⛔ 𝐂𝐚𝐥𝐞𝐧𝐝𝐥𝐲 𝐒𝐨𝐜𝐢𝐚𝐥 𝐄𝐧𝐠𝐢𝐧𝐞𝐞𝐫𝐢𝐧𝐠 𝐒𝐜𝐚𝐦 ⛔
Have you been contacted by a 'Forbes Employee' or someone who wants to interview you for an article, partnership, or job? Are they asking you to connect your wallet or twitter account to Calendly? If so, DON'T DO IT!!!
This is a Social Engineering scam that is currently compromising twitter accounts, but how does this work? ⤵️⤵️⤵️
A very convincing individual will contact you pretending to be an employee from Forbes or another company asking to interview you and will ask for you to schedule a meeting via Calendly...
Once you go to the calendly link it actually goes to Calendly[.]fi (SCAM LINK) not Calendly[.]com, which prompts you to "Connect X Integration" to schedule a meeting...
When you go to connect you get redirected to grant the real looking scam "Calendly" all of the dangerous permissions to act on your behalf of your X account....
After they have you authenticate your account, they will create a fake site, and post tweets, with comments off, and botted stats to try and get your followers to click on the "limited 100 mint website" which leads to a wallet drainer site... This has already gotten many accounts by posting a FOMO wallet drainer link, which they also update the bio to the scam link, and continuously spam the malicious posts..
It is extremely important to note that when you get a random DM you should never connect your wallet, twitter account, or anything!!!! If you have connected your account, you need to go:
- Settings > Security & Account Access > Apps & Sessions > Connected Apps and revoke the app
We have gotten the website, app, API key, and other stuff associated to this taken down but this is another social engineering scheme we have seen be super successful and we must educate to prevent this from having a further impact on our Web3 community.