MrBeast Scam Explained: What It Is and What To Do Next

Your friend didn't send those MrBeast giveaway screenshots. Here's what stole their account, why viewing the images is safe, and how to get your own accounts back.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

A friend messages you on Discord, or a story shows up on their Instagram. It's a few screenshots of MrBeast handing out $2,500, with a website address printed across the picture.

The bad news is that your friend didn't actually send the messages, and you're looking at a popular scam in action. The good news is that looking at the images can't infect your device with malware.

We cover how the MrBeast scam works, why good antivirus software often misses the malware behind it, and the order to follow if your own accounts are sending it.

In this article
What is the MrBeast scam?
Is it safe to click the MrBeast scam images?
How the MrBeast scam works
Why antivirus doesn't always catch infostealers
What to do if you fell for the MrBeast scam
How to avoid infostealer malware
Bottom line: the MrBeast scam
FAQs

What is the MrBeast scam?

The MrBeast scam is a fake giveaway sent from real, hijacked social media accounts. The messages follow a pattern: MrBeast is giving away $2,500, claim your reward, you've been selected, or an offer of free credits at an online casino. They arrive as images rather than links, sent to everyone in the account's contact list and every server it belongs to.

Attackers take over established accounts instead of building new ones, because a profile with a real friend list and real server history doesn't get flagged the way a new account would. The owner usually finds out when friends start asking about it.

MrBeast isn't a random choice. Bitdefender points to his reach with kids and teenagers as what makes him an effective lure. He also isn't the only face used. RaidProtect, which makes a moderation bot for Discord, reports the same campaigns running with Elon Musk, Andrew Tate, and the streaming brands Kick and Stake.

It isn't only a Discord problem either. People in r/antivirus and r/cybersecurity_help describe the same posts appearing on Instagram, Facebook, Messenger, Steam, Roblox, Riot, Microsoft, Xbox, and EA accounts, often several at once.

RaidProtect provides the clearest numbers. As of July 1, 2026, across the 375,000 Discord servers running its bot, the company says it had deleted 4 million scam images and identified 160,000 hijacked Discord accounts since mid-February. That count of hijacked accounts doubled in June, after doubling in May.[1] Those are the company's own figures from its own detection product, not independently audited ones, and they cover only servers running that bot rather than all of Discord.

Focuses on Scam Prevention, Not Just Protection
5.0
Editorial Rating
Claim Deal
On Bitdefender's website
2026 Editors’ Choice
Best Antivirus for Scam Protection
Antivirus Software
Bitdefender
PROMOTION: Save 50%
  • Consistently receives top scores across all third-party testers
  • Comprehensive scam protection, including AI-powered Scam Copilot and phishing defense
  • Includes extra features like safe banking, VPN, and more

Is it safe to click the MrBeast scam images?

Yes. Clicking an image to view it full size is still just looking at it, and that can't infect your device or take your account.

This is the question people ask most often and agree on least. One person in r/antivirus put it plainly: some people told him having the pictures render was enough to get hacked, while others said they were harmless, and he couldn't tell who was right.[2]

Here's why viewing them is safe:

  • The images are the advertisement, not the attack. Aryeh Goretsky, a veteran malware researcher who answers questions in r/antivirus, explains that looking at the screenshots does nothing. Only the web addresses printed inside them lead anywhere, and you'd have to type one in by hand.[3]
  • A picture isn't a program. These are screenshots. The payload is the web address printed on them, not the file itself.
  • Check the file name if you saved it. A real .jpg or .png is inert. Anything ending in .exe, .scr, or .bat is a program, and that's the file that does the damage.

The real risk is a file disguised as an image, usually with a doubled extension like .png.exe. That's something you download and run, not something you look at. If you saved the image instead of just viewing it, check the full file name before you open it.

So if you only saw the images, you're fine. Don't type in the address, and tell your friend their account is compromised.

How the MrBeast scam works

The scam has two halves that people tend to mix up. The infection happens on someone's computer. The MrBeast messages happen afterward, from a different machine entirely.

The sequence runs like this.

  1. Someone runs an infostealer on their device. The malware collects saved passwords, browser cookies, session tokens, and crypto wallet files, then usually deletes itself.
  2. Attackers use those stolen sessions to log in, then run automated tools that push the giveaway images to the victim's whole contact list before the owner or the platform can step in.
  3. Anyone who types in the address lands on a fake crypto or casino site that takes their money, or serves them the same malware.

The sites themselves take a few forms. Some are fake crypto casinos using a celebrity's logo, some promise free coins or credits, and some are straightforward phishing pages. What they ask for varies: connect a wallet, scan a QR code, download software to claim a prize, or log in with an account you already have. Any of those hands over either money or the credentials to get it.

What is a session token?

A session token is the credential behind "remember this device." It's what lets you open Discord or Instagram without logging in every time.

When someone steals that token, they don't need your password, and in many cases they don't need your second factor either, because the service sees a device it already trusts.[4] That's why people in these threads describe accounts posting scam images while multi-factor authentication was switched on the whole time, with no login alert.

Revoking a session tells a service to forget every device that's currently logged in, including the attacker's. It's a separate action from changing your password. Look for a setting called active sessions, devices, or where you're logged in; sign out of everything; then log back in only on a device you trust.

Why the scam sends screenshots instead of links

This is what makes the campaign work, and two independent sources point in the same direction.

Goretsky explains that real links are easy to filter automatically, so putting the web address inside a photograph makes it harder to read and block, including by software that scans images for text. The victim has to retype it, which costs the scammers reach but buys them survival.[3]

RaidProtect's data supports that. The company describes scammers splitting a single scam across combined image formats to defeat detection, moving from four images to two to three, and says it caught the three-image version during a burst of more than 2,000 images in a matter of minutes.[5]

How people get infostealer malware

The entry point is almost always something downloaded and run. Bitdefender lists game mods, cracked software, cheating tools, malicious browser extensions, and phishing as the common routes, and the accounts people give in these threads match:

  • Game mods and trainers, including mods for Crimson Desert and GTA San Andreas and a trainer for Dragon Ball Z Kakarot
  • Cracked software and key generators, including one for a version of Paint Shop Pro from 2004
  • Pirated games, including a Sims 4 DLC unlocker, titles from steamunlocked, and a Mario Kart 8 ROM
  • Fake CAPTCHA pages that instruct you to paste a command into Windows PowerShell
  • Fake Discord servers that ask you to "verify" through a bot or a login page

Not every case involves malware. One person entered their credentials on a fake Discord login page, and that alone was enough.

Why antivirus doesn't always catch infostealers

A clean scan after the fact doesn't mean nothing was taken, and that is where many people get a false sense of safety.

  • The malware is usually gone before you scan. Infostealers typically delete themselves within seconds or a couple of minutes, which makes them harder to identify afterward.
  • Detection isn't recovery. Even when antivirus software works exactly as designed and quarantines the file, your passwords and session tokens have already left the machine. Removing the malware doesn't call them back.
  • Settings may have been changed. Infostealers can alter security and network settings, and security software often can't judge what your settings should have been. One r/antivirus poster found his Windows hosts file modified alongside the detected files.[6]

That last point is the usual argument for wiping a machine even when scans come back clean.

What to do if you fell for the MrBeast scam

Order matters more than any single step. One person in r/antivirus formatted his PC but didn't change his passwords afterward, and the spam kept going until he did.[7]

1. Stop using the affected device

Work from a phone, tablet, or a different computer. Changing passwords on a machine that may still be compromised could hand the new ones straight back.

2. Secure your email first

Your email is the reset path for everything else, and an attacker who controls it can undo whatever you fix downstream. Give it a new, unique password and turn on multi-factor authentication before you touch anything else.

3. Log out all sessions, then change passwords

This is the step most people skip, and it's the one that cuts off a stolen token. On Discord, go to User Settings > Devices and log out the sessions you don't recognize. On Instagram, use Accounts Center > Password and security > Where you're logged in. Change the password after you've revoked the sessions, not before.

4. Turn on app-based multi-factor authentication

Token theft can get around MFA, which has led some people to write it off. It's still worth having, because it blocks the ordinary password-based takeovers that follow when stolen credentials get resold. Use an authenticator app rather than SMS or email, since attackers may have reached both.

5. Check for access the attackers left behind

This can explain accounts that start spamming again weeks later. Remove any Discord applications you don't recognize, then check each service for OAuth connections, mail forwarding rules, linked devices, and recovery emails or phone numbers that aren't yours. Removing malware doesn't remove any of these.

6. Decide whether to reinstall Windows

If the device ran an infostealer, a clean reinstall from a USB drive made on a different computer is the safest option. Your documents, photos, and game saves can generally come with you on external storage. Programs, installers, and anything executable shouldn't, and neither should whatever you downloaded right before the trouble started.

Tell your contacts not to click anything your account sent while it was out of your hands.

5.0
2026 Editors’ Choice
Best Antivirus for Scam Protection
Antivirus Software
Bitdefender
  • Top-rated antivirus that regularly earns top scores on AV-TEST across Windows, macOS, and Android
  • Passed every malware, drive-by download, and phishing detection test we ran, blocking threats instantly
  • Blocks and reverses ransomware attacks on Windows, restoring your files automatically
Learn More

How to avoid infostealer malware

Nearly every case is traced back to running something from an untrusted source.

  • Get mods and patches from established sites with moderation, and skip anything a stranger sends you directly.
  • Treat cracked software as the main risk. It's the common thread in most of these reports, and a free download of paid software is the oldest delivery method.
  • Never paste a command into PowerShell because a web page told you to. No real CAPTCHA asks for that. This one is worth teaching younger family members by name.
  • Use a password manager so one stolen password doesn't open everything else.
  • Keep real-time protection on. It won't undo a theft that already happened, but our testing of the best antivirus software covers which products block these files before they run.

We've broken down how this class of malware behaves in plain language in our explainers on WordListLoader, the CrashStealer infostealer targeting Macs, and infostealers hidden in Roblox downloads.

Bottom line: the MrBeast scam

MrBeast isn't giving away $2,500, and your friend didn't send you those pictures. An infostealer took their session token, and criminals used it to post from an account people already trust.

If you only looked at the images, nothing happened to you. If your own accounts sent them, you're already hacked. Move to a clean device, secure your email, revoke active sessions before changing passwords, then check for authorized apps and forwarding rules the attackers may have left behind.

The MrBeast scam has been circulating for over a year, and the reports climbed sharply through spring 2026. New posts are still going up daily, so it's worth knowing what it looks like before it reaches someone you know.

FAQs

Can I get hacked by clicking the MrBeast scam images?

Clicking to view the image in Discord or Instagram is generally safe. Discord stores and serves its own copy of the file, and a standard image doesn't run code. The risk comes from downloading a file that looks like an image but has a double extension, like .png.exe, and then running it. Check the full file name before opening anything you saved. 

Do I have to reinstall Windows?

Not always, but it's the safest option if you ran an unknown file. Infostealers often delete themselves, and they may change security or network settings that antivirus software can't evaluate, so a clean scan isn't proof the machine is clean. Reinstall from a USB drive created on a different computer.

Can I keep my files if I reinstall?

Usually. Documents, photos, and game saves can be copied to external storage first. Leave behind programs, installers, and anything executable, especially whatever you downloaded just before the problem started.

Why did the scam posts come back after I deleted them?

Most likely the attackers still hold access somewhere you haven't checked. Look for authorized Discord applications, OAuth connections, mail forwarding rules, linked devices, and recovery emails or phone numbers you didn't add. Wiping a computer doesn't clear any of those.

Is changing my password enough?

Often not on its own. If someone has an active session token, they may stay logged in through a password change. Revoke all active sessions first, then change the password, and do both from a device you trust.

Does multi-factor authentication stop the MrBeast scam?

It helps, but it isn't complete protection. A stolen session token can let someone in without triggering the second factor, because the service already recognizes the device. Keep it turned on anyway, and use an authenticator app instead of text messages.

Is Mr. Beast actually giving away money?

He has run real giveaways through his own channels, which is what makes the fake ones effective. Anything that reaches you as a DM, a story, or a screenshot with a website address is a scam. Check his official accounts directly before believing any offer.


Top-of-the-Line Defense Against the Toughest Threats
5.0
Editorial Rating
Claim Deal
On Bitdefender's website
2026 Editors’ Choice
Best Antivirus for Scam Protection
Antivirus Software
Bitdefender
PROMOTION: Save 50%
  • Consistently receives top scores across all third-party testers
  • Comprehensive scam protection, including AI-powered Scam Copilot and phishing defense
  • Includes extra features like safe banking, VPN, and more
Author Details
Kate Quinlan is a Senior Editor at All About Cookies, where she has tested dozens of digital security tools and contributed to more than 370 articles spanning web hosting, VPNs, ad blockers, parental controls, and data security. Before joining AAC, she managed a team of more than 150 writers at SuperSummary, where she developed editorial standards at scale. She holds a B.A. in Professional Writing from Kutztown University.

Citations

[1] RaidProtect, June 2026 threat report

[2] r/antivirus, "How does the Mr. Beast scam spreads itself by sending screenshots?"

[3] Comment by Aryeh Goretsky, r/antivirus, August 5, 2026

[4] Bitdefender, "Hackers are using stolen Discord accounts to spread fake MrBeast giveaways"

[5] RaidProtect, May 2026 threat report

[6] r/antivirus, "I got infected by the mrbeast crypto scam"

[7] r/antivirus, "Mr. Beast Scam strikes again."