Fake MrBeast Giveaways Are Taking Over Discord And Threads
MrBeast's popularity has become a powerful tool for cybercriminals, with scammers increasingly using his name and image to lure victims into cryptocurrency fraud across Discord and Threads.
Rather than relying on fake profiles, attackers are taking over genuine Discord accounts and using the trust built between friends to spread convincing scam messages.
Because the messages come from familiar contacts, many recipients are far more likely to believe they are genuine.
In many cases, account owners remain unaware that their profiles have been hijacked until friends begin asking about suspicious links or promotions sent from their account.
Why Hackers Prefer Hijacked Discord Accounts
Creating brand-new accounts often attracts attention from automated security systems.
Instead, attackers compromise long-established Discord profiles that already have trusted friend lists, verified server memberships and years of activity.
Once inside, automated tools rapidly send scam messages to everyone in the victim's contacts and across multiple Discord servers before either the account owner or Discord can react.
Security researchers have linked these campaigns to fake cryptocurrency giveaways, investment schemes, online casinos and phishing websites.
According to RaidProtect, tens of thousands of compromised Discord accounts may already have been involved in large-scale scam operations during 2026.
Security researchers said,
"The number of hacked accounts identified has doubled in a month, and the volume of deleted images now exceeds 2.3 million. The unique image catalog is growing too (+72%): this mainly signals that new visual clusters are appearing."
Why MrBeast Keeps Appearing In These Scams
Attackers deliberately choose MrBeast because he is one of the internet's most recognisable creators, particularly among children and teenagers.
His reputation makes fake promotions appear more believable, increasing the chances that users will click suspicious links or follow instructions without questioning them.
Some campaigns also feature convincing graphics designed to imitate posts from MrBeast, Elon Musk and other high-profile personalities to further strengthen the illusion that the offers are legitimate.
How Victims Get Tricked Into Giving Away Their Accounts
Many account takeovers begin when users download unofficial mods, cracked software, cheating tools or malicious browser extensions.
Others fall victim to phishing websites that steal login details or authenticated sessions.
In some cases, criminals gain access to an already active Discord session, allowing them to control the account without immediately logging the real owner out.
After gaining access, the compromised account automatically begins sending messages claiming that users have won prizes or free cryptocurrency.
Common messages include "MrBeast is giving away $2,500," "Claim your reward," "You've been selected," and invitations to join online casinos in exchange for free credits.
Anyone who follows these instructions may be persuaded to download malware, connect a cryptocurrency wallet, scan a QR code, authorise a malicious Discord OAuth application or enter their credentials into a fake website.
Once their account is compromised, the same scam is sent to their own contacts, allowing the campaign to spread quickly.
Threads Is Also Being Flooded With Fake MrBeast Posts
The same tactic is now appearing across Threads, where popular discussions are increasingly attracting strange replies featuring blurry images, meaningless text and fabricated headlines about MrBeast.
According to Engadget's investigation, these replies form part of a much larger cryptocurrency scam network connected to more than 10,000 malicious "crypto casino" websites.
Infoblox staff security researcher Zach Edwards found that the operation relies on promises of giveaways, bonuses and "free money" to encourage people to visit fraudulent websites and register for fake offers.
Instead of placing website links directly into replies, scammers often hide domain names inside blurry screenshots designed to resemble articles from recognised publications including The Times and CNN.
Mark Beare, head of consumer at Malwarebytes, shared that the approach appears to have been designed specifically for Threads, where Meta has said replies generate around half of all views.
To Edwards, the constant changes are intentional.
He said,
"This network is a monster for A/B testing. These threat actors have potentially figured out that their domains are being picked up too quickly when they embed them in the post, so they've tried this weird process where you bury the domain and you make the person sort of feel like it's a scavenger hunt."
Protecting Your Discord Account Before It's Too Late
Anyone who believes their Discord account has been compromised should change their password immediately using a trusted, malware-free device.
Securing the linked email account is equally important, as attackers who retain email access may simply regain control of Discord after the password is changed.
Users should also enable multi-factor authentication, remove any unfamiliar authorised Discord applications, scan their devices for malware and warn friends not to interact with suspicious messages that may have been sent from the compromised account.
Remaining cautious around unexpected giveaways, cryptocurrency promotions and offers promoted by celebrities can also reduce the risk of becoming the next victim.
Trust Has Become The Real Target
Coinlive believes the most valuable thing cybercriminals are stealing is no longer passwords but trust itself.
As scammers increasingly hide behind familiar faces, well-known creators and genuine accounts, every unexpected giveaway or cryptocurrency offer deserves careful scrutiny before a single click.
Taking a few extra seconds to verify a message may be the simplest way to stop an attack before it spreads to everyone else.