Scam pictures
Hacked accounts post the same scam picture — a fake crypto-casino withdrawal, a giveaway — in every channel. SUPREO removes it and acts on the account.
Do this on my dashboardA hacked account rarely posts text any more: it posts a picture — a screenshot of a "withdrawal success" on a crypto casino, a celebrity "giveaway", a promo code — and it posts it in every channel it can see. Text filters never look inside a picture. The scam-picture filter does.
It is on by default, on every plan, and needs no setup. Its settings have their own page: Scam pictures, under Community.
How a scam picture is recognised
- Known scams. Every picture is reduced to fingerprints: short codes that stay the same when the picture is resized or recompressed, and from which the picture cannot be rebuilt. They are compared to SUPREO's shared list of confirmed scam pictures.
- Variants of known scams. The same scam cropped (a browser bar or a side cut off), with a border or more screen around it, or edited — another amount, another username, a sticker — still matches: SUPREO also compares the parts of each picture. A variant found this way joins the review queue, so its exact copies are recognised next time. Logos, icons and flat pictures are only ever matched as exact copies, never as variants: they look too much alike.
- Floods (on by default). The same picture posted by one account in 3 channels within 30 seconds — what a hacked account does — is removed even if nobody has seen it before, with the copies already posted.
- Text in the picture (Premium, off by default). SUPREO reads the text of the picture and recognises a scam from what it says: a crypto withdrawal, a promo code, a casino bonus, a giveaway. It also compares the text with the known scams, which catches what a fingerprint cannot: a phone photo of the screen, a screenshot taken again, a scam pasted into a bigger image. It catches new campaigns before anyone reports them. English text.
The shared list grows from every server: pictures the honeypot catches, floods and text matches join a review queue, and the SUPREO team confirms or rejects them. A picture caught by the honeypot on two servers, or found on three, is confirmed by itself. Only confirmed pictures are acted on everywhere.
What happens
- The picture is deleted — in a flood, every copy.
- The member gets a DM explaining why, if DM the account to explain why is on.
- The action applies to the account, once per flood.
- The catch is listed under Recent catches on the Scam pictures page, with how it was spotted, and posted in the log channel if you set one.
Action on the account is, by default, the same as the honeypot — a softban unless you changed it — or a 24-hour timeout on a server without a honeypot. You can pick another: softban, ban, kick, timeout, or Log only.
Who is never checked
Bots, the server owner, administrators, staff with Manage Messages, and the roles in Exempt roles (the honeypot's exempt roles count too). Only pictures are looked at — PNG, JPEG, WebP and GIF, up to 8 MB, four per message.
Settings
| Setting | Default |
|---|---|
| Remove scam pictures | On |
| What counts as a scam — known scams only, or known scams and floods | Known scams and floods |
| Read the text in pictures (Premium) | Off |
| Action on the account | Same as the honeypot |
| DM the account to explain why | On |
| Exempt roles, Log channel | None |
The bot needs Manage Messages to delete the picture, and the permission for the action (Ban Members, Kick Members or Moderate Members). The Scam pictures page warns when one is missing.
Privacy
Pictures are checked as they are posted and are not stored. For a picture identified as a likely scam, SUPREO keeps its fingerprint and, while it is reviewed, a small thumbnail for up to 14 days. The catch itself is kept 90 days, like a honeypot catch. See Data & privacy.
Honeypot
A bait channel your members are told never to write in. Spam bots post everywhere they can — their first message there gives them away, and SUPREO acts.
Verification
New members prove they are human before they can talk — a button, a captcha inside Discord, or a web check with alt detection — and members who never pass can be removed.
