All About Cookies is an independent, advertising-supported website. Some of the offers that appear on this site are from third-party advertisers from which All About Cookies receives compensation. This compensation may impact how and where products appear on this site (including, for example, the order in which they appear).
All About Cookies does not include all financial or credit offers that might be available to consumers nor do we include all companies or all available products. Information is accurate as of the publishing date and has not been provided or endorsed by the advertiser.
The All About Cookies editorial team strives to provide accurate, in-depth information and reviews to help you, our reader, make online privacy decisions with confidence. Here's what you can expect from us:
- All About Cookies makes money when you click the links on our site to some of the products and offers that we mention. These partnerships do not influence our opinions or recommendations. Read more about how we make money.
- Partners are not able to review or request changes to our content except for compliance reasons.
- We aim to make sure everything on our site is up-to-date and accurate as of the publishing date, but we cannot guarantee we haven't missed something. It's your responsibility to double-check all information before making any decision. If you spot something that looks wrong, please let us know.
A friend messages you on Discord, or a story shows up on their Instagram. It's a few screenshots of MrBeast handing out $2,500, with a website address printed across the picture.
The bad news is that your friend didn't actually send the messages, and you're looking at a popular scam in action. The good news is that looking at the images can't infect your device with malware.
We cover how the MrBeast scam works, why good antivirus software often misses the malware behind it, and the order to follow if your own accounts are sending it.
Is it safe to click the MrBeast scam images?
How the MrBeast scam works
Why antivirus doesn't always catch infostealers
What to do if you fell for the MrBeast scam
How to avoid infostealer malware
Bottom line: the MrBeast scam
FAQs
What is the MrBeast scam?
The MrBeast scam is a fake giveaway sent from real, hijacked social media accounts. The messages follow a pattern: MrBeast is giving away $2,500, claim your reward, you've been selected, or an offer of free credits at an online casino. They arrive as images rather than links, sent to everyone in the account's contact list and every server it belongs to.
Attackers take over established accounts instead of building new ones, because a profile with a real friend list and real server history doesn't get flagged the way a new account would. The owner usually finds out when friends start asking about it.
MrBeast isn't a random choice. Bitdefender points to his reach with kids and teenagers as what makes him an effective lure. He also isn't the only face used. RaidProtect, which makes a moderation bot for Discord, reports the same campaigns running with Elon Musk, Andrew Tate, and the streaming brands Kick and Stake.
It isn't only a Discord problem either. People in r/antivirus and r/cybersecurity_help describe the same posts appearing on Instagram, Facebook, Messenger, Steam, Roblox, Riot, Microsoft, Xbox, and EA accounts, often several at once.
RaidProtect provides the clearest numbers. As of July 1, 2026, across the 375,000 Discord servers running its bot, the company says it had deleted 4 million scam images and identified 160,000 hijacked Discord accounts since mid-February. That count of hijacked accounts doubled in June, after doubling in May.[1] Those are the company's own figures from its own detection product, not independently audited ones, and they cover only servers running that bot rather than all of Discord.
Is it safe to click the MrBeast scam images?
Yes. Clicking an image to view it full size is still just looking at it, and that can't infect your device or take your account.
This is the question people ask most often and agree on least. One person in r/antivirus put it plainly: some people told him having the pictures render was enough to get hacked, while others said they were harmless, and he couldn't tell who was right.[2]
Here's why viewing them is safe:
- The images are the advertisement, not the attack. Aryeh Goretsky, a veteran malware researcher who answers questions in r/antivirus, explains that looking at the screenshots does nothing. Only the web addresses printed inside them lead anywhere, and you'd have to type one in by hand.[3]
- A picture isn't a program. These are screenshots. The payload is the web address printed on them, not the file itself.
- Check the file name if you saved it. A real .jpg or .png is inert. Anything ending in .exe, .scr, or .bat is a program, and that's the file that does the damage.
The real risk is a file disguised as an image, usually with a doubled extension like .png.exe. That's something you download and run, not something you look at. If you saved the image instead of just viewing it, check the full file name before you open it.
So if you only saw the images, you're fine. Don't type in the address, and tell your friend their account is compromised.
How the MrBeast scam works
The scam has two halves that people tend to mix up. The infection happens on someone's computer. The MrBeast messages happen afterward, from a different machine entirely.
The sequence runs like this.
- Someone runs an infostealer on their device. The malware collects saved passwords, browser cookies, session tokens, and crypto wallet files, then usually deletes itself.
- Attackers use those stolen sessions to log in, then run automated tools that push the giveaway images to the victim's whole contact list before the owner or the platform can step in.
- Anyone who types in the address lands on a fake crypto or casino site that takes their money, or serves them the same malware.
The sites themselves take a few forms. Some are fake crypto casinos using a celebrity's logo, some promise free coins or credits, and some are straightforward phishing pages. What they ask for varies: connect a wallet, scan a QR code, download software to claim a prize, or log in with an account you already have. Any of those hands over either money or the credentials to get it.
What is a session token?
A session token is the credential behind "remember this device." It's what lets you open Discord or Instagram without logging in every time.
When someone steals that token, they don't need your password, and in many cases they don't need your second factor either, because the service sees a device it already trusts.[4] That's why people in these threads describe accounts posting scam images while multi-factor authentication was switched on the whole time, with no login alert.
Why the scam sends screenshots instead of links
This is what makes the campaign work, and two independent sources point in the same direction.
Goretsky explains that real links are easy to filter automatically, so putting the web address inside a photograph makes it harder to read and block, including by software that scans images for text. The victim has to retype it, which costs the scammers reach but buys them survival.[3]
RaidProtect's data supports that. The company describes scammers splitting a single scam across combined image formats to defeat detection, moving from four images to two to three, and says it caught the three-image version during a burst of more than 2,000 images in a matter of minutes.[5]
How people get infostealer malware
The entry point is almost always something downloaded and run. Bitdefender lists game mods, cracked software, cheating tools, malicious browser extensions, and phishing as the common routes, and the accounts people give in these threads match:
- Game mods and trainers, including mods for Crimson Desert and GTA San Andreas and a trainer for Dragon Ball Z Kakarot
- Cracked software and key generators, including one for a version of Paint Shop Pro from 2004
- Pirated games, including a Sims 4 DLC unlocker, titles from steamunlocked, and a Mario Kart 8 ROM
- Fake CAPTCHA pages that instruct you to paste a command into Windows PowerShell
- Fake Discord servers that ask you to "verify" through a bot or a login page
Not every case involves malware. One person entered their credentials on a fake Discord login page, and that alone was enough.
Why antivirus doesn't always catch infostealers
A clean scan after the fact doesn't mean nothing was taken, and that is where many people get a false sense of safety.
- The malware is usually gone before you scan. Infostealers typically delete themselves within seconds or a couple of minutes, which makes them harder to identify afterward.
- Detection isn't recovery. Even when antivirus software works exactly as designed and quarantines the file, your passwords and session tokens have already left the machine. Removing the malware doesn't call them back.
- Settings may have been changed. Infostealers can alter security and network settings, and security software often can't judge what your settings should have been. One r/antivirus poster found his Windows hosts file modified alongside the detected files.[6]
That last point is the usual argument for wiping a machine even when scans come back clean.
What to do if you fell for the MrBeast scam
Order matters more than any single step. One person in r/antivirus formatted his PC but didn't change his passwords afterward, and the spam kept going until he did.[7]
1. Stop using the affected device
Work from a phone, tablet, or a different computer. Changing passwords on a machine that may still be compromised could hand the new ones straight back.
2. Secure your email first
Your email is the reset path for everything else, and an attacker who controls it can undo whatever you fix downstream. Give it a new, unique password and turn on multi-factor authentication before you touch anything else.
3. Log out all sessions, then change passwords
This is the step most people skip, and it's the one that cuts off a stolen token. On Discord, go to User Settings > Devices and log out the sessions you don't recognize. On Instagram, use Accounts Center > Password and security > Where you're logged in. Change the password after you've revoked the sessions, not before.
4. Turn on app-based multi-factor authentication
Token theft can get around MFA, which has led some people to write it off. It's still worth having, because it blocks the ordinary password-based takeovers that follow when stolen credentials get resold. Use an authenticator app rather than SMS or email, since attackers may have reached both.
5. Check for access the attackers left behind
This can explain accounts that start spamming again weeks later. Remove any Discord applications you don't recognize, then check each service for OAuth connections, mail forwarding rules, linked devices, and recovery emails or phone numbers that aren't yours. Removing malware doesn't remove any of these.
6. Decide whether to reinstall Windows
If the device ran an infostealer, a clean reinstall from a USB drive made on a different computer is the safest option. Your documents, photos, and game saves can generally come with you on external storage. Programs, installers, and anything executable shouldn't, and neither should whatever you downloaded right before the trouble started.
Tell your contacts not to click anything your account sent while it was out of your hands.
How to avoid infostealer malware
Nearly every case is traced back to running something from an untrusted source.
- Get mods and patches from established sites with moderation, and skip anything a stranger sends you directly.
- Treat cracked software as the main risk. It's the common thread in most of these reports, and a free download of paid software is the oldest delivery method.
- Never paste a command into PowerShell because a web page told you to. No real CAPTCHA asks for that. This one is worth teaching younger family members by name.
- Use a password manager so one stolen password doesn't open everything else.
- Keep real-time protection on. It won't undo a theft that already happened, but our testing of the best antivirus software covers which products block these files before they run.
Bottom line: the MrBeast scam
MrBeast isn't giving away $2,500, and your friend didn't send you those pictures. An infostealer took their session token, and criminals used it to post from an account people already trust.
If you only looked at the images, nothing happened to you. If your own accounts sent them, you're already hacked. Move to a clean device, secure your email, revoke active sessions before changing passwords, then check for authorized apps and forwarding rules the attackers may have left behind.
The MrBeast scam has been circulating for over a year, and the reports climbed sharply through spring 2026. New posts are still going up daily, so it's worth knowing what it looks like before it reaches someone you know.
FAQs
Can I get hacked by clicking the MrBeast scam images?
Clicking to view the image in Discord or Instagram is generally safe. Discord stores and serves its own copy of the file, and a standard image doesn't run code. The risk comes from downloading a file that looks like an image but has a double extension, like .png.exe, and then running it. Check the full file name before opening anything you saved.
Do I have to reinstall Windows?
Not always, but it's the safest option if you ran an unknown file. Infostealers often delete themselves, and they may change security or network settings that antivirus software can't evaluate, so a clean scan isn't proof the machine is clean. Reinstall from a USB drive created on a different computer.
Can I keep my files if I reinstall?
Usually. Documents, photos, and game saves can be copied to external storage first. Leave behind programs, installers, and anything executable, especially whatever you downloaded just before the problem started.
Why did the scam posts come back after I deleted them?
Most likely the attackers still hold access somewhere you haven't checked. Look for authorized Discord applications, OAuth connections, mail forwarding rules, linked devices, and recovery emails or phone numbers you didn't add. Wiping a computer doesn't clear any of those.
Is changing my password enough?
Often not on its own. If someone has an active session token, they may stay logged in through a password change. Revoke all active sessions first, then change the password, and do both from a device you trust.
Does multi-factor authentication stop the MrBeast scam?
It helps, but it isn't complete protection. A stolen session token can let someone in without triggering the second factor, because the service already recognizes the device. Keep it turned on anyway, and use an authenticator app instead of text messages.
Is Mr. Beast actually giving away money?
He has run real giveaways through his own channels, which is what makes the fake ones effective. Anything that reaches you as a DM, a story, or a screenshot with a website address is a scam. Check his official accounts directly before believing any offer.
[1] RaidProtect, June 2026 threat report
[2] r/antivirus, "How does the Mr. Beast scam spreads itself by sending screenshots?"
[3] Comment by Aryeh Goretsky, r/antivirus, August 5, 2026
[4] Bitdefender, "Hackers are using stolen Discord accounts to spread fake MrBeast giveaways"
[5] RaidProtect, May 2026 threat report
[6] r/antivirus, "I got infected by the mrbeast crypto scam"