fbi-warns-fake-crypto-tokens-130650126.html"}]},{"content":"The campaign used TRC-20 token infrastructure on the Tron network. One identified token contract address associated with the scam is TKYWf5q5dzdeuCg38P8fU3wsGkHo6QL8aF, as reported by Decrypt. The tokens were created approximately eight days before the FBI warning was issued — placing token deployment at around March 11, 2026. The attacker exploited Tron's low transaction fee structure: one identified attacker address executed approximately 920 airdrop transactions at a total cost of approximately $40 in TRX, according to Yahoo Finance. Tokens appeared in standard wallet interfaces and blockchain explorers exactly as any legitimate TRC-20 token would, providing no immediately visible signal of inauthenticity. Token metadata and attached memos displayed fabricated law-enforcement language ordering holders to visit a phishing website to complete identity verification. Secondary address-poisoning tactics — using wallet addresses with character patterns similar to legitimate contacts — were also reported as part of the broader operation, per Yahoo Finance.","heading":"Technical Mechanics","severity":"critical","sources":[{"credibility":2,"name":"Decrypt — token contract address TKYWf5q5dzdeuCg38P8fU3wsGkHo6QL8aF and technical detail","type":"news_article","url":"https://decrypt.co/361819/fake-fbi-crypto-tokens-used-threaten-tron-users-authorities-warn"},{"credibility":2,"name":"Yahoo Finance — attacker cost and transaction volume (~$40 / ~920 txns)","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/fbi-warns-fake-crypto-tokens-130650126.html"},{"credibility":2,"name":"CryptoNews.net — on-chain creation timeline and wallet targeting methodology","type":"news_article","url":"https://cryptonews.net/news/security/32581289/"}]},{"content":"The campaign was not a broad spray-and-pray operation. Available reporting indicates the attacker filtered targets by wallet balance, specifically prioritizing Tron addresses holding seven-figure USDT balances. Tronscan blockchain data cited in multiple outlets confirmed that at least 728 wallets held the fraudulent token at the time the FBI alert was issued on March 19, 2026. Several of the affected wallets reportedly contained over $1 million in USDT. No independent reporting has confirmed the number of wallets whose holders actually visited the phishing site or submitted credentials. Individual financial losses attributable to this specific campaign have not been publicly confirmed in available sources as of the date of this investigation.","heading":"Target Profile and Victim Scope","severity":"high","sources":[{"credibility":2,"name":"Decrypt — 728 wallets, 7-figure USDT targeting","type":"news_article","url":"https://decrypt.co/361819/fake-fbi-crypto-tokens-used-threaten-tron-users-authorities-warn"},{"credibility":2,"name":"Cryptopolitan — TRON users targeted as fake FBI token spread","type":"news_article","url":"https://www.cryptopolitan.com/tron-users-targeted-as-fake-fbi-token-spread/"},{"credibility":2,"name":"Invezz — FBI warns of fake Tron tokens in new crypto phishing scheme","type":"news_article","url":"https://invezz.com/news/2026/03/20/fbi-warns-of-fake-tron-tokens-in-new-crypto-phishing-scheme/"}]},{"content":"Once victims received the token and viewed its message through a blockchain explorer or wallet interface, they were directed to an external website framed as an official AML verification portal. According to multiple reports, the site was designed to harvest personal name, government-issued identification, wallet credentials, and login information. Extrasafe.chat's independent analysis described the site as 'professional-looking' and mimicking government or financial platform aesthetics. Cryptopolitan reported that the message threatened 'total block of assets' to manufacture urgency. The FBI in its X post warned holders explicitly: 'do not provide any identifying information to any website associated with such token.' The specific domain name of the phishing site has not been disclosed in any available public source.","heading":"Phishing and Credential Harvesting Mechanism","severity":"critical","sources":[{"credibility":1,"name":"FBI New York on X — do not provide identifying information","type":"official","url":"https://x.com/NewYorkFBI/status/2034676756469154236"},{"credibility":2,"name":"Cryptopolitan — 'total block' threat language and phishing site description","type":"news_article","url":"https://www.cryptopolitan.com/tron-users-targeted-as-fake-fbi-token-spread/"},{"credibility":3,"name":"Extrasafe.chat — phishing site design analysis","type":"research","url":"https://www.extrasafe.chat/blog/fake-fbi-token-scam-tron-wallet-phishing"}]},{"content":"This campaign is notable for weaponizing federal law enforcement identity rather than technical exploits or romance-style grooming. By deploying tokens that appear in victims' own wallets under the FBI name, the attacker manufactured the appearance of an already-initiated government enforcement action. The psychological mechanism is distinct from generic phishing: it bypasses skepticism by presenting the 'evidence' of legal jeopardy directly inside the victim's own wallet interface, making the threat feel pre-established rather than solicited. Unchained Crypto described the campaign as representing 'a shift from technical exploits toward social engineering, impersonation, and user behavior.' The FBI's own precedent of creating an Ethereum token (NexF) in 2024 for a market-manipulation sting — an operation that yielded approximately $14,500 and was widely reported — may have given this impersonation tactic additional surface plausibility with sophisticated targets aware of that prior enforcement action.","heading":"Institutional Authority Impersonation as Attack Vector","severity":"high","sources":[{"credibility":2,"name":"Unchained Crypto — FBI warns of fake token scam targeting Tron users","type":"news_article","url":"https://unchainedcrypto.com/fbi-warns-of-fake-token-scam-targeting-tron-users-with-phishing-attack/"},{"credibility":2,"name":"Decrypt — NexF token precedent and institutional impersonation context","type":"news_article","url":"https://decrypt.co/361819/fake-fbi-crypto-tokens-used-threaten-tron-users-authorities-warn"}]},{"content":"The Tron network's low transaction fees and permissionless token creation made this campaign exceptionally cheap to execute at scale. The attacker's cost of approximately $40 for roughly 920 airdrops illustrates the asymmetric economics: even a single credential compromise against a 7-figure USDT wallet would yield a return measured in thousands of times the attacker's cost. Tron has drawn heightened regulatory attention in the period surrounding this incident: Tron founder Justin Sun reached a $10 million settlement with the U.S. Securities and Exchange Commission in March 2026, as reported by Decrypt; and a January 2026 TRM Labs report documented Tron's use in Iranian sanctions evasion. These pre-existing reputational associations with illicit finance may have made the AML-violation premise of the scam more psychologically convincing to some targets.","heading":"Tron Network Context and Enabling Conditions","severity":"medium","sources":[{"credibility":2,"name":"Decrypt — Justin Sun SEC settlement and Tron regulatory context","type":"news_article","url":"https://decrypt.co/361819/fake-fbi-crypto-tokens-used-threaten-tron-users-authorities-warn"},{"credibility":2,"name":"CryptoNews.net — attacker cost and Tron fee structure","type":"news_article","url":"https://cryptonews.net/news/security/32581289/"}]},{"content":"The FBI's New York Field Office issued its warning on March 19, 2026, via its official X account (@NewYorkFBI). The agency stated that it does not distribute tokens, send blockchain messages, or request AML verification of any kind through crypto wallets or associated websites. The FBI directed any users who had already submitted personal information to the phishing site to file a report with the Internet Crime Complaint Center at ic3.gov. No law enforcement arrests or attributions to specific individuals or criminal organizations have been publicly announced in connection with this campaign as of the date of this investigation.","heading":"Official Response and Reporting Guidance","severity":"low","sources":[{"credibility":1,"name":"FBI New York on X — official warning, March 19, 2026","type":"official","url":"https://x.com/NewYorkFBI/status/2034676756469154236"},{"credibility":1,"name":"IC3.gov — FBI Internet Crime Complaint Center reporting portal","type":"official","url":"https://www.ic3.gov"},{"credibility":2,"name":"The Block — FBI warns fake tokens impersonating agency on Tron network","type":"news_article","url":"https://www.theblock.co/post/394441/fbi-warns-fake-tokens-impersonating-agency-tron-network"}]}],"sources_used":[{"credibility":1,"name":"FBI New York on X — official warning post, March 19, 2026","type":"official","url":"https://x.com/NewYorkFBI/status/2034676756469154236"},{"credibility":1,"name":"IC3.gov — FBI Internet Crime Complaint Center","type":"official","url":"https://www.ic3.gov"},{"credibility":2,"name":"Decrypt — Fake FBI Crypto Tokens Are Being Used to Threaten Tron Users, Authorities Warn","type":"news_article","url":"https://decrypt.co/361819/fake-fbi-crypto-tokens-used-threaten-tron-users-authorities-warn"},{"credibility":2,"name":"Yahoo Finance — FBI Warns of Fake Crypto Tokens Impersonating the Agency on Tron Network","type":"news_article","url":"https://finance.yahoo.com/markets/crypto/articles/fbi-warns-fake-crypto-tokens-130650126.html"},{"credibility":2,"name":"The Block — FBI warns fake tokens impersonating agency on Tron network","type":"news_article","url":"https://www.theblock.co/post/394441/fbi-warns-fake-tokens-impersonating-agency-tron-network"},{"credibility":2,"name":"Cryptopolitan — TRON users targeted as fake FBI token spread","type":"news_article","url":"https://www.cryptopolitan.com/tron-users-targeted-as-fake-fbi-token-spread/"},{"credibility":2,"name":"Unchained Crypto — FBI warns of fake token scam targeting Tron users","type":"news_article","url":"https://unchainedcrypto.com/fbi-warns-of-fake-token-scam-targeting-tron-users-with-phishing-attack/"},{"credibility":2,"name":"Invezz — FBI warns of fake Tron tokens in new crypto phishing scheme","type":"news_article","url":"https://invezz.com/news/2026/03/20/fbi-warns-of-fake-tron-tokens-in-new-crypto-phishing-scheme/"},{"credibility":2,"name":"CryptoNews.net — Fake FBI Crypto Tokens Are Being Used to Threaten Tron Users","type":"news_article","url":"https://cryptonews.net/news/security/32581289/"},{"credibility":3,"name":"Extrasafe.chat — Fake FBI Tokens on Tron: When Your Wallet Becomes the Phishing Channel","type":"research","url":"https://www.extrasafe.chat/blog/fake-fbi-token-scam-tron-wallet-phishing"}],"summary":"In March 2026, an unidentified threat actor deployed fraudulent TRC-20 tokens on the Tron network branded as FBI assets and airdropped them to at least 728 wallets, including high-net-worth addresses holding seven-figure USDT balances. The tokens carried messages falsely claiming recipient wallets were frozen for anti-money laundering violations and directed holders to an external phishing site demanding identity and credential submission. The FBI's New York Field Office issued an official warning on March 19, 2026, confirming it does not distribute tokens or request blockchain-based identity verification of any kind.","timeline":[{"date":"2026-03-11","event":"Fraudulent FBI-branded TRC-20 token (contract: TKYWf5q5dzdeuCg38P8fU3wsGkHo6QL8aF) created on the Tron network, approximately eight days before the FBI alert was issued.","source":"Decrypt","source_url":"https://decrypt.co/361819/fake-fbi-crypto-tokens-used-threaten-tron-users-authorities-warn"},{"date":"2026-03-11","event":"Airdrop campaign begins; attacker executes approximately 920 transactions distributing fake FBI tokens to targeted Tron wallets at a reported cost of roughly $40 in TRX fees.","source":"Yahoo Finance","source_url":"https://finance.yahoo.com/markets/crypto/articles/fbi-warns-fake-crypto-tokens-130650126.html"},{"date":"2026-03-19","event":"FBI New York Field Office issues official public warning on X (@NewYorkFBI), confirming the fake token campaign and instructing users not to submit identifying information to any associated website. At least 728 wallets are confirmed holding the token at this time.","source":"FBI New York on X","source_url":"https://x.com/NewYorkFBI/status/2034676756469154236"},{"date":"2026-03-20","event":"Major crypto media outlets including Yahoo Finance, Unchained Crypto, Invezz, and Cryptopolitan publish coverage of the FBI warning, amplifying the alert to the broader crypto community.","source":"Yahoo Finance","source_url":"https://finance.yahoo.com/markets/crypto/articles/fbi-warns-fake-crypto-tokens-130650126.html"},{"date":"2026-03-21","event":"Additional coverage by The Coin Republic, CryptoNews.net, and Decrypt confirms scope details including 7-figure USDT wallet targeting and the AML-violation threat framing.","source":"Decrypt","source_url":"https://decrypt.co/361819/fake-fbi-crypto-tokens-used-threaten-tron-users-authorities-warn"}]},"v":1}
    Verify offline (run on your own machine)
    python -m src.verify_decision 85338594-acfc-455e-a43f-4c55c48339e9
How verification works. The “Row integrity” check above is computed in your browser — your machine recomputes the SHA-256 of the canonical bytes and compares against the stored hash. No avoid.net server can fake that check. The “full verify” link goes one level deeper: your browser fetches the on-chain transaction from a Solana RPC node and confirms the same hash is in the memo. If you don’t want to trust either avoid.net or the public RPC, run the CLI verifier on your own machine — python -m src.verify_decision <event_id>.