The Receipt Is the Payload: A Domainless Crypto-Reward Scam
The Receipt Is the Payload: A Domainless Crypto-Reward Scam
Between May 8 and 13, 2026, we tracked a crypto-reward scam that carried its entire lure inside genuine, Google-signed Forms response receipts. The operator never registered a domain, never spoofed a sender, and never stood up a server. Instead the lure text lived inside a Google Form's auto-confirmation receipt, so it reached targets as a real message from forms-receipts-noreply@google[.]com, passing SPF, DKIM, and DMARC because Google genuinely sent it. Every click-through destination sat on a legitimate shared platform, and a real Bitcoin block explorer was pressed into service as fake proof of funds. The campaign delivered hundreds of these receipts across 18 localized variants over six days, then went quiet.
Key Takeaways
- The delivery channel is a Google Forms response receipt. Attacker copy rides inside the form's confirmation email, which Google sends and signs, so sender-reputation and authentication filtering have nothing to catch.
- There is no operator-owned infrastructure anywhere. Six legitimate platforms carry the click-through, and the only durable indicators are the operator-authored resource paths, not any apex or sender.
- The lure is advance-fee fraud dressed as a crypto payout: a fabricated wallet balance, a promo code, and a countdown, all pointing the victim toward a fee-to-release or wallet-connect step.
- A genuine
mempool[.]spaceblock-explorer view is embedded as manufactured proof of funds, borrowing a trusted tool's authenticity to make an invented balance look verifiable. - Operator-authored strings survive platform rotation. Date-indexed Telegraph slugs and a fixed Cloudflare Workers subdomain grammar fingerprint the same actor even as the landing host changes.
Background
The campaign surfaced while we were mapping unrelated Cloudflare Workers abuse and noticed a cluster of one-shot Worker landers whose sending address was, in every case, a Google Forms receipt relay carrying multilingual crypto-conversion subjects. Pivoting on that relay pulled the rest of the operation into view.
Advance-fee fraud promises a large benefit that is supposedly ready to release, then extracts value before it can be collected. Here the promised benefit is a crypto reward or converted-Bitcoin payout, and the extraction step is a fee (framed as a blockchain tax, a verification charge, or a wallet-synchronization step) or a wallet connection that hands the operator funds or spending approvals. The payout never exists. Crypto's irreversibility makes any loss permanent, which is why the pretext has migrated so heavily onto reward and payout framing.
What makes this operation worth documenting is not the pretext but the delivery. Google Forms lets a form's creator turn on a response receipt, an automated confirmation email Google generates when the form is submitted. The creator controls the form's title, description, and confirmation text, so attacker-authored copy, promo codes, and links end up inside a message that Google itself sends from forms-receipts-noreply@google[.]com. The mail is not spoofed. It authenticates as genuine Google mail on SPF, DKIM, and DMARC, and cannot be blocked at the sender without breaking legitimate Google Forms traffic for everyone. A recipient can be enrolled simply by an attacker typing the target address into the form, so a receipt does not mean the victim ever touched anything.
The rest of the stack follows the same living-off-trusted-platforms logic. Rather than register domains that accrue detectable reputation, the operator parks every hop on services a reader and a URL scanner both trust:
docs.google[.]comForms and Drawings render attacker content, including clickable links embedded in a Drawing, on a URL that inherits Google's domain trust. Drawings here host fabricated wallet-balance graphics.telegra[.]ph, Telegram's account-less instant-publishing tool, hosts throwaway landing pages styled to look like payout portals. Its anonymity and clean reputation make it a favored disposable lander for crypto scams.workers[.]dev, Cloudflare's free developer hosting, spins up one-shot landers under a trusted parent domain with TLS by default and near-zero cost.ok[.]me, the OK.ru and VK social-network short-link service, launders the true destination behind an established, high-reputation domain.link.ok[.]ru, the same social network's redirect host, adds a first-stage hop that fronts the fake proof-of-funds page.mempool[.]space, a legitimate open-source Bitcoin block explorer, gets linked as staged proof of funds. Because any address or pending transaction is publicly viewable, a real explorer view manufactures credible evidence that a balance exists. The project itself has publicly warned that it runs no recovery service and that its name is impersonated in scams.
Google Forms receipt abuse and broader Google-relay phishing have both drawn public reporting: messages sent from genuine Google addresses pass authentication and slip past gateways, with parallel abuse documented across other trusted notification relays. This campaign is a clean instance of the pattern, narrowed to a single lure family.
Discovery and Infrastructure
The relay sender is the spine of the operation. Every message, across all six platforms and every language variant, arrives from forms-receipts-noreply@google[.]com with a trix[.]bounces[.]google[.]com return path. A host-by-host view fragments the campaign into unrelated one-shot landers; the relay reunifies it. That single pivot expanded an eight-host Worker cluster into the full footprint below.
| Platform | Role | Distinct operator resources | Date span |
|---|---|---|---|
telegra[.]ph |
Landing pages | 13 slugs | May 8 to May 13 |
docs.google[.]com / forms[.]gle |
Landers and fake-balance graphics | 14 | May 8 to May 13 |
workers[.]dev |
One-shot landers | 8 subdomains | May 8 to May 11 |
ok[.]me |
Short-link redirectors | 4 codes | May 8 to May 11 |
link.ok[.]ru |
First-stage redirects | 3 codes | May 8 to May 12 |
mempool[.]space |
Fake proof-of-funds decoy | Reached via redirects | May 10 to May 12 |
The landing destination rotates across all six platforms in parallel, with Telegraph and Google Forms dominant. No single host carries the campaign, which is the point: each one is disposable, and none is worth blocking at the apex because doing so would harm the platform's real users. The durable signal is the combination of the relay sender and the lure family, plus a set of operator-authored naming conventions that persist even as hosts rot.
How It Works
The operator builds a Google Form and writes the scam into it: the reward pitch goes in the title and confirmation text, a link to the next hop goes in the body, and the response receipt is switched on. The target's address is entered into the form, which triggers Google to send a confirmation receipt to that address. The victim receives what looks like, and technically is, a routine Google Forms receipt.
Inside the receipt, Google's own chrome wraps the lure. The localized receipt opener ("Thanks for filling in this form", "Gracias por completar el formulario") sits above an emoji-heavy reward body, a per-victim user ID, a receipt number, and a promo code. Google's genuine boilerplate ("You received this email because you filled in the following form... make sure you recognize and trust this form before clicking any links") appears at the bottom, where it reads as reassurance rather than warning. In several samples the operator populated the form-owner label with an official-sounding organization, such as a government education department, so the boilerplate lends borrowed authority.
The body promises a crypto reward or a completed Bitcoin-to-cash conversion, shows a multi-row wallet ledger of recoverable balances, and closes with a line telling the victim the money will be sent to their Bitcoin address once they act. A copy-this-link-and-paste-it instruction sits next to the CTA, a small touch that defeats link rewriting in some mail clients. The link leads to a Telegraph page, a Google Form or Drawing, or a Cloudflare Worker, sometimes by way of an OK.ru redirect. For victims who want to verify the balance, an OK.ru short link fronts a real mempool[.]space view, so the fabricated funds appear to exist on the public blockchain. From there the funnel drives toward the fee-to-release or wallet-connect step where the actual loss occurs.
Sample Lures
All recipient data has been removed. The user IDs, receipt numbers, and reward amounts below are attacker-generated tokens, not victim identifiers. Domains are defanged.
Spanish-locale receipt, Google Forms click-through, reward-and-promo-code variant:
From: Recibos de respuestas de Formularios <forms-receipts-noreply@google[.]com>
Return-Path: <...@trix[.]bounces[.]google[.]com>
Subject: Gracias por completar el formulario Hi! User: XMC45BH. 777 USD reward is ending soon! 33h left.
Event - Unlock extra rewards
Use code REWARD777 -> GET $777 instantly
+57277 USD
+74898 USD
(fabricated wallet ledger)
Money from these wallets will go to your BTC address! ID-41127MMWTL
Best regards, Ronald Roberts Help Desk
CTA: http[:]//forms[.]gle/... -> http[:]//docs.google[.]com/forms/d/e/1FAIpQLSe...
English-locale receipt, Telegraph click-through, Bitcoin-conversion variant with block-explorer decoy:
From: Forms response receipts <forms-receipts-noreply@google[.]com>
Return-Path: <...@trix[.]bounces[.]google[.]com>
Subject: Thanks for filling in this form: Critical Update. No.615298. Trade bitcoins for USD. Status Revision: Officially Acknowledged!
CTA: http[:]//telegra[.]ph/Entrance-is-allowed-05-13-6
Decoy "proof of funds": http[:]//mempool[.]space/
Technical Analysis
An Authenticated Delivery Channel
The delivery mechanic is the whole trick. Because the mail is a genuine Google Forms receipt, it carries valid SPF, DKIM, and DMARC alignment to google[.]com at the source. There is no spoofed header to fail, no lookalike domain to flag, and no negative sender reputation to accrue, since the sender is one of Google's own service addresses. The operator's control surface is the form's editable text, and the abused tenant is a disposable per-form identity that leaves no reusable sender artifact. Detection has to come from the content and the click-through, not from who sent the mail or whether it authenticated.
Localized Receipt Chrome
The operator generated the receipt in 18 distinct display-name variants spanning roughly 16 languages, which points to broad international targeting rather than a single market. Two of the variants are English casings and two are Spanish regionalizations, with the Dutch variant the most frequent.
| Display name | Language |
|---|---|
| Ontvangstbewijzen voor reacties op formulieren | Dutch (most frequent) |
| Forms Response Receipts | English (title case) |
| Forms response receipts | English (sentence case) |
| Recibos de respuestas de Formularios | Spanish (Latin America) |
| Acuses de recibo de respuestas al formulario | Spanish (Spain) |
| Empfangsbestätigungen für Formularantworten | German |
| Réponse à un formulaire | French |
| Ricevute di risposta di Moduli | Italian |
| Comprovante de resposta do Google Formulários | Portuguese (Brazil) |
| Confirmări pentru răspunsurile la formulare | Romanian |
| Email cho biết đã nhận câu trả lời trong biểu mẫu | Vietnamese |
| Konfirmimi i marrjes së përgjigjeve të formularëve | Albanian |
| Shakllar javoblarini yuborish | Uzbek |
| Αποδείξεις απαντήσεων φόρμας | Greek |
| Копии ответов респондентам | Russian |
| फारामहरूमा प्राप्त जवाफका इमेल | Nepali |
| フォームの回答のコピー | Japanese |
| رسائل استلام الردود على النماذج | Arabic |
The display name is a localization of Google's own receipt sender label, not attacker free text, so it changes with the locale of the form rather than with the operator's choice. The breadth of locales is still an operator-footprint signal: this is not a single-country run.
Operator-Authored Resource Grammar
Once the sender and apexes are stripped as non-signals, what remains is a set of naming conventions the operator authored, and those are consistent enough to fingerprint the actor across platforms.
Telegraph slugs follow two date-indexed patterns: entrance-is-allowed-<MM-DD-N>, where N is a per-day sequence index that runs from single digits into the 300s, and entrance-is-allowed-ID<digits>-<MM-DD>, a nine-digit ID variant. Leading capitalization varies between entrance- and Entrance-, which Telegraph treats as distinct pages. The date is baked into the slug, so the slug family both identifies the operator and timestamps the send.
Cloudflare Worker subdomains follow the grammar [word]-[word]-[4-char-pad].[account-label].workers[.]dev. The pad is a fixed four-character alphanumeric token. The account labels split into two shapes: provisioned app-[random] labels and human-name-styled labels such as ardizzoneplyer62 and yitzchokmcguirejooi.
| Worker subdomain | Account-label shape |
|---|---|
orange-frog-e8ls.app-u3saniofi8.workers[.]dev |
Provisioned |
divine-waterfall-ahdy.app-gtkigbqs.workers[.]dev |
Provisioned |
restless-wildflower-rdt6.app-i4buz5jslc.workers[.]dev |
Provisioned |
long-scene-celq.app-e9f0yiu7h.workers[.]dev |
Provisioned |
odd-snowflake-5ybe.shannbettyd1lte693.workers[.]dev |
Name-styled |
lingering-mountain-udae.ardizzoneplyer62.workers[.]dev |
Name-styled |
winter-dream-691q.yitzchokmcguirejooi.workers[.]dev |
Name-styled |
icy-bird-r016.ruweydasig0356.workers[.]dev |
Name-styled |
The OK.ru layer uses five-character mixed-case codes on two hosts: ok[.]me/<code> as the primary shortener and link.ok[.]ru/<code> as a first-stage redirect. Case-variant duplicates appear (dllp1 and dllP1), and several link.ok[.]ru codes redirect into the mempool[.]space decoy, which establishes the OK.ru redirector as the layer that fronts the fake proof of funds. The same link.ok[.]ru first stage also appeared on an unrelated casino lure earlier in the year, which suggests the OK.ru redirect layer may be a shared first-stage supplier used by more than one crypto or gambling operator.
The Google side uses form IDs under the standard 1FAIpQLS response-ID prefix, reached through forms[.]gle short links, alongside docs.google[.]com/drawings/d/... resources that carry the fabricated wallet-balance images.
The Content Fingerprint
The body is as templated as the infrastructure. Each message carries a per-victim user ID in a seven-character letters-digits-letters shape (XMC45BH, FQQ60SK, NHS66VP), a receipt number (No.615298, No.-1792550-), and a promo-code close (REWARD777 yielding "GET $777 instantly"). Prize amounts rotate across a tight band ("Your $1759 Prize is Ready", "Win $1479 and Celebrate!", "Your $1819 Bonus is Ready"), as does a conversion-pretext set ("Trade bitcoins for USD", "Bitcoin successfully converted", "The coin got transformed to paper money"). The fake wallet ledger renders as stacked +NNNNN USD rows, and the advance-fee close is always some variant of "Money from these wallets will go to your BTC address! ID-[alnum]", signed off by a fabricated help-desk persona. Subject lines lean on status theatre: "Critical Update", "Status Revision: Officially Acknowledged!", "Transaction fully recognized", "Immediate Access".
Nothing to Take Down
Registration-cohort analysis, usually one of the strongest operator signals, gives nothing here, because there is no operator-owned domain to analyze. Every apex is a long-lived platform: google[.]com, ok[.]ru, ok[.]me, mempool[.]space, and workers[.]dev are all established service domains, and telegra[.]ph has no WHOIS record at all. Blocklisting has to target the operator-authored resource paths, the form IDs, Telegraph slugs, Worker subdomains, and OK.ru codes, and never the parent platforms, because an apex block would only damage legitimate Google, Telegram, OK.ru, and Cloudflare traffic. That constraint is exactly why the model appeals to the operator: the takedown surface is minimal and short-lived by design.
Detection Observations
The useful signal is the pairing, not any single attribute. A message from the Google Forms receipt relay is entirely ordinary on its own; the same relay carrying crypto-reward body text, a per-victim user ID, a promo code, and a Bitcoin-address close is not. The relay sender combined with the lure body is the strongest content pivot, and it holds regardless of which platform the click-through lands on.
The operator-authored strings give a second, host-independent pivot. The entrance-is-allowed-<date> Telegraph slug family and the [word]-[word]-[4pad].[account] Worker grammar both identify the actor even after the individual pages and subdomains go dead. A link.ok[.]ru or ok[.]me short link that resolves toward a mempool[.]space view is a specific and unusual chain worth watching, since a legitimate reason to bounce a social-network short link into a raw block-explorer address is rare.
Two smaller tells round it out: the copy-this-link-and-paste-it instruction, which is a deliberate attempt to sidestep link rewriting, and the fabricated multi-row wallet ledger, which has no analog in legitimate Google Forms receipts. None of these depends on the sender failing authentication, which is the whole reason the campaign needs content-level and click-through-level signals to catch it.
Indicators of Compromise
All indicators are defanged. These are the operator-authored resource paths, the only durable indicators in a campaign with no owned domain. The Cloudflare Worker subdomains and Google Forms and Drawings resources are enumerated in the Technical Analysis section above; they are not listed here because they sit on shared hosting and redirect infrastructure that must not be blocked at the host or apex level.
Operator Landing Pages (Telegraph)
| Value | Role |
|---|---|
http[:]//telegra[.]ph/entrance-is-allowed-05-08-39 |
Landing |
http[:]//telegra[.]ph/entrance-is-allowed-id045288759-05-08 |
Landing |
http[:]//telegra[.]ph/entrance-is-allowed-05-09-26 |
Landing |
http[:]//telegra[.]ph/Entrance-is-allowed-ID503733428-05-09 |
Landing |
http[:]//telegra[.]ph/entrance-is-allowed-05-10-18 |
Landing |
http[:]//telegra[.]ph/Entrance-is-allowed-05-10-3 |
Landing |
http[:]//telegra[.]ph/entrance-is-allowed-05-10-41 |
Landing |
http[:]//telegra[.]ph/Entrance-is-allowed-05-10-43 |
Landing |
http[:]//telegra[.]ph/Entrance-is-allowed-05-11-30 |
Landing |
http[:]//telegra[.]ph/Entrance-is-allowed-05-11-4 |
Landing |
http[:]//telegra[.]ph/Entrance-is-allowed-05-12-5 |
Landing |
http[:]//telegra[.]ph/entrance-is-allowed-05-13-302 |
Landing |
http[:]//telegra[.]ph/entrance-is-allowed-05-13-6 |
Landing |
Redirect Short Links (OK.ru / VK)
| Value | Role |
|---|---|
http[:]//ok[.]me/lrc01 |
Redirect |
http[:]//ok[.]me/NQcO1 |
Redirect |
http[:]//ok[.]me/ogcO1 |
Redirect |
http[:]//ok[.]me/qrc01 |
Redirect |
http[:]//link.ok[.]ru/dllp1 |
First-stage redirect |
The entries above are the verified-malicious export subset. The operator rotated additional OK.ru short codes over the window, including case-variant duplicates, that front the same redirect chain.
MITRE Fight Fraud Framework Mapping
The mapping aligns to the MITRE Center for Threat-Informed Defense Fraud matrix (https://ctid.mitre.org/fraud). The matrix is young and its technique identifiers are still stabilizing, so the rows below name the tactic and technique rather than assert a numeric ID.
| Tactic | Observed behavior | How it appears here |
|---|---|---|
| Initial Access | Phishing message from a trusted, authenticated relay | Lure delivered as a genuine Google Forms receipt that passes SPF, DKIM, and DMARC |
| Stealth | Abuse of legitimate infrastructure to evade detection | Living-off-trusted-platforms delivery and click-through across Google, Telegraph, Cloudflare, and OK.ru |
| Initial Access | Fabricated evidence and borrowed authority | A real mempool[.]space block-explorer view staged as proof of funds; official-sounding form-owner label |
| Execution | Urgency and incentive manipulation | Countdown timers, promo codes, and a fabricated recoverable wallet balance |
| Monetization | Advance-fee collection and crypto transfer | Fee-to-release or wallet-connect step framed as the way to claim the promised payout |
Conclusion
Trusted-relay delivery is the part of this campaign worth carrying forward. When the lure arrives inside a message a major provider genuinely sends and signs, the usual first-line defenses, sender reputation and authentication, have nothing to act on, and the operator gets to skip domain registration entirely. The trade-off for the operator is a thin, short-lived infrastructure footprint, which is why the durable indicators here are content fingerprints and operator-authored resource strings rather than any domain or sender. Defenders watching for the next wave should key on the relay-plus-lure pairing and the naming conventions, and treat a social-network short link that resolves toward a raw block explorer as the specific oddity it is.
Related research
The Supplement SMS Kit That Borrows Real Business Identities
Since April 2026, one operation has run 26 supplement storefront domains by text message, most carrying the legal identity of a real registered business.
How a Government-Impersonation Smishing Kit Signs Its Own Registration Batches
A smishing kit impersonating toll agencies, tax offices and national police stamped the registration date into its own WHOIS records.
One Lure, Four Operators: Ad Tracking Strings as Fingerprints
Four separate operators ran the same fake TradingView desktop-app ads on Facebook for nine months, and one query-string key was all that told them apart.