DEV Community

Cover image for The Email That Almost Fooled a Developer: A Story About Open Source, Trust, and Scams
Hieu Louis
Hieu Louis

Posted on

The Email That Almost Fooled a Developer: A Story About Open Source, Trust, and Scams

I am a developer. For months, I have poured almost all of my free time into Halis, a systems programming language that I believe can change how people think about safety in software. I have written thousands of lines of code. I have fixed my own compiler errors, my own security bugs, my own infinite loops. I am at stage 30 out of 150. There is still a long road ahead, but I am proud of what I have built.

Then one morning, I opened my inbox and found a strange email.

The sender called himself Joshua. He wrote in English, with a confident and direct tone. He said he knew my project was underexposed, but that was a fixable problem. He said he noticed I had been committing recently, and that mattered more than people thought. He said the core work was already done, and what was missing was distribution, getting Halis in front of the right communities, the right people. He offered to rewrite the README, find four or five channels that fit my audience, and build a sustained presence. At the end, he invited me to a short call, no obligation, no pitch.

I sat there for a moment. My first feeling was joy. Someone cared about what I was building. Someone saw value in the code I had stayed up late to write. But then an uneasy feeling crept in. I did not reply right away. I read the email again, slower this time, line by line, and I started to see the cracks.


The Artificial Directness

His opening line was a perfect example.

"I will be direct, since you probably get plenty of vague emails."

It sounded sincere. But any scammer can write that sentence. He was trying to separate himself from the spam, trying to lower my defenses in the first few seconds. A real person who genuinely wants to help does not need to convince me that he is not a scammer. He just needs to show me that he understands my project.

This is a classic psychological trick. By acknowledging that I probably get spam, he is implying that his email is not spam. But the truth is that any scammer can write this exact sentence. It requires no knowledge, no skill, and no real intention to help. It is a canned line designed to lower my defenses in the first three seconds.


The Obvious Weakness

Then he said Halis was underexposed. That was true, but anyone who opens my GitHub can see it. He did not need to read my code or understand what Halis does. He just needed to look at the number next to the star.

He called it a fixable problem and positioned himself as the one with the solution. This is how he creates dependence. He wanted me to think I needed him.

Think about what that phrase does. It tells me that I have a weakness, and he has the solution. He is creating a problem in my mind and positioning himself as the only person who can solve it. This is manipulation, pure and simple.


The Public Information

He said he noticed my recent commits. But I had just published an article about Halis on dev.to a few days earlier. Anyone who read that article would know I was actively working on the project.

He did not need to follow my GitHub. He only needed to read a public post. He used public information to create the illusion that he was paying close attention. In reality, he just repeated what he had read.

He is using publicly available information to create the illusion that he is paying close attention to my work. He wants me to believe that he is genuinely interested in Halis, that he has been watching my progress. But the truth is simpler. He read a blog post and repeated what he saw.


The Lie About My Project

Then came the sentence that stopped me cold.

"From what I can tell, the core work is already done."

If he had actually read my ROADMAP, he would know Halis is at stage 30 out of 150. If he had looked at the repository, he would have seen the long list of features still missing. He did not read. He did not know. He just guessed, and he guessed wrong. That told me he had not spent any time understanding my project. He just wanted to sell me something.

This was the moment I realized something was very wrong. A real consultant would spend time understanding the project before offering advice. This man did not do that. He just wanted to convince me that everything was ready and that all I needed was his help to "distribute" it.


The Vague Promises

He talked about finding the right communities, introducing the project without being flagged as promotion, keeping momentum after the initial spike. It sounded intelligent. But he mentioned no specific community. He offered no strategy. He did not say how to write a post, how to approach admins, how to create value for readers. These are basic marketing principles anyone can write without knowing anything about Halis.

He promised to rewrite my README. But rewrite it how? Focus on what features? Emphasize what points? He did not say.

He promised to find four or five channels. But which ones? Reddit? Hacker News? Dev.to? He did not say.

He promised sustained presence. But for how long? How many posts? How much engagement? He did not say.

He was selling me a service with promises that had no concrete commitments. This is a hallmark of scammers. They use vague language so they can never be held accountable for failing to deliver.


The "No Obligation" Call

Then he invited me to a short call. No obligation. No pitch.

But this was the trap. Over the phone, he would use his voice, his speed, and psychological pressure to make me agree to pay. He would say this opportunity only comes once. He would say he was busy with other clients. He would push me to decide fast.

"No obligation" was just bait to make me say yes.

The phrase "no obligation" is another psychological trick. He wants me to feel safe so I will say yes. But once I am on the call, he will create urgency. He will tell me that this opportunity is limited. He will say that he is busy with other clients. He will push me to make a decision quickly, before I have time to think. This is high-pressure sales disguised as a friendly conversation.


The Wrong Frame

He called Halis a product. He called it a service. But Halis is an open source programming language. I do not sell it. I do not make money from it.

If he had actually read the repo, he would know that. He was trying to frame my project as merchandise and me as a customer in need of help. He did not want to contribute. He wanted to sell.

He is trying to frame my project as a commercial thing and me as a customer who needs help selling it. This is a tactic to turn a potential contributor into a paying client. He does not want to help Halis grow. He wants to sell me a service.


The Ghost

He used a generic email address. A professional marketer usually has a company email, or at least a verifiable online presence.

He had no LinkedIn. No GitHub. No blog. No portfolio. I could not find any trace of this person.

He was a ghost.

He wanted me to trust a person who did not exist.


What Kind of Scam Is This?

This is a marketing consulting scam. It works like this.

  1. The scammer finds active open source projects on GitHub.
  2. He sends personalized emails to build trust.
  3. He offers marketing services for a fee.
  4. If the developer pays, he does very little or nothing.
  5. Sometimes he asks for repository access, then disappears with the code.

After the payment is made, the scammer vanishes. The developer loses money, and the project gets nothing.


What I Did

I did not reply. I marked the email as spam. I reported the account. I went back to building Halis.

And I realized something important. If someone genuinely cared about my project, they would read the ROADMAP. They would know what stage I am at. They would not call Halis a product. They would not send a vague email. They would start by contributing code, or at least opening a specific issue.

Joshua did none of that. Joshua wanted to sell me something.

I did not buy.


What You Should Look Out For

If you are building an open source project, a personal product, or anything you pour your heart into, let me say this honestly.

Be careful with emails like this.

They are not always obvious scams. They are often written with great skill, soft and precise, aimed directly at the psychology of a builder who longs to be seen. A scammer does not need you to be stupid. They only need you to be lonely, tired, and wishing someone would acknowledge your work.

Here is what to watch for.

  • Fake directness. A sentence designed to sound honest is not proof of honesty.
  • Exploiting an obvious weakness. Anyone can see a public repo with few stars. That does not mean they understand your work.
  • Praising public information. They are building false familiarity by repeating what they read.
  • Lying about the state of your project. If they cannot be bothered to read your documentation, their advice is worthless.
  • Vague language. Real experts give specific, actionable advice.
  • The "no obligation" call. It is much easier to pressure you when you can hear their voice.
  • Treating your project like a product. Not everyone who offers help wants to help.
  • No verifiable identity. Trust is earned, not requested.

Always verify the sender. Read every line slowly. Ask yourself: does this person truly understand my project, or are they just repeating what is visible from the outside?

Do not let excitement cloud your judgment. Someone who genuinely wants to walk beside you will not rush. They will take time to understand. They will ask specific questions. They will not need you to answer this week.

And above all, remember that your worth is not measured by how many people notice you. It lives in the code you write, the problems you solve, and the patience you keep when no one is watching.

Do not let a strange email shake that.

Top comments (0)