Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
A Network of 10,000 Fake Crypto Sites Is Running Spam Across Threads, Using Mr Beast as Bait

The Scam You've Probably Already Scrolled Past
If you use Threads with any regularity, you've seen it: a reply to a popular post with a random phrase like "pencil shavings curl like thoughts" and a low-resolution screenshot of what looks like The Times of London. The screenshot always features YouTuber MrBeast. There's usually a second image, often a bouquet of flowers with an iPhone sitting nearby.
According to analysis by Zach Edwards, a staff security researcher at Infoblox, every one of those accounts is promoting websites tied to a single network running more than 10,000 malicious crypto casino sites. Engadget identified dozens of Threads accounts posting this specific format, some accumulating hundreds of thousands of views over the past 30 days. Edwards confirmed all of them link back to the same network.
How It Actually Works
The scam doesn't look like a typical scam. There's no obvious link in the post. The images appear random. But zoom in on those low-res MrBeast photos and you'll find a fake news story embedded in the screenshot, a fabricated headline claiming he's launching a "project" or "promotion" and directing readers to a sketchy website to claim money.
The URLs are buried. Deliberately so.
Edwards told Engadget the network appears to have figured out that embedding domains directly in posts gets them flagged and removed too quickly. "These threat actors have potentially figured out that their domains are being picked up too quickly when they embed them in the post," he said, "so they've tried this weird process where you bury the domain and you make the person sort of feel like it's a scavenger hunt. If you're promoting just an image and there's an obscure URL that's not even super prominent, a lot of these AI [detection] systems may miss it."
Mark Beare, head of consumer at scam detection platform Malwarebytes, confirmed the Threads execution is unusual compared to typical crypto spam. Most of these schemes lean hard on get-rich-quick language. This one doesn't.
Gaming Threads' Own Algorithm
The network also appears to have reverse-engineered something specific about how Threads distributes content. Meta has publicly stated that roughly half of all views on Threads come from replies. The spam accounts exploit that directly: they reply to high-traffic posts to inherit visibility, then let the weird images and phrases do the work of staying under the moderation radar.
Edwards described the operation as a "monster for A/B testing" — meaning the sheer volume of accounts lets the operators run constant experiments to see which image combinations, phrase structures, and posting patterns maximize reach while avoiding takedown.
This is not a teenager running a crypto side hustle. The infrastructure (10,000-plus websites, coordinated account behavior, systematic evasion of AI moderation) points to a professional operation.
The Strongest Concern Worth Taking Seriously
Critics of large social platforms have a legitimate point here. Meta profits from engagement, and spam generates engagement. A company with Meta's resources and AI capabilities has the tools to catch this kind of coordinated inauthentic behavior. The fact that accounts in this network accumulated hundreds of thousands of views over 30 days raises a fair question about whether moderation enforcement is actually a priority or just a PR talking point.
Platforms have routinely been reactive on scam enforcement rather than proactive, and the economic incentive to let borderline content run until it's publicly embarrassing is real.
This network specifically engineered its tactics to defeat automated detection: burying URLs in images, using nonsensical text that doesn't pattern-match to known scam language, and relying on a visual format that's harder for AI systems to parse than plain text. The evasion is deliberate and technically creative. That doesn't excuse slow enforcement, but it does mean the challenge is more than a simple resource allocation problem.
What Hasn't Been Answered
As of July 2, 2026, Meta has not publicly responded to the Infoblox findings or Engadget's reporting on the scope of the network. No takedown timeline has been announced. The accounts Engadget identified were still posting in the format described.
Edwards' research maps the network's website infrastructure, but the identity of whoever is running it — individual, group, or organization — has not been established publicly, and no law enforcement action has been announced.
The open question is whether Meta will treat this as a one-off cleanup or address the underlying algorithmic incentive that makes replies to popular posts the easiest free distribution mechanism on the platform and the obvious exploit for the next network that comes along.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.