@Cloudd (X)
https://x.com/Cloudd
✓ Verified by GACS · gacs.app/scam/cloudd-x-9450c2
Composite score from 6 signals below.
- In GACS scam database+40
- On active blacklist+30
- Critical severity+15
- 1 community report+5
- Active 108+ days+5
- Confirmed by social_scan+5
Don't get hit by this twice.
Activate your free Shield to get instant alerts when this scam — or anything like it — comes back.
Next 5 minutes — what to do right now
Most damage from this scam type happens in the first hour. Knock these out in order.
- 1Verify the exact identifier
Paste the website, wallet, phone, or social handle into the free checker. You'll see every report tied to it in seconds.
Run a free check - 2Save it to your Shield
Activating your free Shield gives you alerts if this scammer surfaces again under a new handle, domain, or wallet.
Activate my free Shield - 3Report what you saw
Even a 30-second report makes the next victim's lookup land here. Anonymous is fine.
File a report - 4Warn one person you know
The fastest way to neutralize an active scam: send this page to one friend or family member who fits the target profile.
Get the family playbook
Free · no signup · cross-referenced against 1,700+ confirmed scams.
Related scam alert hubs
Live feeds for this scam's category and region.
Check another handle, link or wallet
Paste any X/Telegram handle, website, or crypto wallet. Free, no signup, 5-second verdict.
You just helped flag a scam. Create a free GACS account to receive an alert the next time a wallet, domain, or handle matching this pattern is reported.
Create free accountGACS verdict: Do not engage
- Listed on the GACS active blacklist (multi-source confirmed).
- Severity classified as CRITICAL based on harm pattern.
- 1 independent user report on file.
- Cross-referenced against external feed: social_scan.
- Tactic category: social.
Case summary
Reviewed by handThis listing combines three separate signals into one picture. The handle sits one character from known blacklisted entities (Cloud Token, USDT Cloud Mining 2026, and an OpenPhish-listed CloudFront host). The profile bio advertises "DM for Promo" — paid promotion. And the posts push a specific altcoin, MONI on Monad, with a contract address (0x0CC9B2e2AcD7BACfF79eb7dB48F5662B622E7777) and a Telegram link (t.me/MoniOnMonad). A paid-promotion account posting a contract address is the standard delivery mechanism for a low-liquidity token launch: buyers arrive from the post, price rises on thin liquidity, and the holders who arranged the promotion sell into it. The contract address is recorded here so anyone can check the token's holder distribution and liquidity themselves before touching it.
Originally published on GACS — Global Anti-Crime & Safety. Verify the latest status of this report at https://gacs.app/scam/cloudd-x-9450c2. Browse the full public scam registry, see live scam alerts, or report a scam. © GACS · Licensed CC BY 4.0 with attribution to gacs.app.
How this one runs
- 1Operate a handle near-identical to known scam brands so search traffic mixes.
- 2Advertise paid promotion in the bio.
- 3Post a contract address plus a Telegram group for a specific low-liquidity token.
- 4Buying pressure from the post exits into existing holders.
What we verified
- Handle within one character of blacklisted entities including an OpenPhish-listed host.
- "DM for Promo" stated in the profile bio.
- Token contract address and Telegram link posted publicly.
Limits of this evidence: Posting a contract address is not itself proof of a rug pull. The finding is the combination: paid promotion, typo-squat proximity, and an unaudited low-liquidity token.
Indicators observed
- Handle is one character away from a known blacklisted scam: Cloud Token, USDT Cloud Mining 2026, OpenPhish: d2n9osbflux4k6.cloudfront.net. Typo-squatting is the #1 impersonation tactic — double-check the spelling matches the real account
- Promotion of specific altcoin 'MONI on Monad' with a contract address (0x0CC9B2e2AcD7BACfF79eb7dB48F5662B622E7777) and a Telegram link (t.me/MoniOnMonad) in Post 3. This often indicates shilling or pump-and-dump schemes
- Profile bio states 'Dm for Promo', indicating paid promotions which can be used to shill dubious projects
- Engaging in 'shill me some NFTs to buy' (Post 5) can attract scam projects to promote
- 'Professional Degenerate' in bio, while possibly a self-aware joke, often aligns with high-risk, speculative crypto activities that can lead to scams
- Use of shortened link t.co/9kBOhtpwuq in the bio, which obfuscates the destination URL and can be redirected to malicious sites
Pattern: Exchange / brand impersonation
The operator registers a handle that wraps a real brand name in an extra word — support, giveaway, recovery, airdrop, official — so it looks like a department of the company. Victims searching for help find the fake account before the real one, and the conversation moves straight to direct messages where there is no moderation and no record.
- The genuine account never bolts words like "official", "support" or "airdrop" onto its handle
- Account is far younger than the brand it claims to represent
- First move is always to take you into a private chat
- Asks for a seed phrase, a screen-share, or a "verification" transfer
Sources and method
- OpenPhish
Threat feed that listed the related CloudFront phishing host.
- SEC Investor.gov — Social media and investment fraud
Undisclosed paid promotion of a token is a documented fraud pattern.
- GACS social scanner
Our scanner reads the public profile and recent posts, scores the behavioural signals, and re-checks the account on a schedule so a listing reflects current behaviour, not a single moment.
- Primary observation
The page or profile this listing was created from.
- 1 community report
Independent submissions from people who ran into this. Reports are matched on the identifier, not the name, so renaming does not reset the count.
Checked against our live signals at listing time and re-checked whenever the identifier appears in a new report or feed update. This listing has also been reviewed by hand: the narrative above was written from the observed evidence, not generated. If you believe this listing is wrong, you can appeal it and we will re-check the evidence.
Identifiers flagged
- Websitehttps://x.com/Cloudd
- Also known asCloudd · @Cloudd
Got hit by this scam?
You're not alone. Take action now — every minute counts.
US victims — file with the FTC & FBI's IC3
Step-by-step reporting guide that walks you through both filings in under 15 minutes — what evidence to bring and how to navigate each official form.Check another website for free
Run any URL through the GACS website checker — domain age, SSL, content red flags and 137,000+ community reports in one scan.
Related scam alert hubs
Live, updating feeds tied to this scam's category and region — playbooks, red flags, and how to report.
Browse every registered scam starting with “C” in the GACS directory.
Browse scams by country
Reports from people in your region — local helplines, currency-specific tactics, and "saved from loss" stories.
How GACS compares
See how this free scam registry stacks up against the major alternatives.
Cite this page / Press kit
Journalists, researchers and educators are welcome to cite this page. Use the permalink below or copy a ready-made citation.
https://gacs.app/scam/cloudd-x-9450c2- APA
GACS. (2026). @Cloudd (X) — GACS scam report. GACS — Global Anti-Crime & Safety. Retrieved September 24, 2026, from https://gacs.app/scam/cloudd-x-9450c2
- MLA
"@Cloudd (X) — GACS scam report." GACS — Global Anti-Crime & Safety, GACS, 2026, https://gacs.app/scam/cloudd-x-9450c2. Accessed September 24, 2026.
- Chicago
GACS. "@Cloudd (X) — GACS scam report." GACS — Global Anti-Crime & Safety. Accessed September 24, 2026. https://gacs.app/scam/cloudd-x-9450c2.
- BibTeX
@misc{gacs_scam_cloudd_x_9450c2, author = {GACS}, title = {@Cloudd (X) — GACS scam report}, howpublished = {GACS — Global Anti-Crime & Safety}, year = {2026}, note = {Accessed: September 24, 2026}, url = {https://gacs.app/scam/cloudd-x-9450c2} }
Press / media enquiries: About GACS · Editorial policy · Methodology
Authoritative sources
Independent primary sources used to check and corroborate the guidance on this page.
- FBI Internet Crime Complaint Center (IC3)
Official US channel for reporting internet-enabled fraud and cybercrime.
- US Federal Trade Commission — ReportFraud
Consumer fraud reporting and published enforcement data.
- UK Action Fraud
UK national reporting centre for fraud and cybercrime.
- Canadian Anti-Fraud Centre
Canada's central repository for fraud reports and scam alerts.
