A post rockets across your timeline: "๐ We're giving away 50 PS5s โ retweet, follow, and click the link to claim your entry!" It has thousands of retweets, a countdown, and a slick graphic. But the reason it spread so fast isn't excitement โ it's that the "claim" link quietly turned every clicker into a broadcaster for the next round. Wormable giveaway scams don't just fool one person at a time; they weaponize your own account to reach your followers. Here's how they work and how to shut them down.
How the worm hijacks your account to repost itself
The dangerous versions of "retweet to win" don't stop at asking you to retweet. The claim link sends you to a page that looks like a giveaway portal, then asks you to "connect your account" or "authorize to verify your entry." That authorization screen is a real OAuth prompt โ but the app requesting access is malicious, and the permissions it wants include posting on your behalf and reading your DMs. Approve it and you've handed a stranger a key to your account without ever typing your password.
From there it's automated. The rogue app posts the same giveaway from your account, replies to your followers with it, and sometimes DMs your contacts โ each new victim adds another trusted-looking amplifier, which is exactly why these things go viral. The scam is self-propagating: it grows because the mechanism of "winning" is the mechanism of spreading. If you ever see the exact giveaway posted from a friend's normally-quiet account, that's not enthusiasm, that's an infection. ๐ชฑ
Masked shorteners and the "off-platform claim" red flag
Scammers hide the destination behind URL shorteners โ bit.ly, tinyurl, cutt.ly, or throwaway lookalike domains like ps5-giveaway-claim[.]net. The short link masks a redirect chain that can end on a fake login, an OAuth trap, or a drive-by download disguised as an "entry app." Never trust the words on the button; the button text and the real destination are set by different people. On most platforms you can long-press or hover a link to preview where it actually goes before tapping.
Here's the rule that cuts through all of it: a legitimate giveaway never requires you to click an off-platform link to "claim" or "activate" your entry. Real promotions on X, Instagram, or Facebook run inside the platform โ you like, follow, retweet, or comment, and that's the entry. The winner is contacted later by the real host. Any post that pushes you to an external site to "verify," "unlock," or "secure" your entry before the giveaway even ends is manufacturing urgency to get your click. That external claim step exists to harvest something โ an authorization, a password, or a malware install.
If you already clicked, contain it fast
Move quickly, because the app keeps working while you hesitate. First, revoke the rogue app's access: in X, go to Settings โ Security and account access โ Apps and sessions โ Connected apps, and remove anything you don't recognize. Do the same on any account you authorized through that page. This alone stops most of the auto-posting, because the worm runs on the token you granted, not your password.
Then change your password, turn on two-factor authentication if it wasn't already, and delete the scam posts and DMs the app sent from your account so you stop infecting others. Report the original post to the platform so it can be taken down at the source. If you entered credentials on a fake login rather than using OAuth, treat that password as compromised everywhere you reused it and reset those accounts too.
Never authorize an app or click an off-platform link to "claim" a giveaway โ real ones are won inside the platform, not on a page that wants access to your account.