Cardano's IOG Warns Users After YouTube Channel Hijacked

ADA
Charles HoskinsonYouTube hijackphishing scamfake giveawayAI deepfakeCardanoIOG
10 hours agoSource: crypto.news
Cardano's IOG Warns Users After YouTube Channel Hijacked

Input Output Group has warned Cardano users to avoid its YouTube channel on Sept. 18 after an apparent takeover resulted in a suspected AI-manipulated Charles Hoskinson livestream promoting a cryptocurrency giveaway.

Summary

  • Input Output warned users to avoid its YouTube channel after an apparent account hijack Friday.
  • A suspected AI-manipulated Charles Hoskinson livestream promoted a fraudulent giveaway promising viewers doubled crypto returns.
  • The broadcast used Project Catalyst branding and displayed a QR code directing users toward payments.
  • IOG told users not to click links, send funds, or share personal information with scammers.
  • Cardano has documented similar YouTube giveaway scams for years, including hijacked channels impersonating ecosystem leaders.

Input Output said through its official X account that users should avoid interacting with the channel “until further notice,” while warning people not to click links, transfer funds or provide personal information through material appearing there.

The warning came while the channel was carrying a livestream presented as a Project Catalyst town hall. The broadcast used footage resembling Hoskinson and promoted an offer that claimed viewers could “double your wealth” by following instructions linked through a QR code. No evidence reviewed shows Hoskinson or Project Catalyst authorized the promotion.

IOG warns users away from its compromised YouTube channel

At the time of the warning, the suspicious livestream had remained online for close to two hours, according to reporting on the incident. IOG did not state publicly how access to its channel had been obtained or identify the party behind the apparent takeover.

Its security message focused on preventing further interaction. Users were told not to follow links, send cryptocurrency or submit personal details until the organization confirmed that its YouTube presence was safe again.

No subsequent official post located during this review confirmed that the channel had been fully recovered. Current search results still surface IOG’s ordinary historical videos, but their availability does not by itself establish that administrative control has been restored.

IOG has not published a wallet address associated with the fraudulent broadcast. It has likewise not disclosed whether anyone sent ADA or another asset after viewing the stream, leaving any claimed losses unverified.

No credible blockchain-forensics firm or security researcher reviewed for this report had published a verified attribution, scam-wallet balance or transaction trail tied specifically to the Sept. 18 incident.

Fake Hoskinson livestream followed an old scam pattern

The format closely resembles a type of fraud that Cardano has warned users about for years.

Cardano’s official scam-awareness guide specifically describes ADA giveaway schemes in which scammers promise to double a user’s holdings after receiving an initial transfer. The guidance says fraudulent streams frequently use fake videos of Charles Hoskinson or other well-known figures to make the offer appear authentic.

Cardano warns that legitimate giveaways never require users to send cryptocurrency first. Once ADA is transferred to a scam address, blockchain transactions cannot simply be reversed by Cardano’s developers or ecosystem organizations.

The Cardano Foundation documented the same technique as early as 2020. In a community notice, it said scammers had been hijacking YouTube accounts with established audiences, impersonating Cardano organizations and promoting offers that claimed users would receive more crypto after making a deposit.

The Foundation stated that neither it, EMURGO nor Input Output would promote giveaways requiring users to send ADA or another asset.

Community reports have since documented multiple fake Hoskinson streams. One 2024 report described an impersonation channel using what the user characterized as AI-generated Hoskinson footage to promote a giveaway. That community report did not establish who created the video.

Project Catalyst branding gave the stream a legitimate appearance

The Sept. 18 broadcast was presented as a Project Catalyst event, using branding associated with Cardano’s community-funding program.

Project Catalyst is a genuine Cardano initiative. Its official site describes the program as a community funding system through which Cardano users submit, review and vote on proposals. The platform says 2,221 proposals have received funding across its completed rounds.

Input Output has historically played a direct role in Catalyst. A February 2026 Catalyst update identified IOG as the program’s operator at that time while responsibilities were being reorganized with the Cardano Foundation and Intersect.

By June, Intersect said administration had transferred from IOG to the Cardano Foundation, with remaining milestones from one IOG Catalyst project canceled and 2.06 million ADA returned to the treasury.

Using Catalyst branding therefore gave the fraudulent livestream a recognizable Cardano context even though no official Catalyst source reviewed for this report announced a legitimate town hall matching the giveaway broadcast.

The use of a familiar project name combined with apparent Hoskinson footage follows the social-engineering pattern described in Cardano’s scam guidance: genuine-looking ecosystem material is combined with a malicious payment request.

Cardano has dealt with compromised official accounts before

The incident is not the first time a prominent Cardano-linked social account has been compromised.

As previous Cardano account breach coverage reported, the Cardano Foundation’s X account was compromised in December 2024 and used to publish a false claim that the U.S. Securities and Exchange Commission had sued the organization. The attackers falsely told users that support for ADA would cease.

Hoskinson responded at the time by identifying the posts as unauthorized. The fake announcement was unrelated to the current YouTube incident, but both cases involved trusted Cardano-branded communication channels carrying content that did not originate from the organization controlling the account.

Scam reports involving YouTube stretch back even further. Cardano’s community forum contains reports from users who said they lost ADA after encountering fake livestreams offering to return twice the amount sent. One 2022 user reported transferring 10,000 ADA after seeing a fraudulent Hoskinson-themed broadcast. That loss was self-reported by the user and was not independently verified.

Another forum thread describes the attackers’ recurring method: taking control of established YouTube channels, replacing their content with crypto giveaway livestreams and directing viewers toward payment addresses or external sites.

Suspected AI manipulation has not been independently verified

The latest video has been described as AI-manipulated, but no technical forensic report reviewed for this update has confirmed how the Hoskinson footage was produced.

The distinction remains relevant because scam operators can use several methods, including edited historical footage, altered audio, synthetic voice generation or fully generated video.

Cardano’s current security guidance explicitly warns that improvements in artificial intelligence are making impersonation scams more sophisticated. Its giveaway section names fake livestreams featuring Hoskinson as a recurring risk.

IOG itself has been experimenting publicly with AI-generated content. In June, Hoskinson defended an AI-generated influencer post published through an Input Output account, saying it formed part of experiments around AI agents and Midnight City. Earlier coverage of IOG’s AI content tests reported that some community members objected to the synthetic content.

That legitimate experimentation is unrelated to the Sept. 18 suspicious livestream. IOG’s warning expressly told users not to interact with the compromised YouTube channel, while the giveaway itself has not been endorsed by the company.

At the time of this review, IOG had not announced how the channel was compromised, whether multi-factor authentication was bypassed, whether other corporate accounts were affected or whether the attacker obtained access to internal systems beyond YouTube.

Its official instruction remains to avoid the channel until the organization issues another notice confirming that normal control has been restored.