Input Output Group warned Cardano users on Sept. 18 to stop interacting with its official YouTube channel after an apparent account takeover was used to broadcast a fraudulent cryptocurrency giveaway featuring what appeared to be a manipulated version of Cardano founder Charles Hoskinson.
The compromised channel aired a livestream presented as a Project Catalyst event and directed viewers toward a QR code while promising to “double” their cryptocurrency.
IOG responded through its official X account, telling users to avoid the YouTube channel until further notice and warning them not to click links, send funds or provide personal information through content appearing there.
Hoskinson separately said the IOG YouTube account appeared to have been compromised and that the team was working with YouTube to remove the content and reset credentials.
The suspicious livestream remained available for close to two hours during early reporting on the incident.
IOG has not publicly explained how the attackers obtained control of the channel, whether multifactor authentication was bypassed or whether any other corporate accounts or internal systems were accessed.
There is also no verified victim-loss figure. No wallet address tied conclusively to the Sept. 18 scam has been publicly disclosed by IOG, and no major blockchain-forensics company has published a confirmed transaction trail showing how much cryptocurrency, if any, viewers sent.
The incident should therefore be separated from a compromise of Cardano itself. There is currently no evidence that the Cardano blockchain, ADA protocol infrastructure or user wallets were breached merely because attackers gained control of IOG’s YouTube presence.
That distinction resembles other recent crypto security incidents where identifying exactly which infrastructure layer was compromised was essential to understanding the actual risk to customer assets.
Scammers Used a Familiar Cardano Giveaway Formula
The technique itself is not new.
Cardano’s official scam guidance has warned for years about fake livestreams involving Hoskinson or other recognizable figures that tell users to send ADA with the promise of receiving a larger amount back.
Legitimate giveaways do not require participants to send cryptocurrency first, Cardano’s guidance says.
What makes the Sept. 18 attack more dangerous is that the fraudulent broadcast appeared through a genuine IOG communication channel rather than a newly created impersonation account.
The stream also borrowed Project Catalyst branding. Catalyst is Cardano’s genuine community funding initiative, giving the fraudulent video another layer of apparent legitimacy for viewers familiar with the ecosystem.
The video has been widely described as AI-manipulated, but no technical forensic analysis has yet established exactly how it was created. The attackers could have used edited historical footage, synthetic audio, face manipulation or a combination of techniques.
The distinction matters technically but probably matters much less to a potential victim. Modern AI tools are making it increasingly difficult to rely on voice, facial appearance or professional production quality as evidence that a crypto message is genuine.
The crypto industry has seen the same problem move across communication channels. During the recent Brevo security breach, attackers gained access to legitimate marketing infrastructure used by cryptocurrency companies, allowing fraudulent messages to arrive through channels customers had reason to recognize.
Trezor customers were subsequently targeted through an email campaign that attempted to collect wallet backups, with a malicious file designed to forward entered recovery information to attackers. The incident showed how phishing infrastructure becomes much more convincing once a trusted communication channel has already been compromised.
Cardano Has Faced an Official-Account Compromise Before
The Sept. 18 incident is not the first time attackers have obtained control of an official Cardano-related social account.
In December 2024, the Cardano Foundation said its official X account had suffered unauthorized access. Attackers used the account to publish false information, including claims involving regulatory action against the organization.
The Foundation eventually regained control and said no other Cardano Foundation systems had been affected.
That earlier case and the IOG YouTube takeover illustrate a broader problem for crypto organizations: security around the blockchain itself can remain intact while attackers target the trusted communication infrastructure surrounding it.
This distinction has become increasingly important as attacks move away from direct protocol exploitation and toward credentials, employee devices, communications platforms and third-party providers.
A recent ApeX-related incident, for example, involved a key located on a former employee’s device, prompting INDODAX to freeze APEX transfers while the ecosystem investigated the implications.
In each case, the security boundary extends beyond blockchain code.
An Official Channel Is No Longer Proof That a Crypto Message Is Genuine
The most important part of this incident is not the giveaway format.
Everyone who has spent enough time in crypto has seen the basic scam: send one coin and supposedly receive two back.
The dangerous change is where the message came from.
Traditional anti-phishing advice tells users to check whether an account is official, look for the correct username and avoid obvious impersonators.
That advice becomes much less useful when the attacker controls the real account.
In this case, a viewer could open IOG’s established YouTube channel, see Cardano branding, watch what appears to be Charles Hoskinson and encounter a stream presented as a genuine Project Catalyst event.
Almost every superficial trust signal is present.
The remaining defense is behavioral rather than visual: legitimate crypto organizations do not need users to send assets first in order to receive a giveaway.
That is a much stronger rule than trying to decide whether someone’s face looks AI-generated.
AI will make this problem worse because the quality gap between authentic and fraudulent content is shrinking rapidly. A scammer no longer needs badly synchronized archived footage or an obviously fake voice. The cost of creating plausible executive video and audio keeps falling.
At the same time, control of a trusted distribution channel gives the scam something AI alone cannot manufacture: an existing audience.
That combination is powerful.
A malicious video published from an unknown YouTube account has to persuade viewers that the account is real. A malicious video published through IOG’s actual channel begins with that trust already established.
This is similar to why compromised email providers are so dangerous. The recent Brevo incident mattered not just because attackers created phishing content, but because they could distribute it through infrastructure connected to legitimate companies.
Crypto also makes the consequences unusually difficult to reverse. If a user sends ADA after scanning the QR code, there is generally no card network, bank or payment processor capable of canceling the blockchain transaction afterward. Other recent cases involving unauthorized crypto transfers show how quickly the discussion shifts from preventing a transaction to tracing assets once they have already moved.
The next important disclosures from IOG should therefore answer two very different questions.
The first is technical: how did attackers obtain administrative access to the YouTube channel, and have all credentials and connected accounts now been secured?
The second is financial: did anyone actually send funds to addresses promoted during the livestream?
If IOG or blockchain investigators identify the scam addresses, the public ledger should make at least part of that answer measurable.
Until then, claims about victim losses would be speculation.
The incident is nevertheless useful as a warning about where crypto security is moving. Securing wallets, smart contracts and private keys is no longer enough when attackers can compromise the communication layer that tells users what to do with those assets.
For Cardano users, the safest takeaway from Sept. 18 is unusually simple: an official logo, an official account and even an apparently familiar founder on video are no longer sufficient authentication.
When the instruction is “send crypto and receive more back,” the transaction itself is the warning sign.
Shane Neagle is a financial markets analyst and digital assets journalist specializing in cryptocurrencies, memecoins, prediction markets, and blockchain-based financial systems. His work focuses on market structure, incentive design, liquidity dynamics, and how speculative behavior emerges across decentralized platforms.
He closely covers emerging crypto narratives, including memecoin ecosystems, on-chain activity, and the role of prediction markets in pricing political, economic, and technological outcomes. His analysis examines how capital flows, trader psychology, and platform design interact to create rapid market cycles across Web3 environments.
Alongside digital assets, Shane follows broader fintech and online trading developments, particularly where traditional financial infrastructure intersects with blockchain technology. His research-driven approach emphasizes understanding why markets behave the way they do, rather than short-term price movements, helping readers navigate fast-evolving crypto and speculative markets with clearer context.

