V2EX = way to explore
V2EX 是一个关于分享和探索的地方
现在注册
已注册用户请  登录
lait
V2EX  ›  信息安全

疑似 GitHub × Gitcoin 的骗局

  •  1
     
  •   lait · 8 小时 51 分钟前 · 2123 次点击

    今天收到来自 notificationpromo[bot] [email protected] 的邮件:

    📌 GitHub × Gitcoin Developer Fund 2025
    Dear community,
    
    We are excited to introduce the upcoming phase of the GitHub Developer Fund, a joint program with Gitcoin designed to highlight and support those who strengthen open-source technologies and digital public goods.
    
    Your GitHub account qualifies for participation in this phase. We value every type of involvement — from occasional contributions to long-term commitment — as essential to shaping the future of open source.
    
    Program overview:
    
    Funding approach: Quadratic Funding, boosting community influence through a shared pool
    Total allocation: $15,000,000 USDC
    Eligibility: Active participation and potential future impact — open to everyday contributors and maintainers, not just project founders
    Next step:
    To secure your preliminary registration and confirm eligibility, please verify your wallet using Gitcoin Passport. This ensures fairness, protects against Sybil attacks, and never requests personal data. Verification takes under a minute: connect your wallet and sign a message.
    
    Please note:
    The authorization requires a refundable deposit, which will be fully returned after the process is completed.
    
    📝 Continue with authentication and submission here: https://grants.github.com/apply
    Participation and funding eligibility are finalized only with a valid Gitcoin Passport score. Full guidelines are available on our portal.
    
    Best regards,
    GitHub Developer Fund Team
    In partnership with Gitcoin
    
    This message was sent to you as a registered GitHub user.
    ©2025 GitHub, Inc. All rights reserved.
    Address: 88 Colin P Kelly Jr St, San Francisco, CA 94107, USA.
    [Manage notifications] | [Privacy Policy]
    

    点邮件里 https://grants.github.com/apply 实际指向了 https://github-fund.com/

    邮件是借助 GitHub 的 ieeues @xx 功能自动触发通知邮件产生,原始仓库地址: https://github.com/gitcoinoda/org/issues

    大家注意防范!!!

    14 条回复    2025-09-23 15:02:22 +08:00
    KagurazakaNyaa
        1
    KagurazakaNyaa  
       8 小时 49 分钟前
    SilenceLL
        2
    SilenceLL  
       8 小时 47 分钟前
    我也收到了,没管它
    wu67
        3
    wu67  
       8 小时 46 分钟前
    同收到. 应该是最近有过在知名开源项目发 issue/讨论的行为, 就会被爬公开的邮箱然后发垃圾邮件.
    penzi
        4
    penzi  
       8 小时 45 分钟前
    一直有 unread notification ,点进去空的😡
    mcwq123
        5
    mcwq123  
       8 小时 36 分钟前
    我也收到了, 而且下面 @了很多人, 都是和自己的 id 开头字母接近的, 有点难绷.
    lait
        6
    lait  
    OP
       8 小时 30 分钟前
    pakholeung372
        7
    pakholeung372  
       8 小时 27 分钟前
    同收到,不用管
    gsw945
        8
    gsw945  
       8 小时 22 分钟前
    我也收到了,当找到文档后准备去举报时,仓库和用户已经被清除了。

    举报操作相关文档如下:
    https://docs.github.com/zh/communities/maintaining-your-safety-on-github/reporting-abuse-or-spam
    csrocks
        9
    csrocks  
       5 小时 34 分钟前


    这种我反手就举报, github 很快就把账户封了
    westfall
        10
    westfall  
       5 小时 30 分钟前
    我被骗了 7 美元,幸亏钓鱼网站不支持 phantom ,我用小狐狸连接的,包里没多少钱
    stimw
        11
    stimw  
       5 小时 26 分钟前
    猜猜谁没有收到邀请————我。。。。
    kuro1
        12
    kuro1  
       5 小时 8 分钟前
    昨天举报过了
    wogogoing
        13
    wogogoing  
    PRO
       4 小时 58 分钟前
    我昨天收到邮件的时候,反复确认了好几遍发信地址。。。
    CKylinMC
        14
    CKylinMC  
       4 小时 35 分钟前
    收到了,看上去就觉得不对劲,尤其是链接和目标不同。report 了,然后秒封。
    关于   ·   帮助文档   ·   自助推广系统   ·   博客   ·   API   ·   FAQ   ·   实用小工具   ·   2994 人在线   最高记录 6679   ·     Select Language
    创意工作者们的社区
    World is powered by solitude
    VERSION: 3.9.8.5 · 21ms · UTC 11:37 · PVG 19:37 · LAX 04:37 · JFK 07:37
    Developed with CodeLauncher
    ♥ Do have faith in what you're doing.