defirisk.co
rubric v1.7.0

Social-media impersonation scam spike

ether.fi's assessment for RD-F-109 — scored yellow on the v1.7.0 rubric. The evidence below is the curator's reasoning for this score.

Evidence summary #

Multiple fake ether.fi domains documented active as of Nov 2025 (claim-ether[.]fi, ethar[.]fi, etc.) running ETHFI giveaway scams that drain wallets. Persistent impersonation ecosystem active across X/Twitter, fake domains, and phishing overlays. This is a persistent low-level condition rather than an acute spike but warrants yellow given breadth of documented fake infrastructure.

Sources #

Methodology #

Detect a sharp uptick in Discord/Telegram/X accounts impersonating the protocol team or announcing fake airdrops.

See the full factor methodology and distribution across all protocols →

rubric_version v1.7.0 protocol ether-fi factor RD-F-109 score yellow collected_at 2026-04-28 13:58:46