DEV Community

Cover image for I Found a Phishing Scam Hiding in Dev.to Comments (Here’s How to Spot It) 🚨
Harun - solo dev
Harun - solo dev

Posted on

I Found a Phishing Scam Hiding in Dev.to Comments (Here’s How to Spot It) 🚨

Hey DEV Community! 👋

I’ve been spending a lot of time here lately, reading incredible articles, sharing my own journey building a 142KB AI app on a $150 phone, and learning from all of you.

But recently, I noticed a nasty pattern hiding in the comment sections of multiple posts.

If you’ve been on Dev.to lately, you might have seen a comment that looks exactly like this:

DEV SUPPORTS • [Recent Date]
Official Platform Update
Security protocols have been updated for all developer accounts.
tr.ee/dev-to

At first glance, it looks official. It has the Dev.to logo. It uses urgent language. But this is a phishing scam. 🚨

I’ve called it out in the comments every time I see it, and I want to break down exactly why this is dangerous and how you can protect yourself (and your fellow developers).

🕵️‍♂️ The Anatomy of the Scam

Let’s dissect why this comment is a massive red flag:

  1. The Fake Urgency: "Security protocols have been updated" is a classic social engineering tactic. It’s designed to make you panic and click without thinking.
  2. The Sketchy URL: tr.ee is a third-party link shortener. Dev.to will NEVER ask you to verify your account via a third-party link shortener in a comment section. Real platform updates happen via official emails from @dev.to or native in-app notifications, not random comments.
  3. The Bot Account: Notice the username: suppdevbot. It’s designed to look like "Dev Supports," but it’s just a compromised or newly created bot account spamming the same copy-pasted message across dozens of popular articles.

💀 Why This is Dangerous

If you click that link, it doesn’t take you to Dev.to. It takes you to a fake "verification" page. These pages are designed to look like a login screen. If you enter your Dev.to credentials (or worse, your GitHub/Google login), the attackers steal your account. From there, they can:

  • Post more spam from your trusted account.
  • Access any private repositories linked to your profile.
  • Use your reputation to scam other developers.

🛡️ How We Fight Back (The Community Defense)

The good news? The Dev.to community is sharp, and we are catching it every time.

Whenever I see this comment, I reply with a loud, clear warning:

"THIS IS A PHISHING SCAM 🚨 Do not click this link. Dev.to will never ask you to verify your account via a third-party link in the comments."

I’ve also seen other awesome community members doing the exact same thing. This is what a healthy, self-policing community looks like. We protect our own.

✅ Your Action Plan

If you see this comment:

  1. DO NOT CLICK THE LINK.
  2. Reply with a warning so others scrolling by see it immediately.
  3. Use the "Report" button on the comment to flag it to the real Dev.to moderation team.
  4. Spread the word. Share this article with your dev friends, especially juniors who might not recognize the red flags yet.

💡 The Takeaway

We spend hours writing secure code, validating inputs, and protecting our users from vulnerabilities. Let’s apply that same security-first mindset to how we navigate the web.

Stay sharp, verify your sources, and keep building amazing things.

Have you seen this scam on other platforms? How do you spot phishing attempts? Let’s discuss in the comments! 👇🐯

Top comments (1)

Collapse
 
nyaomaru profile image
nyaomaru •

I reported this user. Thank you for warning! 👍