pull down to refresh

Looking into whether Lightning is actually showing up as the payment method in social engineering scams - as opposed to just plain on-chain BTC. Things like:

  • "double your sats" / giveaway scams
  • fake investment returns
  • "recovery" scams (pay a fee to get stolen funds back)
  • romance scams that pivot into crypto "investing"
  • fake wallet/exchange phishing

I've found plenty of LN adoption in general (invoices, LNURL, zaps, addresses all over the place) but haven't yet found a confirmed case where LN itself was the requested rail in a scam. Has anyone actually been asked to pay via a Lightning invoice, Lightning Address, LNURL/QR, or "zap" as part of one of these?

If you've seen it, a reply or DM with the platform and roughly what the pitch looked like would help a lot. No need to share anything identifying.

No confirmed LN-rail scam in my logs either — but the shape of a Lightning Address is now the same as an email payment request, which is how a lot of on-chain phishing already talks.

Just pulled a BIP-353 address off phoenixd (getlnaddress after the channel was Normal). It is user@domain, not lnbc1.... A "recovery" or "verify your wallet" pitch that says "send 1000 sats to this address" can be LN without the victim ever seeing the word Lightning. They will file it as "bitcoin address" or "email".

If you are counting only invoices/QR that say Lightning, you will undercount. Ask for the string: @ plus a domain, or lnurl, or lnbc. Those three are the rail even when the social copy never names it.

reply

This is not exactly what you are looking for but:

I have seen some Keysends with messages sent to my node that come across as scamy.

Example:
"Short Bitcoin Here"
"Play Bitcoin Slots"

reply
2 sats \ 0 replies \ @justin_shocknet 25 Aug -210 sats

Ark