Discord scam cover

The scam is convincing. The record does not have to be.

Impersonation works because it is boring. It looks like the account your members already trust, doing the thing that account already does, at a moment nobody is reading carefully.

How it actually arrives

The scam is a helpful stranger.

It rarely looks like an attack. It looks like support answering a question, an announcement arriving slightly early, or a familiar name offering to sort something out in a direct message. The whole technique is to be unremarkable.

How do scams usually reach a Discord server?

Through the ordinary front door, in the ordinary way. An account joins, waits, and then borrows the appearance of someone your members already trust. The three familiar shapes are the moderator who never messages first suddenly messaging first, an announcement that arrives in the wrong place, and a support conversation that moves somewhere private.

Communities holding anything of value get all three, repeatedly, and the reason they keep working is not that people are careless. It is that being suspicious of every plausible message is not a way anybody can spend their day. The load has to sit somewhere other than on each member's individual attention.

What SwarmUp does with it

Signals, not verdicts.

Patch surfaces scam and impersonation signals. It does not conclude that somebody is a scammer, because that is a judgement about a person and this product does not let software make those alone.

Who decides whether a suspected scammer is removed?

A person does, for anything permanent. The signal is raised, the low-risk deterministic response runs if you configured one, and the decision that would follow somebody around goes on the incident queue with an owner. That is slower than an automatic ban and it is slower on purpose.

The cost of getting impersonation wrong runs in both directions. Miss it and a member loses something. Act on it automatically and you have removed a real member on a pattern match, on a platform where their reputation and their history live. The second mistake is the one that is hardest to walk back, so it is the one that waits.

After the message is gone

The evidence outlives the post.

Deleting a scam message protects the next member who would have read it. It also destroys the thing you would want to look at when the same approach turns up again next month under a different name.

What is kept when a scam post is removed?

The action and everything attached to it:

  • the community
  • the sender
  • what detected it
  • a confidence value
  • the evidence
  • the action taken
  • who owned it

Appeals and undo are retained, and reversals are recorded. Impersonation is the category where wrongly flagged members are most likely, and a member who was cleared deserves a record showing they were cleared, rather than a flag that quietly stops being mentioned.

The same names turn up twice

One workspace, both platforms.

An impersonation campaign against a project rarely bothers to pick a platform. The same handles, the same phrasing and the same approach arrive in the Discord and the Telegram group, often within hours.

Can one policy cover impersonation on Discord and Telegram?

Yes. Both are operated from the same workspace on one Community Blueprint, so a pattern your team has already decided about is not rediscovered from scratch on the second platform. Each platform and channel keeps its own permissions, so shared policy does not flatten the differences between the two communities.

The alternative most projects are running is two tools that have never heard of each other and a moderator carrying the connection between them personally. That works exactly as well as that person's memory and working hours, which is to say it works until it matters.

Where the automation stops

What the AI is not allowed to do.

The reason to trust a moderation product is not how clever it is. It is what it is prevented from doing without you.

  • AI cannot ban a member on its own.
  • AI cannot apply a permanent sanction on its own.
  • AI cannot publish a change to your policy.
  • Deterministic low-risk rules act automatically. Everything above that line waits for a person.
  • Every action is reversible, and the reversal is recorded too.
  • Provider identities are stored as one-way pseudonyms, not as raw platform accounts.

Straight answers

What people want to know first.

What is a Discord anti-scam bot?

A Discord anti-scam bot looks for the patterns scams arrive in and raises them for moderation. SwarmUp surfaces scam and impersonation signals inside the same workspace and the same record as the rest of your moderation, so what was flagged and what was done about it sit together.

Can a bot detect somebody impersonating a moderator?

It can surface the signal. Impersonation works by resembling a trusted account closely enough to pass a glance, which is a pattern software can raise and a person is far better at confirming. SwarmUp raises it; who acts, and how permanently, is governed by the limits you set.

Will it remove a suspected scammer automatically?

Not permanently. AI cannot ban a member on its own and cannot apply a permanent sanction on its own. Deterministic low-risk rules act automatically, and a judgement about whether an account is impersonating somebody sits above that line, where it waits for a person.

What happens to the evidence after a scam post is deleted?

It stays in the record. The action carries what detected it, the evidence, the action taken and who owned it, so the case survives the message being removed. Deleting the post is what protects the community; keeping the evidence is what lets you act on the pattern later.

Does SwarmUp store the accounts it flags?

Provider identities are stored as one-way pseudonyms rather than as raw platform accounts. A flagged account stays reviewable and comparable across incidents without the workspace holding a copy of your members' platform identities, which is a liability nobody needs to be carrying.

Can it cover impersonation across Discord and Telegram?

Yes. Both communities run from one workspace on one Community Blueprint, so an account pattern you acted on in one place is not unknown in the other. Impersonation campaigns rarely stop at one platform, and neither should the record of what you did about them.

Where we are today

SwarmUp is not open to the public yet. Moderation is the core of the product and it runs today. Engagement and rewards are still in testing. Plans and prices are final, and nothing is charged before the workspace opens.

One email, when it opens

We will not waste the one email.

We are not naming a launch date until we can hold it. What you get for an address is a single message the day the workspace opens, and the same plain account of where the product stands on that day.