BUSINESS SCENARIO LIBRARY

A collection of representative B2B lead discovery scenarios, showing how AI identifies qualified sales opportunities from real-world business conversations.

SCENARIO 317Web3 projects

The Same Admin Name Appeared in Three Groups. Which Source Should a Web3 Security Provider Trace First?

Three Telegram groups mention the same admin name — a Web3 brand-security provider sales lead must tell whether one screenshot is circulating or separate impersonation accounts exist before messaging the project's security owner.

Business stage
Initial cross-group impersonation triage
Lead quality
★★★★☆
Typical buyer
Web3 brand-security provider sales lead
Estimated intent
High · urgent risk, independent sourcing unconfirmed
Illustrative scenario

This is an illustrative scenario designed to explain the product’s judgement logic. It is not a real customer case, testimonial, contract, revenue result, or conversion claim.

HOW TO READ THIS SCENARIO

01Situation

02Signal judgement

03Confidence vs priority

04Human next step

Signals considered

  • Similar account reports appear across groups
  • Reports preserve account handles and links
  • Independent moderators provide separate sources

This is a simulated composite scenario. Its messages, numbers, deadlines and business circumstances are illustrative and do not represent a real customer, conversation, contract or result.

Three Telegram groups, one admin name, one open question: how many of these mentions are independent evidence, and how many are the same screenshot touring the ecosystem? For a Web3 brand-security provider sales lead, that question lands on a Tuesday morning with a calendar already full and a project team that answers fast whenever their name shows up in a chat.

The scene below is composite: three groups, two screenshots, one text-only warning, one admin display name. It does not describe a real customer or incident, and every timestamp is illustrative. What is not illustrative is the decision: I either send the project’s security owner a note that reads “three groups reported your admin name” before noon, or I spend the morning tracing each mention to its origin first. The note I send becomes the opening of the first security-service conversation with that project — or the opening of a conversation built on a count that meant nothing.

The three groups sit in different parts of the ecosystem: the project’s own community chat, a trading group we watch, and a regional news channel. Nothing connects them except the name. That is exactly why the count feels urgent, and exactly why it should not be trusted yet.

Draw the source tree before you count the reports

A source tree is a map of who posted first and who copied later. One root with three branches is one incident; three roots are three incidents. Sales instinct says three mentions are three reasons to open a conversation. The tree often says the opposite: if two mentions are the same post pasted twice, the project team will see one fact dressed up as three, and the credibility of the note collapses.

For each mention, fill four fields before deciding anything:

  • Account handle: the @username, not the display name. A display name in Telegram is text that anyone can change; the username is stickier. Three groups may quote the same display name while pointing at different handles — that difference is itself a finding.
  • Message link: Telegram’s t.me/… link for the post. It names the channel and the message ID, which lets you check whether two mentions point at the same post.
  • First-seen time: when your monitoring first recorded it, not when the post claims to be from. Screenshots can carry an older internal clock than the moment they were pasted.
  • Repost relationship: what the post says it was copied from — a forward marker, a caption, or nothing.

Unknowns go into the tree as well: who posted first is often invisible, a screenshot may have had its forward header cropped, and two groups that look unrelated can share an operator. The tree is honest about what it does not know. The count is not.

Read the forward chain: one screenshot or three accounts?

Three kinds of posts behave differently in a tree:

  • Original post: a message that appears in a group without a forward marker and with the earliest credible timestamp. It is the root.
  • Screenshot forward: a picture pasted into another group, sometimes with a “forwarded from” marker, sometimes re-screenshotted until the marker is gone.
  • Independent report: a warning whose wording, handle or timestamp does not come from any other mention.

The observable checks are mechanical. Do the screenshots share the same chat background, avatar set and timestamp? If yes, they are copies of one original, whatever the captions say. Do the message links point to different channels with different message IDs? If yes, the posts are physically separate, even when they look similar. Is the text-only report worded differently from the captions on the screenshots? If yes, it is a candidate for an independent source.

The middle case is where most of the time goes: one screenshot circulating with new captions attached at each stop. The caption is a comment, not a new source. Counting the comments as evidence would turn one incident into four.

What remains unknown in every forward chain: a clean-looking post may itself be a copy of a deleted original; timestamps can be edited inside a screenshot; and the account behind the display name cannot be identified from the name alone. Telegram display names are not identity — that fact carries the whole weight of the decision later.

What observation can confirm, and what it cannot

Impersonation and fraud are different claims. Impersonation means an account presents itself under a name it does not own. Fraud means someone was actually deceived. Observation can support the first; only the project team — or the account owner — can verify the second. A sales lead who writes “this account is a scammer” without verification is asserting a fact the record does not contain.

What the record can confirm: where the name appeared, when, under which handle, and which posts are copies of which. What it cannot confirm: whether the account is operated by an impersonator, whether anyone has been approached or harmed, and whether the project already knows. Silence, an old screenshot, or a display name that matches are not proof of any of those.

Organizing the record is where tooling enters the scene. Top Prospect works only with Telegram groups a sales lead deliberately connects and is authorized to access; it preserves the original message, its source and the surrounding context, deduplicates copies of the same post, and returns a classification for human review. It does not automatically contact group members or anyone else, and it certifies neither buying intent nor that an account committed fraud. The call about who to message stays with the sales lead.

When to open a security-service conversation — and when to watch instead

A conversation with the project’s security owner is justified when you can attach a tree: one verifiable original, a mapped forward chain, and a short list of open questions. A restrained first message can carry all three:

“Hi — brand-risk note on the admin display name @meridian_ops. Three groups mentioned it this week: two posts look like the same screenshot (links below), one is a text-only report. I cannot confirm whether the account is an impersonator or whether anyone has been approached. Want me to keep watching, or should we review what is visible so far?”

The message reports, labels its unknowns, and asks. It does not assert, and it does not promise a fix.

Observation is the only responsible step when the record cannot support even that message. That happens when the only copy is an unverifiable screenshot with no link, when the single source is a group operated by the very account being reported, or when the project has already acknowledged the name and is handling it — in which case a new report adds noise, not value.

By early afternoon, the note that actually went out contained a tree, not a count: one original post, one copy, one independent text report, and one open question about the account behind the display name. That is the whole difference between “three groups reported your admin” and “here is what we can see and what we cannot.” The second version opens a conversation even when the answer is: keep watching. The tree stays on the desk either way — it is the thing that turns three mentions into one judgement the project can check.