Free guide · No signup
X Safety Cheat Sheet 2026
The 60-second daily routine that keeps X (Twitter) users one step ahead of impersonators, fake giveaways, and recovery scams. Built on real signals from the GACS scam database.
“Solid free hub for X users on fraud awareness and protection basics… happy to point people your way.”
xAI's official Grok account publicly reviewed this cheat sheet on X and recommended it to its followers. Free, ad-free, no signup — share it with anyone who uses X.

Daily 60-second routine
- •Open gacs.app and run a quick scan on your own @ handle (free, 10/week, no signup).
- •Scan 5–10 people who recently DMed or followed you.
- •If any account flags, use the one-click Warn-Your-Network share button.
Spot impersonators (the #1 X threat)
- •Before clicking any link in a DM, paste the sender's profile into the Social Scanner.
- •Red flags: account <30 days old, creator's photo, 'giveaway' / 'DM for verification' / 'Elon sent me'.
- •GACS auto-detects Cyrillic/Greek lookalikes (е→e, о→o), zero-width chars, and leetspeak in handles.
- •Never send crypto, gift cards, or 'verification fees' — those are always scams.
Power tools you should be using
- •Profile Scam Check on every new follower or reply-guy.
- •Wallet Scam Check on any crypto address pasted in your DMs or replies.
- •Website / Link Checker on every shortened URL before you click.
- •Honeypot Checker on any new token someone is pushing on you.
Power-user workflow (5 min/day)
- •1. Quick self-scan.
- •2. Scan the latest 5 followers + anyone who replied to you.
- •3. Check any wallet or link in your DMs.
- •4. Watchlist your @ so you get an alert any time someone reports a profile matching yours.
- •5. Share one warning or success story — community reports make the next scan smarter for everyone.
Privacy & account settings
- •Enable 2FA on X with an app-based authenticator (not SMS).
- •Turn off 'Allow message requests from everyone' if you get DM spam.
- •Never connect a wallet to any site unless GACS verifies it as safe.
- •Periodically review your Following list — old accounts get hacked and turned into scam vectors.
Hidden powers most people don't know GACS does
- •Detects homoglyph handles (е, о, р, с — Cyrillic letters that look identical to Latin).
- •Cross-references 136,000+ community-confirmed scams across 40+ countries.
- •Works on X, TikTok, Instagram, Telegram, Facebook, YouTube, wallets, websites, links, and tokens.
- •Completely free for individuals. No ads. No data sold.
Emergency toolkit — save this
Pro move — add this to your X bio
Safety first → Scanned by gacs.app · DMs = GACS checkedSignals to scammers you do your homework. Free, takes 5 seconds, builds trust with real followers.
Plain-English glossary
Tap any term to expand. Built so you can explain these to a parent, a journalist, or a sceptical friend in one sentence.
Scammers swap normal letters for visually identical ones from other alphabets (mostly Cyrillic and Greek) so a fake handle looks exactly like the real one. Your eye reads 'elonmusk' but the computer sees a different account entirely.
An account copies a real person's or brand's name, photo, and bio — usually adding 'official', 'support', 'airdrop', or trailing digits — to trick you into clicking, sending crypto, or sharing a code. It's the #1 attack vector on X.
GACS takes what you paste (a profile URL, a website, a wallet address, a token, a phone number) and checks it against 136,000+ confirmed scams, learned fraud patterns, and live community reports. You get a Safe / Caution / Danger verdict with the exact signals that drove it.
Looks identical to the real site (X, Binance, MetaMask, your bank) but the URL is slightly off. Once you type your password or sign a wallet transaction, the scammer takes over.
After you lose money, fake 'recovery agents', 'blockchain forensics experts', or 'asset recovery lawyers' DM you offering to get it back — for an upfront fee. They take the fee and disappear. Real recovery never works this way.
Translated from 'sha zhu pan' (杀猪盘). The scammer befriends or flirts with you for weeks, builds trust, then introduces a 'guaranteed-return' trading platform. The platform shows fake profits until you try to withdraw — and the money is gone.
The contract is written so only the deployer can sell. You watch the chart pump, try to take profit, and the transaction silently fails. Your money is stuck forever.
Hosted on phishing sites disguised as airdrop claims, NFT mints, or token unlocks. The signature you're asked to approve isn't a login — it's permission for the attacker to move every asset out.
Unicode includes characters that render nothing on screen (zero-width space, zero-width joiner, byte-order mark). Scammers paste them inside otherwise-real-looking handles to bypass exact-match blocklists.
Every scan ends with one of three labels: Safe to research (no red flags found), Caution (suspicious patterns — verify before engaging), or Danger (matches a known scam or strong impersonation). The verdict is always followed by the exact signals that produced it — never a black box.
Save any handle, wallet, domain, or keyword to your watchlist. If a new community report comes in that matches, GACS emails you within minutes so you can react before more victims fall for it.
Save your scans + get re-alerted
Free account · we'll email you if anything you scanned gets new reports.
Create free accountAuthoritative sources
Independent primary sources used to check and corroborate the guidance on this page.
- FBI Internet Crime Complaint Center (IC3)
Official US channel for reporting internet-enabled fraud and cybercrime.
- US Federal Trade Commission — ReportFraud
Consumer fraud reporting and published enforcement data.
- UK Action Fraud
UK national reporting centre for fraud and cybercrime.
- Canadian Anti-Fraud Centre
Canada's central repository for fraud reports and scam alerts.
