You publish a post. Seconds later, a comment appears from "DEV Support" — official-looking logo, urgent tone::
"Dear User, due to an increase in bot activity on the platform, we require verify of your account. Please log in via the link below: [shortened link]. Verification deadline — 12 hours. Failure to verify will result in restricted access."
Do not click that link. It's a phishing scam, it's spreading across dev.to right now, and its entire goal is to steal your login on a fake page that looks like DEV.
I'm writing this because it just landed on my own post, within seconds of publishing — and it's hitting hundreds of others. Here's how to spot it every time, and what to do.
Why it lands the moment you publish
These bots watch the freshly-published feed. The faster they comment, the more likely you're still online, distracted, and reacting. Reports have them arriving 38–79 seconds after a post goes live. It's not personal and it's not about your account — you just showed up on the new feed.
The 5-second tells (every one is in this scam)
- A brand-new account impersonating staff. "DEV Support" / "Dev_Supports", joined yesterday, zero real posts, using the DEV logo as its avatar. Real platform staff don't have day-old accounts.
- Manufactured urgency. "12 hours." "Restricted access." "Failure to verify…" Deadlines exist to stop you from thinking. That's the oldest trick in phishing.
-
A link that isn't dev.to. A URL shortener (
tr[.]ee/…) or a domain registered days ago (anti-bot[.]icu/…), often hidden behind Cloudflare. The real platform never sends you to a random shortened domain to "verify." - Lookalike Unicode letters. Look closely at the message and you'll see Cyrillic characters swapped in — "Dеаr", "Рlеase", "Sіncеrеlу". Those aren't the Latin letters they look like. Scammers use them to slip past dev.to's spam filters. If a word looks subtly off, copy it into a Unicode checker — mixed scripts in a "support" message is a dead giveaway.
- Broken grammar in an "official" notice. "we require verify of your account", "Verificated deadline". A real support team writing to millions doesn't ship that.
Any one of these should stop you. This scam has all five.
The one rule that makes you immune
No legitimate platform will ever comment on your post, DM you, or email you demanding you "verify your account" through a link, under a countdown. Verification, when it's real, happens inside the site you already trust — via a URL you typed yourself, never via a link someone sent you.
When in doubt, don't click anything. Open a new tab, type dev.to yourself, and check your notifications/settings there. If there were a real account issue, it'd be in your actual account — not in a stranger's comment.
What to do right now
- Don't click. Don't log in anywhere the link sends you. That page exists only to capture your password.
- Report the comment and the account. On the comment: the ⋯ menu → Report Abuse. On the profile: Report. The faster these get flagged, the faster they're removed.
- Delete the comment from your post so it can't fool your readers.
- Warn your followers — a quick heads-up post or note. Community immunity is faster than moderation.
- Turn on 2FA on your account (Settings → Account). Even if a credential leaks, 2FA blocks the takeover.
If you already clicked and entered your password
Move fast, in this order:
-
Change your DEV password immediately — from
dev.totyped by hand, not any link. - Revoke active sessions / sign out everywhere in account settings.
- Enable 2FA now.
- If you reused that password anywhere else, change it there too — credential-stuffing is the whole point of stealing it.
- Watch for follow-on scams; a compromised account gets targeted again.
The bigger picture
This works for the same reason every phishing scam works: it hijacks trust and urgency faster than you can engage your skepticism. The DEV logo buys the trust; the 12-hour countdown kills the skepticism. Slow down, check the sender, check the URL, and it falls apart instantly.
Share this with anyone who posts on dev.to — especially newer folks, who are the target. The best defense against a scam that spreads in 60 seconds is a community that recognizes it in 5.
Did this "DEV Support" comment hit your post too? How fast did it arrive after you published? Drop it below so people know how widespread this is — and report every one you see. 👇
I write about security and the honest ways things break. Follow me here if that's your lane. 👋

Top comments (1)
Some comments have been hidden by the post's author - find out more