A coordinated criminal operation is leveraging social media platforms and Discord to promote hundreds of sophisticated fake gambling and gaming websites designed to steal cryptocurrency from unsuspecting players. The network encompasses more than 1,200 active scam domains, each employing identical social engineering tactics and shared technical infrastructure to maximize victim payouts.

The scheme typically begins with misleading advertisements claiming partnerships with well-known content creators. These ads reference personalities like Mr. Beast, who recently established Beast Games, and promise players a $2,500 credit using a supplied promotional code. The gaming sites themselves feature polished interfaces and legitimate-looking games—such as basketball betting games like B-Ball Blitz—where users wager on outcomes.

The fraud escalates when victims attempt to withdraw their supposed winnings. The sites reject withdrawal requests and demand a "verification deposit" in cryptocurrency, typically around $100, before releasing any funds. Victims who comply are subsequently asked for additional payments, with no legitimate withdrawals ever processed. The displayed winnings are entirely fabricated, and deposited cryptocurrency disappears permanently.

https://www.youtube.com/embed/lNjqXIq1s5g?si=-30qS1Bw73VdIXow

Adding insult to injury, victims frequently encounter "recovery experts" on social media who falsely claim they can retrieve lost funds, perpetuating the victimization cycle.

Uncovering the Infrastructure

Security researcher Thereallo, a 17-year-old developer who manages multiple Discord servers, began investigating after witnessing relentless spam promoting these sites. "We were being spammed relentlessly by these scam posts from compromised or purchased [Discord] accounts," Thereallo said. "I got frustrated with just banning and deleting, so I started to investigate the infrastructure behind the scam messages. This is not a one-off site, it's a scalable criminal enterprise with a clear playbook, technical fingerprints, and financial infrastructure."

The “verification deposit” stage of the scam requires the user to deposit cryptocurrency in order to withdraw their “winnings.”

By analyzing the code across multiple gaming sites, Thereallo discovered they all utilized the same API key for an online chatbot, suggesting either limited deployment or custom development. A search using the threat hunting platform Silent Push identified at least 1,270 recently registered and active domains, all featuring gaming or wagering-related names.

Unified Platform, Multiple Fronts

The operators generate a unique Bitcoin wallet for each gaming domain, but these function as decoys. "Once the victim deposits funds, they are never able to withdraw any money. Any attempts to contact the 'Live Support' are handled by a combination of AI and human operators who eventually block the user. The chat system is self-hosted, making it difficult to report to third-party service providers."

The scam gaming site spinora dot cc shares the same chatbot API as more than 1,200 similar fake gaming sites.

Thereallo identified a revealing technical characteristic: attempting to register at multiple sites from the same device and internet address triggers blocking mechanisms. "They're tracking my VPN IP across their entire network," Thereallo explained. "My password manager also proved it. It tried to use my dummy email on a site I had never visited, and the site told me the account already existed. So it's definitely one entity running a single platform with 1,200+ different domain names as front-ends. This explains how their support works, a central pool of agents handling all the sites. It also explains why they're so strict about not giving out wallet addresses; it's a network-wide policy."

Similarities to Pig Butchering Schemes

These scambling operations share methodological overlap with "pig butchering" schemes, the more elaborate cryptocurrency fraud where victims are gradually manipulated by online contacts into depositing money on fraudulent trading platforms. However, the scambling network differs significantly in scale and execution. Pig butchering typically involves kidnapped individuals in Asia coerced into operating from cubicles, whereas these gaming sites employ automation and centralized support to extract smaller amounts from larger victim pools with reduced operational overhead and lower initial investment.

Zach Edwards from Silent Push noted the unusual investment level in these operations. "That's a very odd type of pig butchering network and not like what we typically see, with much lower investments in the sites and lures," Edwards said. The operators nonetheless spend substantial resources ensuring the sites maintain a polished, professional appearance resembling legitimate modern casinos.

Source: Krebs on Security