The
@Coredao_Org impersonation scam. 🚩
A never-ending story with a happy ending?
@Aayush_gupta_ji made a great post about it.
1. Scammers impersonating Core reach out.
2. They then send an ‘NDA’ as a Google Doc containing malware. The moment you open it, you’re compromised.
But there’s something we overlook.
The misuse of trust.
We communicate digitally and tend to trust other humans. But the era of blind trust is over. We can no longer believe what we see or hear.
Impersonation has become the number one driver of online scams:
• Fake accounts
• Compromised accounts
• Fake websites, links, and documents
• AI deepfakes and voice clones
• BEC scams and spoofing
We’ve seen it all.
AI tools make our lives easier, but they also make impersonation almost indistinguishable from reality.
We preach “Don’t Trust, Verify,” but we can't verify the actual person we’re interacting with.
This applies to
@Coredao_Org, but the same principle works for anyone who wants to become verifiable and make impersonation irrelevant.👇
Not everything has to be a token. Some things just have to work.
In 1991,
@StuartHaber and
@ScottStornetta published the paper “How to Time-Stamp a Digital Document.” They showed that you could prove the existence of a digital document at a specific time without needing a trusted third party to act as the sole authority.
This work laid the foundation for blockchain technology. The first blockchain has been running continuously for over 30 years, and it never had a token.
⚡Satoshi was inspired by their research and cited both gentlemen 3 times in the Bitcoin whitepaper.⚡
The same core idea has now evolved to solve what may be an even bigger problem today: verifying reality and distinguishing what’s real from what’s fake in the age of AI.
@SuremarkDigital, Cryptographic identity with certainty
Today, impersonators make it increasingly difficult for people and brands to maintain a clean digital reputation.
Suremark prevents people from getting scammed in
@Coredao_Org’s name, no matter how sophisticated the impersonation becomes.
If the Core team decides to apply “Don’t Trust, Verify” not only to on-chain transactions but also to identity, interactions, and content, they can protect themselves and enjoy the AI show without getting hurt.
With control over your digital voice, you decide what counts as authentic.
This is how
@Coredao_Org and its team should be protected
🔶Anyone from the team becomes verifiable.
Interactions (SMS, video calls, DMs, emails), both internal and external, can be verified in real time.
🔶Content from the team and official accounts becomes verifiable.
When posts, videos, or documents carry a cryptographic signature, anyone can independently check whether they actually come from Core.
People no longer have to blindly trust NDAs, interviews, or statements. They can simply verify the signature.
Becoming verifiable makes life easier.
Once the community knows they can verify Core, impersonation scams lose their power.
You receive a message or NDA? Just ask them to verify their identity or check for a cryptographic signature.
Not verified? Not real. Simple as that.
People often overlook
@SuremarkDigital. But whether you’re a regular user, a Bitcoiner, a Web3 builder, a company, or an exchange, cryptographic verifiability is becoming essential.
Use the right tool.
🚨 SCAM ALERT 🚨
Active scam targeting Web3 devs right now.
@AdamBendjemil reaches out on X claiming to be a contributor and BD at
@Coredao_Org, pitching a strategic advisory group helping startups in the Core DAO ecosystem and adjacent chains. Says your technical skills would be useful.
Moves the conversation to Telegram, where he adds you to a group with other scammers posing as
@DominusDomitius,
@JX_Solv, @CoreChrisFlores, @DylanDennisCore (Core DAO ecosystem leads).
Then they send an "NDA" as a Google Doc. The doc contains a fake "Google OAuth2 update" page that tells you to paste a base64 bash command into Terminal to "decrypt" it. That command is malware. The moment you run it, your machine is compromised: wallet keys, seed phrases, GitHub tokens, SSH keys, all gone.
Real
@Coredao_Org has nothing to do with this. They're being impersonated.
Block, report, do not click, do not run anything. RT so the next dev sees this in time.