Scammers monitor every tweet containing requests for support on MetaMask, TrustWallet, and other popular crypto wallets and respond to them with scam links within seconds.

To conduct these targeted phishing attacks, scammers abuse Twitter's APIs that allow them to monitor all public tweets for specific keywords or phrases.
If these phrases are present, these same programs will direct Twitter bots under the scammer's control to automatically reply to tweets as fake support agents with links to scams that steal cryptocurrency wallets.
These attacks are nothing new, and there was a report about them in May. However, these attacks have spread to other cryptocurrencies and the scams continue to run rampant.
The anatomy of the Twitter crypto scam
In tests conducted by BleepingComputer, tweets containing the words “support” or “help” along with keywords like “MetaMask,” “Phantom,” “Yoroi,” and “Trust Wallet” will lead to near-instant responses from Twitter bots with fake support forms or accounts.
Other keywords have mixed results, such as wallet names and the word “stolen.”.
The first test of these cryptocurrency scam bots was to pack a tweet with lots of keywords and have Bleepingcomputer see what happens.
He then conducted further testing to try to narrow down which keywords would trigger the bot's responses.
Within seconds of publishing our tests, we received responses from multiple scam accounts pretending to be MetaMask and TrustWallet support accounts, “previous victims,” or helpful users.
All scam responses have a common purpose – to steal the recovery phrases for a victim's wallet, which attackers can use to import the wallet into their own devices.
To steal recovery phrases, threat actors created support forms on Google Docs and other cloud.
These forms impersonate a basic support form, asking the user for their email address, the issue they are experiencing, and their wallet recovery phrase, as seen in the fake MetaMask support form below.

When they ask for the recovery phrase, they include gibberish about it being processed by the “encrypted cloud bot,” likely trying to convince the user to publish the sensitive information.

Once the recovery phrase is sent to the attackers, the game is over and they now have full access to the cryptocurrency inside your wallet and can transfer it to other wallets they control.
Before you assume that no one falls victim to these scams, unfortunately this is untrue and many Twitter users have had their wallets, cryptocurrencies, and NFTs stolen.
Never share recovery phrases!
As a general rule, you should never share your wallet recovery phrase with anyone. The recovery phrase is for you alone and no legitimate support person from MetaMask, TrustWallet, or elsewhere will ever ask you for it.
It's also important to remember not to share your screen with an untrusted user who then asks you to show your recovery phrase. At that point, they can simply take a screenshot and then use it for their attacks.
Ultimately, these attacks will continue unless Twitter finds a way to prevent these bots from running rampant, restrict the use of specific keywords, or place tighter controls on who can sign up for their developer platform.
Information source: bleepingcomputer.com




