Skip to main content
AVOID.NET

v1 → v2

Scores

trust_score5544
severity_base
score_modifier00

Sections

SEC Enforcement Action and Origin (2019–2020) → Background and SEC Enforcement Action (2018–2020)

unchanged

Pavel Durov Arrest and Criminal Charges (2024–Present) → Recentralization Risk: Telegram Reasserts Control (May 2026)

unchanged

Phishing Drainers and Wallet Theft Infrastructure (2024) → Pavel Durov Arrest and Criminal Charges in France (2024–Present)

unchanged

Pyramid Schemes and Referral Bot Fraud (Kaspersky Investigation) → Phishing Campaigns and Wallet Drainer Activity (2024–2025)

unchanged

Fake Stablecoin Fraud Targeting Major Exchanges → AngelX Drainer Toolkit Targeting TON (September 2024)

unchanged

Use by Pro-Russia Hacktivist Groups (KillNet) → Pyramid Scheme and Referral Bot Fraud (Kaspersky Investigation, 2023–2024)

unchanged

Structural Risk: Forensic Coverage Gaps and Traceability Limitations → Fake Stablecoin Fraud Targeting Major Exchanges

unchanged

Note on ZachXBT Reporting and On-Chain Addresses → Rug Pull Activity on TON Decentralized Exchanges

unchanged

Background and SEC Enforcement Action (2018–2020) → Illicit Marketplace Activity: Guarantee Markets in the Telegram/TON Ecosystem

- Telegram raised approximately $1.7 billion in two private presale rounds during Q1 2018 from 171 investors for its planned TON blockchain and Gram token, in one of the largest token sales in history at the time. In October 2019, the U.S. Securities and Exchange Commission filed an emergency enforcement action (Case No. 19-cv-9439, S.D.N.Y.) arguing that the Gram token sale constituted an unregistered securities offering under the Howey Test. On March 24, 2020, Judge P. Kevin Castel of the Southern District of New York granted a preliminary injunction blocking distribution. Telegram settled in June 2020, agreeing to pay an $18.5 million civil penalty and return approximately $1.22 billion to investors, offset by $1.19 billion already paid as contractual termination amounts. Pavel Durov subsequently abandoned the project. The TON blockchain was then revived and maintained by an independent community group operating as the TON Foundation, operating separately from Telegram until May 2026.+ 

Recentralization Risk: Telegram Reasserts Control (May 2026) → TON Blockchain as Malware Command-and-Control Infrastructure (2026)

- On May 4, 2026, Pavel Durov announced that Telegram would replace the TON Foundation as the primary driving force behind the TON blockchain and would become its largest validator by staking approximately 2.2 million TON tokens. This announcement reversed the decentralized narrative that had legitimized the community-run network since 2020 and raises governance concentration concerns. The price of Toncoin surged approximately 36% on the announcement. Critics note that Telegram's reassertion of control over a network it was legally forced to abandon reintroduces single-entity risk to what was marketed as a decentralized protocol.+ 

Pavel Durov Criminal Indictment (France, 2024) → Use by Pro-Russia Hacktivist Groups (KillNet)

- Pavel Durov was arrested at a Paris airport on August 24, 2024. French prosecutors placed him under formal investigation on 12 counts, including alleged complicity in administering an online platform that facilitated illegal transactions such as child sexual abuse material distribution, drug trafficking, and organized fraud, as well as refusal to provide encryption keys to law enforcement. Durov posted bail of EUR 5 million and was subject to judicial supervision. The criminal investigation remains active as of May 2026, though travel restrictions have been partially lifted. When arrest news became public, Toncoin's market value fell over 20%, losing approximately $2.4 billion in market capitalization within 48 hours. The platform's deep structural link to Telegram means that legal pressure on its founder directly translates into ecosystem risk for TON.+ 

Phishing Campaigns and Wallet Drainer Activity (2024–2025) → Network Stability Incident: DOGS Airdrop Outage (August 2024)

- The TON ecosystem experienced a sharp increase in phishing attacks and wallet drainer operations throughout 2024, driven by the network's rapid growth—TVL increased 4,500% in 2024 to approximately $648 million—combined with an absence of mature security tooling. Security firm SlowMist issued a public warning in June 2024 flagging the surge, citing the ease with which attackers gain access to large Telegram group chats and deploy phishing links and bot forms. In May 2024, a TON-based phishing scheme exploited the TON transfer comment feature (which allows transactions to display custom messages at signing) to falsely show 'Receive 5,000 USDT' to victims. One drainer operating this technique accumulated at least 22,000 TON (approximately $152,000) according to Scam Sniffer. A documented fund collection address for a separate phishing campaign targeting fake virtual Telegram number NFTs is UQB1QBhyiY76wtIDTaV3pFtl8jE_aCrlGeDDTRbz2LaNjTvH, which received 6,483 TON (approximately $45,000) within a brief window in 2024. That campaign used nftTONificatorBot to distribute counterfeit NFTs impersonating legitimate '+888' series virtual numbers, charging victims 1.02 TON per failed transfer attempt versus a legitimate fee of 0.02 TON. A TON drainer script was sold on underground Telegram markets for as little as $300–$1,000, with one variant limited specifically to Tonkeeper wallet and targeting Toncoin and Jetton tokens. Crypto phishing attacks targeting Telegram surged 2,000% between November 2024 and January 2025, with losses exceeding $200 million from Telegram-specific fraud in 2025 alone.+ 

AngelX Drainer Toolkit Targeting TON (September 2024) → Structural Risk: Forensic Coverage Gaps and Traceability Limitations

- On August 31, 2024, security firm Blockaid detected the launch of AngelX, an upgraded version of the Angel Drainer phishing toolkit that specifically targeted TON and Tron blockchains due to their perceived lack of robust security infrastructure. Within four days, AngelX had deployed over 300 malicious decentralized applications (dApps). Blockaid documented over 150 new phishing scams powered by AngelX within its first five days of operation and credited early detection with protecting approximately $400,000 in user funds. The original Angel Drainer had been responsible for over $25 million in theft across 35,000 wallets prior to its rebranding. AngelX's operators targeted TON and Tron because, in Blockaid's assessment, these chains lacked security monitoring tools comparable to Ethereum. In October 2024, the primary TON-focused wallet drainer announced via Telegram that it was shutting down operations due to a 'lack of whales' (high-value holders) on the network, redirecting its customer base toward Bitcoin draining operations.+ 

Pyramid Scheme and Fake Boost Scam (2023–2024) → Official Bridge Infrastructure and Ethereum Contract Addresses

- Beginning in November 2023, scammers exploited the rising profile of the TON/Telegram integration to run pyramid schemes targeting Toncoin holders. According to research by Kaspersky Lab and AMLCrypto, victims received referral links from acquaintances directing them to unofficial Telegram bots that posed as cryptocurrency storage or yield platforms. Once connected, users were solicited to purchase 'boost' levels named 'bicycle,' 'car,' 'train,' 'plane,' and 'rocket,' priced between 5 and 500 TON, with a referral commission structure offering 25 TON per referred user—a classic pyramid payout structure. Individual losses ranged from $2 to $2,700 per victim. In H1 2024, over 1,200 fraud cases were reported on TON, a 45% increase year-over-year. Fake mini-apps mimicking Hamster Kombat—a Telegram game with a claimed 150 million cumulative players—and Notcoin, which gained approximately 35 million users, were used to trick users into connecting wallets to malicious contracts.+ 

Rug Pull Activity on TON DEXs → (section 15)

- Rug pulls have been documented on TON's primary decentralized exchanges, DeDust and Ston.fi. Academic research analyzing 48,380 tokens traded on these DEXs between January 1, 2024 and April 1, 2025 found patterns consistent with liquidity exit scams within the first five minutes of trading in a measurable portion of new token launches. A token explicitly labeled 'Rug Pull' (RUGPULL) with master contract address EQDzvs6ZhNDZMQMeKK2Inc8ymDpORl0H5hAfgtf3dXRbt7I7 is flagged and indexed on Tonviewer with 146–169 holders and a near-zero market cap of approximately $3,890. A DeDust liquidity pool at address EQDXOSJeAPITOr7NrdmqXRALMzskzKo087qCb-0V3ZrKFuUp, trading a pair labeled 'SCAM/NOT,' has also been flagged by the TON Explorer with associated jetton master contract EQDBNIPn1h1KkIzdNWEm5XyqM8usCoGcnBABjf66dAQzHs4c. These on-chain artifacts illustrate an ecosystem where fake or fraudulent tokens proliferate with minimal friction, as any participant can deploy jetton contracts without audits or listing gatekeeping. Tonviewer labels suspicious transactions as 'SUSPICIOUS' and fraudulent airdrop NFTs as 'SCAM,' but these flags are applied reactively.+ 

Illicit Marketplace Activity: Tudou Guarantee and TON-Adjacent Fraud Infrastructure → (section 16)

- Tudou Guarantee (formerly Huione Guarantee) is a Telegram-based illicit marketplace that processed over $12 billion in transactions before halting public operations in early 2026 following the arrest and extradition of operator Chen Zhi. The marketplace served as infrastructure for pig butchering fraud operations, selling stolen personal data, money laundering services, deepfake tools, and phishing website kits to operators across Southeast Asia. Its presence on Telegram created a structural overlap with the TON ecosystem, particularly following the well-publicized 2025 sale of the Telegram username 'danbao' for approximately 1.9 million TON (roughly $2.2 million), which was later identified as a transaction involving Tudou Guarantee. Blockchain analytics firm Elliptic flagged Tudou Guarantee's central administrative wallets for monitoring. A predecessor operation, Huione Guarantee, processed at least $24 billion in total, making it the largest illicit online marketplace in recorded history. Pig butchering scams globally caused an estimated $5.5 billion in losses in 2024 (per Cyvers) and $50 billion in 2025 (per UNODC/FTC estimates), with Telegram serving as a primary recruitment and operational channel.+ 

TON Blockchain as Malware Command-and-Control Infrastructure (2026) → (section 17)

- In May 2026, cybersecurity firm ThreatFabric disclosed that a new variant of TrickMo—an Android banking trojan first identified in 2019—was routing command-and-control (C2) communications through the TON network's ADNL (Abstract Datagram Network Layer) overlay. TON's use of 256-bit identifiers instead of conventional domain names makes its endpoints resistant to standard DNS-based takedown techniques, as operators do not rely on the public DNS hierarchy. The malware targets banking credentials and cryptocurrency wallets of users in France, Italy, and Austria via phishing overlays, keylogging, screen recording, SMS interception, and OTP suppression. TrickMo previously targeted approximately 40 variants delivered via 16 droppers with 22 distinct C2 infrastructures. The deliberate use of TON infrastructure for illicit C2 routing represents an emerging category of abuse distinct from direct scam activity within the TON DeFi ecosystem.+ 

Network Stability Incident: DOGS Airdrop Outage (August 2024) → (section 18)

- On August 28, 2024, the TON blockchain experienced a near six-hour block production outage caused by a transaction surge from the DOGS memecoin airdrop, which distributed approximately 440 billion of a 550 billion total supply to Telegram users in what was valued at over $550 million. Peak transaction volume reached over 67,000 transactions per second, far exceeding prior highs. Several validators were unable to clear backlogged transaction data, resulting in loss of consensus. The outage coincided with the news period surrounding Pavel Durov's arrest in France, compounding negative price pressure on Toncoin during that window. TON subsequently experienced a second outage later in 2024. These events highlight the network's architectural immaturity under high load conditions, with scalability risks that have direct implications for user asset safety during periods of ecosystem stress.+ 

Official Bridge Infrastructure and Ethereum Contract Addresses → (section 19)

- The official Wrapped TON (TONCOIN) ERC-20 contract on Ethereum, used by the TON-EVM bridge, is deployed at 0x582d872a1b094fc48f5de31d3b73f2d9be47def1 (verified on Etherscan as 'The Open Network: TONCOIN Token'). A separate TON Community token contract exists at Ethereum address 0x6a6c2ada3ce053561c2fbc3ee211f23d9b8c520a. Users interacting with bridge interfaces should verify these official contract addresses directly, as counterfeit bridge sites and fake wrapped token contracts have been a recurring attack vector across EVM-compatible ecosystems. No specific bridge exploit on TON has been documented as of the research date, but the existence of official bridge addresses provides targets that scammers can impersonate.+ 

Timeline events

+ added2019-10-11(no description)
+ added2020-06-26(no description)
+ added2025-02(no description)
+ added2025-03(no description)
+ added2025-07(no description)
+ added2026-01(no description)
+ added2026-05(no description)
+ added2026-07(no description)
- removed2018(no description)
- removed2019-10(no description)
- removed2020-03(no description)
- removed2020-05(no description)
- removed2020-06(no description)
- removed2020-06-25(no description)
- removed2022-11(no description)
- removed2023-09(no description)
- removed2024-02-06(no description)
- removed2024-04(no description)
- removed2024-05(no description)
- removed2024-06(no description)
- removed2024-06-23(no description)
- removed2024-07-10(no description)
- removed2024-08-28(no description)
- removed2024-10(no description)
- removed2024-10-07(no description)
- removed2024-12(no description)
- removed2025-05(no description)
- removed2026(no description)
- removed2026-05-12(no description)
~ changed2018-01: “” → “
~ changed2020-03-24: “” → “
~ changed2023-11: “” → “
~ changed2024-08-24: “” → “
~ changed2024-08: “” → “
~ changed2024-08-31: “” → “
~ changed2025-11: “” → “
~ changed2026-05-04: “” → “

Accepted submissions

No changes to accepted submissions.

Each version is bound to the decision event that created it. Verify the chain anchor for either via the audit log.

v1 hash: 25a01d2a7f115b63bae9ea2effae25ab334f700740aeb3a6fca33ba5df703277
v2 hash: 3b403fe4a9be3e7f0bce3ec512d5a9d34e65258ce11aa6dd564a92323931f17e