Reading: Mrbeast reply spam on Threads is tied to a massive crypto scam

Mrbeast reply spam on Threads is tied to a massive crypto scam

Published
3 min read
Advertisement

Threads users are being hit with a wave of Mr Beast reply spam that is doing more than clogging comment threads. Engadget reported that the posts are tied to a massive crypto scam network linked to more than 10,000 malicious websites, turning a familiar celebrity bait-and-switch into a broader fraud campaign.

The reason people are seeing it now is simple: the spam works inside Threads’ own visibility system. Meta has said half of the views on Threads come from replies, and some of the spam accounts have already pulled in hundreds of thousands of views over the last 30 days. That makes the account behavior hard to ignore even when the posts themselves look broken or random.

Engadget identified dozens of accounts posting the Mr Beast replies, and those accounts were pointing users toward websites Zach Edwards linked to the same network. Edwards said the operation runs more than 10,000 malicious crypto casino websites, and he described the network as a monster for A/B testing. In practice, that means the scammers can keep changing the bait, watching what gets attention, and pushing the version that lasts the longest.

- Advertisement -

The pattern is strange on purpose. The posts often pair a low-quality screenshot of The Times with a fake Mr Beast story, then add a second image such as a bouquet of flowers with an iPhone. The text can include a nonsensical phrase, and the screenshot usually claims that Mr Beast is starting a new project or giveaway and will hand out money if users visit a sketchy site. Mark Beare said the posts do not contain obvious links to the scams they promote, and he said the wording does not read like standard get-rich-quick crypto bait.

That odd setup is part of the defense. Edwards said the threat actors may have learned that their domains are being picked up too quickly when they embed them directly in the post, so they bury the URL and make the user work for it like a scavenger hunt. He said that when the link is obscure and not prominent, AI detection systems may miss it. Beare put the strategy more plainly: they are trying to feed an algorithm, and each platform has a different algorithm.

Beare also said he was not familiar with this particular network of crypto scammers, but he was not surprised by their fixation on Mr Beast. The name works as bait because it is recognizable, and the reply format helps spread it. What remains unclear is how much of the network Meta has already tried to remove, because the spam is still active, still reaching large audiences, and still adapting faster than a simple takedown notice would suggest.

Advertisement
Share This Article