Skip to content

soldrift-devbeast5775-warning/solana-scam-osint-report

Repository files navigation

Soldrift / devbeast5775 OSINT Security Warning Index

Soldrift / devbeast5775 scam warning, Telegram @devbeast5775 Solana drain warning, Solana private-key exposure risk, phishing-tool warning, wallet-drainer risk, malicious backdoor bot warning, GitHub developer scam OSINT report, HFT bot risk, sniper bot risk, arbitrage bot risk, Raydium bot risk, Dexscreener manipulation-tool warning, KuCoin-linked Solscan lead, and public Web3 security evidence index.

Official public report hub:

https://soldrift-devbeast5775-warning.github.io/solana-scam-osint-report/


Fast Search Index

This repository is built as a public Web3 security warning index for users searching for the following risk terms:

  • Soldrift scam warning
  • Soldrift OSINT report
  • Soldrift Solana tool warning
  • Soldrift GitHub developer scam
  • devbeast5775 scam warning
  • devbeast5775 OSINT report
  • devbeast5775 Telegram warning
  • Telegram @devbeast5775 warning
  • t.me/devbeast5775 Solana warning
  • Solana phishing tool warning
  • Solana wallet drainer warning
  • Solana private key scam warning
  • Solana private-key exposure
  • Solana drain tool risk
  • Solana malicious trading bot warning
  • Solana HFT bot risk
  • Solana sniper bot scam warning
  • Solana arbitrage bot scam warning
  • Solana MEV bot warning
  • Solana bundler bot risk
  • Jito bundler scam warning
  • Yellowstone gRPC bot risk
  • Raydium volume bot warning
  • Raydium sniper bot risk
  • Dexscreener trending bot warning
  • Dexscreener volume bot risk
  • Pump.fun launch bot risk
  • PumpSwap trading bot risk
  • Meteora bot risk
  • Orca trading bot risk
  • Jupiter arbitrage bot risk
  • KuCoin API arbitrage bot warning
  • KuCoin-linked Solscan wallet lead
  • GitHub malicious repository warning
  • GitHub developer access scam
  • VPS root access developer scam
  • SSH key backdoor risk
  • .env private key leak risk
  • Web3 wallet automation scam
  • crypto trading bot backdoor warning

Report Pages

Main report hub

https://soldrift-devbeast5775-warning.github.io/solana-scam-osint-report/

The main page is a broad public OSINT security warning hub about Soldrift, Telegram @devbeast5775, related GitHub traces, Solana wallet/private-key exposure, malicious bot risk, and user-reported scam/drain/phishing-tool concerns.

Soldrift / devbeast5775 scam warning

https://soldrift-devbeast5775-warning.github.io/solana-scam-osint-report/soldrift-devbeast5775-scam-warning.html

Focused page for searches involving Soldrift, devbeast5775, scam warning, Solana tool risk, developer-access risk, wallet exposure, and public OSINT identifiers.

Telegram @devbeast5775 Solana drain warning

https://soldrift-devbeast5775-warning.github.io/solana-scam-osint-report/telegram-devbeast5775-solana-drain-warning.html

Focused page for searches involving Telegram @devbeast5775, t.me/devbeast5775, Solana drain warning, phishing-tool risk, wallet-drainer risk, and private-key exposure.

Solana private-key / HFT bot risk

https://soldrift-devbeast5775-warning.github.io/solana-scam-osint-report/solana-private-key-hft-bot-risk.html

Focused page for searches involving Solana private key risk, .env wallet exposure, HFT bot scams, sniper bots, arbitrage bots, bundlers, gRPC tokens, Jito, Raydium, Dexscreener, and KuCoin API risk.

GitHub developer scam OSINT report

https://soldrift-devbeast5775-warning.github.io/solana-scam-osint-report/github-developer-scam-osint-report.html

Focused page for searches involving GitHub developer scam, malicious repository warning, backdoor code, VPS access risk, SSH access risk, repository deletion, and public developer-trace OSINT.

Korean search warning page

https://soldrift-devbeast5775-warning.github.io/solana-scam-osint-report/ko-soldrift-devbeast5775-scam-warning.html

Korean-language search page for users searching terms such as 솔드리프트, devbeast5775, 솔라나 스캠, 솔라나 드레인, 피싱툴, 지갑 드레이너, 프라이빗키 노출, 악성 봇, 백도어, and 깃허브 개발자 사기.


Primary Public Identifiers

  • Main reported identifier: Soldrift
  • Primary Telegram handle: @devbeast5775
  • Telegram URL identifier: t.me/devbeast5775
  • Related public handle traces: whistledev411, @whistle, @soldrift
  • Reported Solscan wallet lead: EfwJn8cXCYhcGrsavxWSDbUFHPrCK9gvdCr6AVywFBPg
  • Observed exchange-linked label in submitted material: KuCoin 2
  • Tracking period: May 2026 onward
  • Time standard: UTC

This repository records public and user-submitted OSINT leads. It does not by itself prove wallet ownership, nationality, criminal intent, profit source, malware authorship, exchange account ownership, or legal liability without independent verification.


Public Safety Purpose

This repository exists to warn Solana and Web3 users before they run unknown trading tools, wallet dashboards, sniper bots, HFT bots, arbitrage bots, bundlers, casino bots, copy-trading bots, Telegram bots, compiled binaries, private repositories, or VPS-deployed systems that request sensitive access.

High-risk access includes:

  • private keys
  • seed phrases
  • funded wallet files
  • wallet export functions
  • .env files
  • RPC keys
  • Helius API keys
  • Yellowstone gRPC tokens
  • Jito bundle access
  • KuCoin API keys
  • exchange API keys
  • GitHub repository access
  • GitHub tokens
  • SSH keys
  • VPS root access
  • PM2/systemd background service access
  • Telegram bot tokens
  • webhook URLs
  • Discord webhook URLs

Any unknown Solana tool that asks for a private key, seed phrase, wallet vault, export permission, RPC key, gRPC token, exchange API key, or server administrator access should be treated as unsafe until independently audited.


Critical Solana Wallet Warning

Do not paste valuable wallet private keys into unknown Solana tools.

Do not run unknown Telegram-distributed Solana trading bots on a machine that contains funded wallets.

Do not give unknown developers root access to a VPS that stores .env, wallet files, API keys, GitHub tokens, SSH keys, or trading infrastructure.

Do not assume that a GitHub repository is safe because it has many repositories, followers, forks, stars, copied README files, or professional-looking documentation.

Do not assume that a Telegram developer, Solana bot seller, sniper bot seller, HFT bot seller, arbitrage bot seller, or volume bot seller is safe without independent audit and operational isolation.


Risk Categories Covered

This report index covers user-reported and public OSINT concerns involving:

Solana wallet and private-key risk

  • Solana private-key exposure
  • Solana seed phrase exposure
  • .env private key leakage
  • wallet export abuse
  • local wallet vault compromise
  • hot-wallet drain risk
  • funding-wallet exposure
  • main-funder wallet exposure
  • automated withdrawal risk
  • malicious sweep logic
  • hidden wallet transfer logic

Bot and trading-tool risk

  • Solana HFT bot risk
  • Solana sniper bot risk
  • Solana arbitrage bot risk
  • Solana MEV bot risk
  • Jito bundler risk
  • Yellowstone gRPC bot risk
  • Raydium volume bot risk
  • Dexscreener trending bot risk
  • Pump.fun launch bot risk
  • PumpSwap trading bot risk
  • Meteora bot risk
  • Orca trading bot risk
  • Jupiter arbitrage bot risk
  • KuCoin API arbitrage bot risk

Developer and infrastructure risk

  • GitHub developer scam warning
  • malicious repository risk
  • backdoor code risk
  • hidden webhook risk
  • Discord webhook exfiltration risk
  • Telegram bot exfiltration risk
  • base64 obfuscation risk
  • dynamic execution risk
  • eval / new Function risk
  • remote logging risk
  • VPS root access abuse
  • SSH key persistence
  • PM2 persistence
  • crontab persistence
  • systemd persistence
  • repository deletion or renaming after exposure

GitHub Repository Warning

A GitHub profile, repository list, or polished README is not a security audit.

Users should be cautious when a repository or developer account shows any of the following patterns:

  • private-key handling
  • seed phrase handling
  • wallet export logic
  • encrypted packages without audit
  • compiled binaries without source review
  • obfuscated JavaScript or TypeScript
  • hidden fetch, axios, XMLHttpRequest, sendBeacon, WebSocket, or EventSource calls
  • webhook URLs
  • unknown Telegram or Discord integrations
  • base64 blobs
  • dynamic code execution
  • remote update logic
  • credential logging
  • wallet sweep functions
  • background services installed on VPS
  • deleted repositories
  • renamed repositories
  • changed Telegram handles
  • copied or recycled README text
  • repeated new accounts selling similar tools

Immediate Actions if You Interacted With a Related Tool

If you used, tested, purchased, deployed, cloned, or ran any tool connected to the identifiers in this report, consider the following actions:

  1. Move funds to fresh wallets.
  2. Retire any private key pasted into a tool, dashboard, .env file, Telegram bot, VPS, or developer-provided software.
  3. Rotate RPC keys and Helius keys.
  4. Rotate gRPC tokens.
  5. Rotate exchange API keys.
  6. Rotate GitHub tokens.
  7. Change VPS root password.
  8. Remove unknown SSH keys.
  9. Inspect authorized_keys.
  10. Inspect crontab.
  11. Inspect systemd services.
  12. Inspect PM2 processes.
  13. Inspect startup scripts.
  14. Search source code for outbound requests, webhooks, private-key export logic, remote logging, and obfuscated code.
  15. Preserve evidence with UTC timestamps.
  16. Report suspicious repositories and accounts through official platform channels.

Code Review Search Terms

When reviewing a suspicious Solana or Web3 bot project, search the codebase for terms such as:

PRIVATE_KEY
SECRET_KEY
seed
mnemonic
wallet
export
withdraw
sweep
transfer
fetch(
axios
XMLHttpRequest
sendBeacon
WebSocket
EventSource
webhook
discord
telegram
eval(
new Function
atob
btoa
base64
process.env
authorized_keys
crontab
systemd
pm2

These terms do not automatically prove malicious behavior, but they are useful indicators for security review.


Evidence Preservation Guidance

Preserve only lawful public or personally obtained evidence:

  • public GitHub URLs
  • public repository names
  • public README text
  • public profile screenshots
  • Telegram handles
  • public Telegram profile screenshots
  • Solscan wallet links
  • transaction hashes
  • public wallet addresses
  • exchange-linked labels visible on explorers
  • archive snapshots
  • UTC timestamps
  • file hashes
  • commit timestamps
  • release names
  • package names
  • clone URLs
  • deployment URLs

Do not publish private keys, seed phrases, unrelated personal data, private phone numbers, private addresses, unrelated identities, or unsupported personal claims.


Korean / 한국어 검색 색인

이 저장소는 다음 한국어 검색어에 대응하는 공개 보안 경고 색인입니다.

  • 솔드리프트 스캠 경고
  • Soldrift 사기 경고
  • devbeast5775 스캠
  • devbeast5775 사기
  • devbeast5775 텔레그램
  • 텔레그램 devbeast5775
  • 솔라나 스캠 경고
  • 솔라나 드레인 경고
  • 솔라나 지갑 드레이너
  • 솔라나 피싱툴
  • 솔라나 프라이빗키 노출
  • 솔라나 시드구문 노출
  • 솔라나 HFT 봇 사기
  • 솔라나 스나이퍼 봇 위험
  • 솔라나 차익거래 봇 위험
  • Raydium 볼륨 봇 위험
  • Dexscreener 트렌딩 봇 위험
  • Pump.fun 봇 위험
  • PumpSwap 봇 위험
  • GitHub 개발자 사기 경고
  • 깃허브 백도어 코드 위험
  • VPS 루트 권한 사기
  • SSH 키 백도어
  • 악성 봇 배포자 경고
  • 웹3 보안 경고
  • 코인 개발자 사기 경고

이 저장소는 특정 국적, 민족, 지역, 신분을 단정하기 위한 목적이 아닙니다. 공개 OSINT 단서와 사용자 신고를 기반으로 한 Web3 보안 경고 및 피해 예방 목적의 색인입니다.


Scope and Limitations

This repository is a public safety and OSINT warning index.

It is based on public identifiers, user-reported material, public screenshots, public blockchain leads, and public repository/security observations.

It does not independently establish:

  • legal guilt
  • criminal conviction
  • malware authorship
  • wallet ownership
  • exchange account ownership
  • nationality
  • physical identity
  • source of funds
  • intent
  • full attribution

Any correction request should include verifiable public evidence.


Correction Policy

If any information is inaccurate, incomplete, outdated, or misattributed, submit a correction request with evidence.

Useful correction evidence includes:

  • public GitHub links
  • public Telegram evidence
  • public blockchain explorer links
  • UTC timestamped screenshots
  • archive links
  • repository ownership clarification
  • wallet ownership clarification
  • transaction clarification
  • public audit results
  • security review notes

Recommended Search Queries

Users, researchers, and victims may search:

Soldrift devbeast5775 scam
Soldrift devbeast5775 OSINT
Soldrift Telegram devbeast5775
Telegram @devbeast5775 Solana
t.me/devbeast5775 warning
devbeast5775 Solana drain
devbeast5775 wallet drainer
devbeast5775 phishing tool
Soldrift Solana private key
Soldrift GitHub scam
Soldrift malicious bot
Solana HFT bot scam
Solana sniper bot private key
Solana arbitrage bot API scam
Raydium volume bot scam
Dexscreener trending bot scam
KuCoin API Solana arbitrage bot scam
GitHub developer VPS root access scam
Web3 developer backdoor warning

License / Notice

This repository is published for public safety, security awareness, lawful OSINT preservation, and Solana/Web3 ecosystem risk documentation.

Do not use this repository to harass, dox, threaten, impersonate, hack, bypass access controls, or publish private personal information.

The purpose is to warn users about high-risk wallet tools, phishing systems, drain patterns, malicious backdoor risks, unsafe bot distribution patterns, and developer-access threats.

About

Public OSINT security warning report about Soldrift, Telegram @devbeast5775, Solana scam risk, wallet/private-key exposure, phishing-tool risk, malicious backdoor bot warnings, and GitHub developer access threats.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Contributors

Languages