Bitcoin Forum
July 24, 2026, 08:58:47 PM *
News: Latest Bitcoin Core release: 31.1 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: [SCAM ALERT] Soldrift / @devbeast5775 — Solana Wallet Drain & KuCoin-Linked Flow  (Read 94 times)
ChainRiskOSINT (OP)
Newbie
*
Offline

Activity: 6
Merit: 0


View Profile
June 10, 2026, 07:26:48 AM
Last edit: June 11, 2026, 02:05:21 PM by ChainRiskOSINT
 #1


UPDATE 2 — Expanded GitHub / Telegram / HFT Fund-Flow OSINT Evidence

This thread has been updated with a larger public OSINT archive and YouTube evidence series covering the reported Soldrift / Hodlwarden / @devbeast5775 GitHub–Telegram identity cluster.

The concern is not only a failed trading-bot deal or a simple Telegram scam.

The stronger risk model is a possible long-term GitHub trust-trap and financial-asset harvesting framework.

The reported pattern includes:

  • 80+ GitHub repositories and forked / MVP-level source-code projects used to build developer credibility.
  • 1k+ GitHub visibility / potential customer reach.
  • Professional-looking Solana / Pump.fun / HFT / arbitrage / trading-bot branding.
  • Telegram contact paths leading potential buyers into private tool sales.
  • Possible exposure to malicious code, backdoors, malware, .env leakage, private-key leakage, RPC / GRPC token exposure, exchange API exposure, VPS/root-access abuse, and wallet-drain risk.
  • Post-incident wallet-flow and HFT / arbitrage / exchange-linked fund-flow leads requiring AML, compliance, and law-enforcement review.

Important clarification:

This is not a final legal conclusion against any exchange, employee, or third party.

Any KuCoin-linked, HFT-linked, API-linked, or exchange-linked flow should be treated as an OSINT / AML review lead requiring independent verification by compliance teams, blockchain investigators, and law-enforcement partners.

The visible account may be only the front-facing layer. The broader concern is a possible organized cyber-enabled financial-harvesting structure using GitHub credibility, Telegram support paths, private Solana tools, wallet access, and exchange-linked fund-flow routes.

Updated public OSINT archive:
https://soldrift-devbeast5775-warning.github.io/solana-scam-osint-report/

Secondary mirror archive:
https://soldrift-devbeast5775-warning.github.io/soldrift-devbeast5775-scam-warning/

YouTube OSINT evidence videos:

Search keywords:

Soldrift scam warning, Hodlwarden scam warning, devbeast5775 Telegram, Soldrift GitHub, Hodlwarden GitHub, GitHub Telegram scam, Solana bot scam, Pump.fun bundler scam, Solana wallet drain, backdoored trading bot, private key exposure, .env exposure, GRPC_TOKEN exposure, HFT fund-flow OSINT, KuCoin-linked wallet lead, Web3 OSINT evidence.

Safety warning:

Never run unaudited Solana bots, Pump.fun bundlers, snipers, HFT tools, arbitrage bots, volume bots, wallet warmers, or wallet-management tools on funded servers.

Never expose private keys, seed phrases, .env files, RPC tokens, GRPC_TOKEN values, exchange API keys, wallet exports, local PC access, SSH access, or VPS/root access to unknown developers.

This material is provided for public safety, evidence preservation, platform-safety review, exchange compliance review, and cybercrime-reporting support.

No harassment, doxxing, threats, or retaliation is intended. All claims should be treated as OSINT leads requiring verification.








SCAM ALERT: Soldrift / @devbeast5775
Solana Wallet Drain, Backdoored Trading Bot, and KuCoin-Linked HFT / Arbitrage Flow

This is a public safety warning for Solana, Web3, HFT, MEV, arbitrage-bot, and crypto trading-bot users.

The developer using the name Soldrift, associated with Telegram @devbeast5775 and GitHub soldrift, is linked to a reported Solana trading-bot scam involving suspicious wallet-drain behavior, VPS/server-access abuse, and fund flows requiring urgent review.

This report is based on victim experience, wallet activity, transaction evidence, suspicious fund movement, and technical risk indicators.

This post does not encourage harassment, threats, doxxing, or personal attacks. Its purpose is to help users, exchanges, blockchain explorers, AML teams, and security researchers independently review the evidence and prevent further losses.

WARNING

Do not run unverified software from this developer.

Do not provide VPS root access, SSH access, deployment access, private keys, seed phrases, RPC keys, exchange API keys, wallet files, or .env files.

Any developer who requires unnecessary access to your server, wallet environment, private credentials, RPC keys, or exchange API keys should be treated as high risk.

1. REPORTED SCAM PATTERN

The actor using the name Soldrift promotes custom Solana trading tools, including:

  • Solana bundler tools
  • HFT trading bots
  • MEV / Jito backrun systems
  • Arbitrage-bot infrastructure
  • Custom VPS-based trading dashboards

The reported pattern appears to involve the following:

  • The victim is offered a custom Solana HFT / MEV / arbitrage / bundler bot.
  • The victim is encouraged to run private code, repositories, or server-side software.
  • The victim may be asked to provide VPS, SSH, root, or deployment access under the excuse of performance optimization.
  • The software environment may expose sensitive files such as private keys, RPC tokens, API keys, wallet files, and .env files.
  • Victim-linked funds then appear to connect with active Solana wallet flows requiring exchange, explorer, and AML review.

2. WHY THIS CASE IS HIGH RISK

This is not a normal failed development job or a simple software dispute.

The concern is not only that one developer allegedly failed to deliver a tool. The concern is that the reported pattern involves trading-bot software, VPS / SSH / root access requests, possible exposure of private keys and environment files, suspicious wallet movement after the victim interaction, and a wallet cluster that appears to interact with larger HFT / arbitrage-style flows.

This does not claim that KuCoin itself was hacked.

The concern is that victim-linked funds may have entered or interacted with a larger KuCoin-linked HFT / arbitrage / API-related flow. KuCoin compliance and AML teams should urgently review any related accounts, API keys, trading entities, deposits, withdrawals, order history, settlement activity, and withdrawal routes.

3. POSSIBLE LARGER OPERATION BEHIND THE FRONT-END ACTOR

The scale and behavior of the HFT / arbitrage flow appear inconsistent with a small independent scammer acting alone.

This raises serious questions about whether Soldrift is only the front-end recruiter, malicious developer, VPS-access operator, or credential-exfiltration point, while the actual liquidity operation may be controlled by a larger entity.

Possible structures requiring investigation include:

  • External customer trading account
  • API-based trading entity
  • Third-party liquidity operator
  • Market-making account
  • Affiliate or partner account
  • Employee-linked or insider-related account
  • Organized wallet-drain and fund-routing operation

This is not a public accusation that any exchange employee or insider is involved.

However, the possibility should be investigated by KuCoin and relevant compliance teams because the victim-linked flow appears to reach beyond a simple isolated scam wallet.

Key concern:

Quote
The victim funds do not appear to be simply sitting in an isolated scam wallet. They appear to be connected to an active Solana HFT / arbitrage operating flow with KuCoin-linked settlement or API-related activity.

4. ADDRESSES OF INTEREST FOR SECURITY REVIEW

The following Solana addresses are listed as addresses of interest based on observed or reported transaction flow.

They are provided for independent review, monitoring, and risk analysis by affected users, exchanges, blockchain explorers, AML teams, and security researchers.

Primary Address of Interest:

Code:
EfwJn8cXCYhcGrsavxWSDbUFHPrCK9gvdCr6AVywFBPg

Solscan:
https://solscan.io/account/EfwJn8cXCYhcGrsavxWSDbUFHPrCK9gvdCr6AVywFBPg

Additional Addresses of Interest:

Code:
GLoyGTsJiS3iDAV66NNsiRWkm1VU6H6UjaywmNdaxs4L
A8Scw8Yt85anFYzFjBiwcwZjsoDZSdicyNKpiFrCsZQm
E8RcJDs3SaBP2udWy6bD7576zJ3WitfbVh16vgeqoAgi
5cZWa1KZQnMPeXTHPRF8JSEPMhzRaHPeAoG1rPtiHGc

Solscan:

GLoyGTsJiS3iDAV66NNsiRWkm1VU6H6UjaywmNdaxs4L

A8Scw8Yt85anFYzFjBiwcwZjsoDZSdicyNKpiFrCsZQm

E8RcJDs3SaBP2udWy6bD7576zJ3WitfbVh16vgeqoAgi

5cZWa1KZQnMPeXTHPRF8JSEPMhzRaHPeAoG1rPtiHGc

These addresses should be reviewed for possible links to suspicious fund movement, victim-reported losses, exchange deposit patterns, API-linked trading activity, arbitrage operations, or operational infrastructure.

5. TRANSACTION HASHES FOR INDEPENDENT REVIEW

TX 1 — Initial Suspicious Flow

Code:
33Jc35XrQwhFAZN93Gcsyi2a3Zb9ujgxNeSPcD2xUMzcQ3b18kqCUHHhUdzzAY5dNDgQHSfqFM7RshX7A4KvCnKW

Solscan:
TX 1

TX 2 — Inter-Wallet Flow

Code:
2Zm267N9eDAbvLX3WooJYmLc5YCkNKyBitV6CRn3HBApxEFHMc7tBuLtHXEcAjmjDhsDz3aBfEefK7HdKPuT8um7

Solscan:
TX 2

TX 3 — Exchange / API-Linked Flow Requiring Review

Code:
3beyL4Um4Wt9duWbCQrStySMdLF33k5QAP1h49VQkE6PTJaHtp36G3JGnTjmVDZ7RcY4z1v8C7ngnNnvHK9wkoqV

Solscan:
TX 3

These transactions should be independently examined before any labeling, freezing, enforcement, or public attribution action is taken.

6. REQUESTED ACTION

KuCoin and relevant security teams should urgently preserve records, review related accounts, review API activity, investigate possible trading-entity connections, and apply temporary withdrawal-risk controls if supported by evidence.

7. PUBLIC OSINT REPORT

Full public report:

Soldrift / devbeast5775 Public Safety Notice

FINAL WARNING

If you are contacted by Telegram @devbeast5775 or GitHub soldrift, proceed with extreme caution.

Do not install software.
Do not provide server access.
Do not expose wallet credentials.
Do not share RPC keys or exchange API keys.
Do not run private trading-bot repositories without a full security audit.

Stay safe. Verify everything. Never expose your keys.
ChainRiskOSINT (OP)
Newbie
*
Offline

Activity: 6
Merit: 0


View Profile
June 10, 2026, 07:37:54 AM
 #2

UPDATE 1: ADDITIONAL CONTEXT

This follow-up provides additional context on why this case should be treated as more than a normal software dispute.

The core concern is not only that one developer allegedly failed to deliver a tool.

The concern is that the reported pattern involves:

  • Solana trading-bot software
  • VPS / SSH / root access requests
  • Exposure risk to private keys, RPC keys, API keys, and .env files
  • Suspicious wallet movement after the victim interaction
  • A wallet cluster that appears to interact with larger HFT / arbitrage-style flows
  • Possible KuCoin-linked settlement, API, or liquidity activity requiring AML review

Important clarification:

This report does not claim that KuCoin itself was hacked.

The issue is that victim-linked funds may have entered or interacted with an exchange/API-linked trading flow. That is why KuCoin compliance and AML teams should review related accounts, deposits, withdrawals, API activity, KYC ownership, device logs, login IPs, order history, and withdrawal routes.

Why the scale matters:

The scale and behavior of the HFT / arbitrage flow appear inconsistent with a small independent scammer acting alone.

This raises the possibility that Soldrift may be only one part of a larger structure, such as:

  • Front-end recruiter
  • Malicious developer
  • VPS-access operator
  • Credential-exfiltration point
  • Wallet-drain entry point
  • Link between victims and a larger trading/liquidity operation

The larger flow may involve an API-based trading entity, third-party liquidity operator, market-making account, affiliate account, employee-linked account, or other trading infrastructure.

This is not a public accusation that any exchange employee or insider is involved.

However, the possibility should be investigated by KuCoin and relevant compliance teams because the victim-linked flow appears to reach beyond a simple isolated scam wallet.

Requested review from KuCoin / AML teams:

KuCoin should urgently review whether any account, API key, market-making entity, affiliate account, employee-linked account, or third-party operator is connected to the listed wallet cluster or transaction flow.

KuCoin should also preserve KYC records, login IP records, device/session logs, API key creation logs, API usage logs, order history, deposit history, withdrawal history, linked account data, and internal risk flags.

If the evidence supports it, temporary withdrawal-risk controls should be applied to prevent further dissipation or laundering of victim-linked funds.

Key point:

The victim funds do not appear to be simply sitting in an isolated scam wallet.

They appear to be connected to an active Solana HFT / arbitrage operating flow with KuCoin-linked settlement or API-related activity.

This is why the case requires urgent review by exchanges, blockchain explorers, security researchers, and law-enforcement partners.

Public report link:

Soldrift / devbeast5775 Public Safety Notice
ChainRiskOSINT (OP)
Newbie
*
Offline

Activity: 6
Merit: 0


View Profile
June 10, 2026, 03:41:46 PM
 #3

UPDATE 2: EVIDENCE INDEX / WALLETS & TRANSACTION HASHES

This comment organizes the wallet addresses and transaction hashes for independent review.

All readers, security researchers, exchanges, blockchain explorers, and AML teams are encouraged to verify the data independently on Solana explorers before drawing conclusions.

1. PRIMARY ADDRESS OF INTEREST

Code:
EfwJn8cXCYhcGrsavxWSDbUFHPrCK9gvdCr6AVywFBPg

Explorer:
Solscan — Primary Address

Reason for review:

This address appears to be connected to active Solana trading / HFT / arbitrage-style wallet flow requiring exchange and AML review.

2. ADDITIONAL ADDRESSES OF INTEREST

Code:
GLoyGTsJiS3iDAV66NNsiRWkm1VU6H6UjaywmNdaxs4L
A8Scw8Yt85anFYzFjBiwcwZjsoDZSdicyNKpiFrCsZQm
E8RcJDs3SaBP2udWy6bD7576zJ3WitfbVh16vgeqoAgi
5cZWa1KZQnMPeXTHPRF8JSEPMhzRaHPeAoG1rPtiHGc

Explorer links:

Solscan — GLoyGTsJiS3iDAV66NNsiRWkm1VU6H6UjaywmNdaxs4L

Solscan — A8Scw8Yt85anFYzFjBiwcwZjsoDZSdicyNKpiFrCsZQm

Solscan — E8RcJDs3SaBP2udWy6bD7576zJ3WitfbVh16vgeqoAgi

Solscan — 5cZWa1KZQnMPeXTHPRF8JSEPMhzRaHPeAoG1rPtiHGc

Reason for review:

These addresses appear in the related transaction flow and should be reviewed for possible fund routing, victim-linked movement, exchange interaction, API-linked trading activity, or operational infrastructure.

3. TRANSACTION HASHES FOR INDEPENDENT REVIEW

TX 1 — Initial Suspicious Flow

Code:
33Jc35XrQwhFAZN93Gcsyi2a3Zb9ujgxNeSPcD2xUMzcQ3b18kqCUHHhUdzzAY5dNDgQHSfqFM7RshX7A4KvCnKW

Explorer:
Solscan — TX 1

TX 2 — Inter-Wallet Flow

Code:
2Zm267N9eDAbvLX3WooJYmLc5YCkNKyBitV6CRn3HBApxEFHMc7tBuLtHXEcAjmjDhsDz3aBfEefK7HdKPuT8um7

Explorer:
Solscan — TX 2

TX 3 — Exchange / API-Linked Flow Requiring Review

Code:
3beyL4Um4Wt9duWbCQrStySMdLF33k5QAP1h49VQkE6PTJaHtp36G3JGnTjmVDZ7RcY4z1v8C7ngnNnvHK9wkoqV

Explorer:
Solscan — TX 3

4. REQUEST TO SECURITY RESEARCHERS

If anyone can identify additional related wallets, exchange deposit addresses, pass-through addresses, API-linked trading wallets, or connected transaction clusters, please reply with verifiable evidence only.

Useful evidence includes wallet addresses, transaction hashes, explorer links, screenshots of relevant wallet flow, GitHub repository links, Telegram handles, code snippets showing malicious behavior, and timeline of victim interaction.

Do not post private keys, seed phrases, unrelated personal data, or doxxing material.

5. PUBLIC OSINT REPORT

Full public report:

Soldrift / devbeast5775 Public Safety Notice
albon
Legendary
*
Offline

Activity: 2506
Merit: 2413



View Profile
June 10, 2026, 11:17:14 PM
 #4

If you are contacted by Telegram @devbeast5775 or GitHub soldrift, proceed with extreme caution.

Do not install software.
Do not provide server access.
Do not expose wallet credentials.
Do not share RPC keys or exchange API keys.
Do not run private trading-bot repositories without a full security audit.
Regardless of the person whose Telegram and GitHub accounts you shared, no one should trust strangers or people who DM them first without doing their own research. All the advice you mentioned should already be common knowledge.

Especially, sharing wallet credentials or exchange API keys is very sensitive and should never be shared with anyone. Also, using any trading bot randomly is risky, as many of the bots advertised as "AI" with exaggerated features are often scams designed to drain victims’ funds and steal their money.

Thanks for the post and the warning, Hopefully no one gets scammed due to greed or lack of experience.

█████████████████████████
███████▀▀███████▀▀███████
█████▀░░▄███████▄░░▀█████
███▀░░██████▀░▀████░░▀███
██▀░░▀▀▀████████████░░▀██
██░░█▄████▀▀███▀█████░░██
██░░███▄▄███████▀▀███░░██
██░░████████████████░░██
██▄░░████▄▄██████▄▄█░░▄██
███▄░░██████░░████░░▄███
█████▄░░▀███░░▐▀░░▄█████
███████▄▄███████▄▄███████
█████████████████████████
.
 ROOBET .██████. BET ON WORLD CUP  🗺 ⚽︎.██████.
|

█▄█
▀█▀
████▄▄██████▄▄████
█▄███▀█░░█████░░█▀███▄█
▀█▄▄░▐█████████▌▄▄█▀
██▄▄█████████▄▄████▌
██████▄▄████████
█▀▀████████████████
██████
█████████████
██
█▀▀██████████████
▀▀▀███████████▀▀▀▀
|.
   BET NOW   
ChainRiskOSINT (OP)
Newbie
*
Offline

Activity: 6
Merit: 0


View Profile
June 11, 2026, 08:52:27 AM
 #5

If you are contacted by Telegram @devbeast5775 or GitHub soldrift, proceed with extreme caution.

Do not install software.
Do not provide server access.
Do not expose wallet credentials.
Do not share RPC keys or exchange API keys.
Do not run private trading-bot repositories without a full security audit.
Regardless of the person whose Telegram and GitHub accounts you shared, no one should trust strangers or people who DM them first without doing their own research. All the advice you mentioned should already be common knowledge.

Especially, sharing wallet credentials or exchange API keys is very sensitive and should never be shared with anyone. Also, using any trading bot randomly is risky, as many of the bots advertised as "AI" with exaggerated features are often scams designed to drain victims’ funds and steal their money.

Thanks for the post and the warning, Hopefully no one gets scammed due to greed or lack of experience.

This is not basic common sense; this is credibility infrastructure fraud.

The issue is not simply that users should avoid trusting strangers on Telegram.

The real issue is that a technically capable scammer can build credibility first:

  • GitHub repositories
  • developer profiles
  • social followers
  • working or partially working software
  • Solana / Pump.fun / HFT / sniper / bundler terminology
  • technical documentation
  • Telegram support channels
  • staged installation or upgrade requests

Then, after the victim believes the developer is legitimate, the attacker can request VPS access, .env configuration, private-key handling, RPC tokens, GRPC_TOKEN values, or exchange API keys.

That is not a normal beginner scam.

That is a credibility-based fraud framework designed to defeat basic due diligence.
ChainRiskOSINT (OP)
Newbie
*
Offline

Activity: 6
Merit: 0


View Profile
June 11, 2026, 08:59:55 AM
Last edit: June 11, 2026, 09:28:12 PM by Mr. Big
 #6

This is not basic common sense; this is credibility infrastructure fraud.

I agree with the general advice that users should never blindly trust unknown Telegram contacts, GitHub accounts, private-key requests, exchange API requests, or trading-bot promises.

However, reducing this case to ordinary “common sense” misses the actual risk model.

This is not a simple low-effort Telegram scam where an anonymous user directly asks for a seed phrase.

The concern is a long-term credibility-based fraud framework.

A technically capable actor does not need to ask for a seed phrase directly. Instead, credibility can be built first through:

  • public GitHub repositories
  • technical-looking documentation
  • developer profiles and social accounts
  • Solana / Pump.fun / HFT / sniper / arbitrage / bundler terminology
  • working or partially working software demonstrations
  • Telegram support channels
  • remote installation, debugging, or upgrade support

This type of structure can mislead not only beginners, but also semi-technical users who believe they are performing due diligence by checking GitHub history, repositories, public profiles, followers, demos, and developer branding.

The credibility itself becomes part of the attack surface.

The dangerous structure is usually not immediate theft. It is gradual trust escalation:

  • The victim first checks GitHub and sees repositories, technical projects, and developer branding.
  • The operator presents himself as a Solana / Web3 / HFT / sniper / arbitrage / bundler developer.
  • The tool may partially work or be demonstrated as working, creating false confidence.
  • The victim may receive source code, but most users cannot fully audit complex Solana bot code.
  • The operator then pushes toward VPS access, installation support, debugging, or “final upgrade” work.
  • A staged bug, incomplete version, or urgent upgrade can be used as a reason to request deeper access.

At that point, the attacker may gain access to sensitive operational material, including:

  • VPS/root access
  • .env files
  • private keys
  • wallet export functions
  • RPC tokens
  • GRPC_TOKEN values
  • exchange API keys
  • remote debugging or upgrade access
At that stage, the risk is no longer theoretical.

A funded server, private key, .env file, RPC credential, exchange API key, or wallet export can become exposed.

This is not simply about greed or inexperience.

This is about professional-looking software potentially being used as a delivery mechanism for:

  • wallet draining
  • private-key exposure
  • server compromise
  • backdoor installation
  • credential theft
  • exchange/API abuse
  • post-theft fund routing
There is also a broader OSINT concern.

The reported public traces involve:

  • hodlwarden
  • soldrift
  • whistledev411
  • Telegram @whistle
  • Telegram @devbeast5775
The concern is not merely one username or one Telegram account.

The concern is a possible GitHub–Telegram identity cluster involving repository relationships, contact-path links, overlapping Solana bot tooling, and the same category of Pump.fun / sniper / bundler / volume-bot infrastructure.

This is why the warning matters.

This should be treated as a serious Web3 security warning, not as a generic “common sense” comment.

The purpose of this thread is to warn future buyers, developers, token launchers, and Solana users before they run unknown tools such as:

  • Pump.fun bundlers
  • Solana snipers
  • HFT bots
  • arbitrage bots
  • volume bots
  • wallet warmers
  • copy-trading bots
  • private launch tools

Minimum safety rule:

  • Never run unaudited trading tools on a funded server.
  • Never give VPS/root access to an unknown developer.
  • Never put private keys or seed phrases into unknown code.
  • Never share exchange API keys, RPC tokens, GRPC_TOKEN values, or .env files.
  • Never allow a remote developer to “fix” or “upgrade” a live wallet system.
  • Never assume GitHub followers, old repositories, working demos, or developer branding prove safety.
If a tool touches wallets, private keys, funded accounts, exchange APIs, RPC credentials, or server secrets, treat it as hostile until independently audited.

The available OSINT suggests that this may not be an isolated one-time incident, but part of a credibility framework built over a long period through developer branding, repositories, social presence, Telegram contact paths, and Solana bot infrastructure.

The structure behind this long-running fraud framework is being closely reviewed, and more detailed technical and OSINT information will be updated as additional evidence is preserved and verified.



Additional update — the reopening of the related GitHub accounts may significantly expand the evidence base.

The fact that these GitHub accounts and related public profiles are visible again should not be viewed only as a setback.

From an OSINT and evidence-preservation perspective, it creates an opportunity to document the structure in far greater detail:

  • repository relationships
  • fork history
  • commit-history traces
  • README contact paths
  • Telegram identity links
  • developer-profile overlaps
  • portfolio and social-profile connections
  • Solana / Pump.fun / sniper / bundler / volume-bot infrastructure overlap
  • possible wallet-flow and exchange-linked traces after reported compromise

The concern is no longer limited to one Telegram account or one GitHub repository.

The available public traces suggest a broader identity cluster involving:

  • hodlwarden
  • soldrift
  • whistledev411
  • Telegram @whistle
  • Telegram @devbeast5775
This should be treated as a structured OSINT and platform-safety matter, not as a simple username dispute.

Based on the visible public traces, this may involve one actor, two actors, or a wider support structure behind the visible accounts. There are also public-profile leads suggesting Malaysia-linked and Pakistan-linked traces. These should be handled carefully as OSINT leads requiring verification, not as final legal conclusions.

The important point is the apparent structure.

This does not look like a one-time amateur scam account. The public footprint suggests a long-running credibility framework built through developer branding, GitHub repositories, social presence, Telegram contact paths, and professional-looking Solana bot infrastructure.

That type of structure can be used to target legitimate users, developers, and launch teams who are looking for private tools such as:

  • Pump.fun bundlers
  • Solana snipers
  • HFT tools
  • arbitrage bots
  • volume bots
  • wallet warmers
  • copy-trading bots
  • private launch systems

The victims are not necessarily reckless beginners.

A legitimate launcher, trader, or developer may be deceived by what appears to be a real technical background: GitHub history, working-looking software, old repositories, social proof, Telegram support, and bot-related documentation.

That is the core danger of this framework.

The allegation is not simply that someone sent a suspicious Telegram DM. The concern is that professional-looking software and developer credibility may have been used as a delivery mechanism for phishing, wallet draining, private-key exposure, server compromise, backdoor installation, credential theft, or exchange/API abuse.

The purpose of documenting this is not harassment, doxxing, or retaliation.

The purpose is:

  • public Web3 safety
  • evidence preservation
  • platform-safety reporting
  • exchange-risk reporting
  • cybercrime complaint preparation
  • warning legitimate launchers, developers, traders, and Solana users
This warning is aimed especially at people who may be targeted by actors who treat wallet phishing and draining as if it were a game, with no regard for the financial and personal damage caused to victims.

The objective is to preserve evidence and escalate the material through lawful channels, including platform abuse teams, exchange compliance teams, cybercrime reporting portals, and relevant law-enforcement complaint channels where applicable.

The reopening of the public accounts may now allow more precise documentation of the actors, aliases, repository links, Telegram paths, technical tooling, and possible fund-flow relationships.

Further technical, repository-level, Telegram-contact, OSINT, and fund-flow details are being reviewed and will be updated as additional evidence is preserved and verified.
ChainRiskOSINT (OP)
Newbie
*
Offline

Activity: 6
Merit: 0


View Profile
June 13, 2026, 06:20:01 PM
 #7

Update — Possible Large-Scale Phishing Crime Network Pattern Found

A new public OSINT evidence archive has been published for the reported Soldrift / devbeast5775 / hodlwarden case.

Archive:
https://soldrift-scam-warning.github.io/solana-scam-osint-report/

The new archive organizes original screenshots, GitHub profile records, Telegram identity records, Solscan wallet-flow screenshots, GitHub Trust & Safety response material, Bitcointalk warning evidence, Google search captures, and six OSINT evidence videos.

The key concern is no longer limited to a simple freelance dispute. The evidence pattern suggests a possible large-scale phishing and crypto cybercrime network using developer credibility, GitHub identities, Telegram handles, Solana trading-tool access, private-key exposure, malicious backdoor risk, wallet-drainer patterns, and exchange-routing fund-flow behavior.

Core identifiers:
Soldrift / devbeast5775 / hodlwarden

Core risk frame:
Soldrift scam, devbeast5775 scam, hodlwarden scam, Solana wallet drainer, phishing tool, malicious backdoor, fake developer trust trap, Solana HFT / arbitrage bot risk, KuCoin / Binance routing concern, and victim-linked fund-flow evidence.

This update is posted for public safety, evidence preservation, and community warning purposes.
Meme Launch Master
Newbie
*
Offline

Activity: 3
Merit: 0


View Profile
July 23, 2026, 04:56:23 PM
 #8

Update — Possible Large-Scale Phishing Crime Network Pattern Found

A new public OSINT evidence archive has been published for the reported Soldrift / devbeast5775 / hodlwarden case.

Archive:
https://soldrift-scam-warning.github.io/solana-scam-osint-report/

The new archive organizes original screenshots, GitHub profile records, Telegram identity records, Solscan wallet-flow screenshots, GitHub Trust & Safety response material, Bitcointalk warning evidence, Google search captures, and six OSINT evidence videos.

The key concern is no longer limited to a simple freelance dispute. The evidence pattern suggests a possible large-scale phishing and crypto cybercrime network using developer credibility, GitHub identities, Telegram handles, Solana trading-tool access, private-key exposure, malicious backdoor risk, wallet-drainer patterns, and exchange-routing fund-flow behavior.

Core identifiers:
Soldrift / devbeast5775 / hodlwarden

Core risk frame:
Soldrift scam, devbeast5775 scam, hodlwarden scam, Solana wallet drainer, phishing tool, malicious backdoor, fake developer trust trap, Solana HFT / arbitrage bot risk, KuCoin / Binance routing concern, and victim-linked fund-flow evidence.

This update is posted for public safety, evidence preservation, and community warning purposes.




🚨 **SCAM ALERT: Soldrift / @devbeast5775**

Do not connect your wallet.
**Wallet drained → funds moved → KuCoin-linked flow.**

Block. Report. Warn others.
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!