Replies: 2 comments 1 reply
-
|
This is the ongoing “Solana Grants / Gitcoin-style” mass-mention phishing scam that has been hitting GitHub hard again. The account ToothWandModulator (created March 8, 2026 — literally 8 days old) is following the exact playbook:
This is pure spam + phishing. They’re hoping someone clicks a link and connects a wallet or falls for a fake grant payout. The heuristics you listed are 100% correct and textbook spam:
You did the right thing reporting the repo. The fact that the “Report discussion” button is missing is a known UI glitch on some discussion pages (especially when the repo is already under review). Quick things you (and anyone pinged) can do right now:
Why isn’t this being auto-flagged yet?GitHub does have spam detection for new accounts + mass mentions + crypto keywords, but these scammers rotate accounts extremely fast and tweak the wording. The volume is massive (thousands of similar repos every week). GitHub has been suspending waves of them, but it’s an arms race. Good news: when I just checked the discussion page it failed to load (“Uh oh! There was an error”), which usually means GitHub is already acting on reports and the content is being taken down. Direct request to GitHub Staff / Moderation team (please escalate this):
To everyone reading this:
This should not still be happening in 2026. Thanks for calling it out, YoshiRulz — and thanks to everyone who’s already reported. GitHub team, let’s get these accounts wiped out quickly. |
Beta Was this translation helpful? Give feedback.
-
|
Same for the user @ApprenticeBattle; reported them. |
Beta Was this translation helpful? Give feedback.
Uh oh!
There was an error while loading. Please reload this page.
-
Select Topic Area
Bug
Body
The repo in question: https://github.com/ToothWandModulator/SolanaGrants-6059162/discussions

I can't report the discussion I was pinged in, because the button does not exist.
I was, however, able to report the repo.
But I have to ask: How is this still a problem? Why wasn't it automatically flagged for moderation and the pings suppressed?

I don't need a million-dollar AI overseer to tell you that this is suspicious activity, it's simple heuristics.
Inexcusable.
Beta Was this translation helpful? Give feedback.
All reactions