A phishing check gmgn search usually comes from one of two situations: you saw a wallet tagged "Phishing" in a token's holder list and want to know what it means, or you are worried about being phished yourself while using GMGN. Both are legitimate concerns, and they are different problems. The tag is GMGN warning you about a wallet's behavior; the second is scammers targeting GMGN's users through fake bots, lookalike domains and fake airdrops, which is how roughly 107 users lost funds in October 2025.

This guide covers both. It explains what the Phishing flag means in GMGN's holder and wallet lists, walks through every check in the token security panel, explains honeypot detection, catalogs the ways scammers go after GMGN traders, and shows how to harden your account with Google Authenticator 2FA. It is an independent guide; GMGN AI App Guide is not affiliated with GMGN.

What does "Phishing" mean on GMGN?

In the GMGN AI app, every holder list and trade feed labels wallets with behavior tags. The documented tags are:

Tag Meaning
Smart Degen Wallet with a strong on-chain track record; feeds the Smart Money leaderboard
Bot Degen Automated trading behavior
Fresh wallet Newly created, little history; common in insider or bundler setups
Sniper Bought in the first blocks after launch
KOL Key opinion leader wallet linked to a known influencer
Phishing Wallet flagged for phishing-style behavior or a suspicious token
Dev sold The token creator's wallet has sold (shown as a status, not a wallet tag)

The Phishing tag is the one that alarms people. In GMGN's usage it marks a wallet flagged for phishing-style behavior, which typically means the address has been associated with scam patterns such as distributing unsolicited "airdrop" tokens that lead to drainer sites, address-poisoning transfers, or interaction with known drainer contracts. It can also appear where the token itself is suspicious.

What the tag does not mean:

  • It does not mean the token you are looking at has phished you.
  • It does not mean GMGN has been compromised.
  • It does not automatically make the token a scam, though a holder list with many Phishing-tagged wallets is a strong negative signal, because scammers often seed their own tokens into flagged wallets.

Treat it the way you would treat a Sniper or Fresh wallet tag: one input into whether the holder base looks organic. The GMGN wallet tracker guide explains how to read the full holder table.

What is a "jeet check" on GMGN?

"Jeet" is trader slang for someone who sells early, also called paper hands. There is no GMGN feature literally named "jeet check." What traders mean is reading the holder list for sold status, hold times and PnL per wallet to judge how much of the supply sits with early sellers. GMGN shows these behavior labels per holder, and the "Dev sold" status is the most important single one. A token whose top holders are all fresh wallets that have already partially sold is a very different proposition from one held by Smart Degen wallets still in position.

The GMGN security panel: every check explained

Every token page on GMGN has a security panel. Here is what each item is checking and why it matters. This is the real "phishing check" most users are looking for.

Check What it tells you Why it matters
Mint authority disabled No one can create new tokens If enabled, the dev can inflate supply to zero
Freeze / Blacklist Whether accounts can be frozen or blocked from selling The classic honeypot mechanism on Solana and EVM
Top-10 holder % Concentration in the ten largest wallets High concentration means a few wallets can dump on you
LP burned % Share of liquidity-pool tokens burned Unburned LP can be pulled (rug) at any time
Rug probability GMGN's aggregate risk estimate Heuristic; useful for triage, not a guarantee
Dev rug history Whether the deployer's past tokens rugged Serial ruggers repeat
Honeypot (ETH) Simulated sell fails on Ethereum Direct detection of unsellable tokens
Contract verified Source code published Unverified contracts hide tax and blacklist logic
Ownership renounced Owner can no longer change the contract Otherwise taxes and limits can be changed post-launch
Buy / sell tax Percentage taken on each side Sell taxes near 100% are honeypots by another name
Insiders Wallets holding pre-launch Pre-allocated supply waiting to dump
Snipers Wallets that bought in the first blocks Fast exits ahead of you
Bundlers Coordinated launch-buy bundles Manufactured early demand
Phishing flag Wallets flagged for phishing-style behavior Contaminated holder base
Dev sold The creator has sold Often the beginning of the end

Use the panel as a fast filter, not as insurance. A token can show LP burned, mint disabled and no honeypot and still collapse when insiders sell. The panel is strongest at catching the mechanical scams (freeze, tax, unverified contract) and weakest at catching social ones (coordinated dumps).

How GMGN honeypot detection works

A honeypot is a token you can buy but cannot sell. On Ethereum, GMGN runs a honeypot check that simulates a sell; if the simulation fails or returns with a near-total tax, the token is flagged. On Solana there is no equivalent contract-level tax logic, so the relevant checks are freeze authority and the blacklist flag: if the freeze authority is still enabled, the deployer can freeze your token account after you buy.

If you already hold a token and try to sell, GMGN reports the failure with a specific code. B4 means honeypot or blacklist, token unsellable; submission failures in the B series cost nothing because the transaction never executes. That is a small mercy. The full code list is in GMGN Trenches and sniper, and the most common non-scam failure, "No Available Router," has its own page at GMGN No Available Router.

The "gmgn honeypot" complaint you will see in forums is usually a user who bought on a chain where the check is weaker (Solana freeze authority not reviewed) or bought so early that the panel had not populated. Slow down by three seconds and read the panel before the first buy.

How scammers target GMGN users

Now the other meaning of "phishing gmgn": attacks on you. GMGN's user base is large, fast-moving and holds funds in hosted wallets, which makes it a prime target. The October 2025 campaign that hit about 107 users, with GMGN promising 100% compensation per Lookonchain, used several of the techniques below.

Fake Telegram bots

The official bots are @gmgnaibot (main), @GMGN_sol_bot, @GMGN_bsc_bot, @GMGN_swap_bot (Ethereum), @GMGN_base_bot and @GMGN_tron_bot. Scammers register handles that differ by a single character, swapping a capital I for a lowercase l, adding an underscore, or using "GMGN_sol_bot_official." GMGN's own guidance is to verify handles character by character. A fake bot will ask you to "verify your wallet" by pasting a seed phrase or private key. GMGN's bots never ask for either, and since GMGN wallets do not allow key export, there is nothing to paste. The real bot workflow is in GMGN Telegram bot.

Lookalike domains

There is no gmgn.io, gmgn.com or "gmgn ia" site. Known typosquats include app-gmgn-ai.com, gmgn-tracker and gmgn-app.at. Clones copy the login page pixel for pixel and forward your credentials or your 2FA code in real time. Type gmgn.ai yourself, bookmark it, and be suspicious of any GMGN link inside a Telegram group, a Discord DM or a search ad.

Fake airdrops, tokens and "rewards"

GMGN has no official token, coin, NFT, points program or airdrop as of September 2026. Co-founder Haze said in February 2025 that the team was "still discussing internally with no final conclusion." Roughly 50 "$GMGN" tokens exist on-chain, the largest under $5k market cap; every one is an imposter. Posts about "GMGN lucky spins," "100 SOL bonus" or "claim free SOL" are scams. The real rewards page is gmgn.ai/rewards and it is a referral dashboard. See GMGN token for the full picture.

Approval and "signature" transactions

If you use "Trade with Wallet" mode with Phantom or MetaMask, a phishing site can ask you to sign a token approval or a message that drains the wallet. GMGN's own advice is to beware "approval" transactions. The web terminal's hosted-wallet mode does not need you to sign approvals in your browser wallet; a request to do so on a "GMGN" page is a red flag.

Fake support

GMGN support is through the in-app ticket system and the official Telegram group t.me/gmgnai. There is no phone line. Anyone DMing you first claiming to be GMGN support, especially asking for 2FA codes or remote access, is a scammer. Real channels are listed in GMGN support.

Fake apps and extensions

The official apps are on gmgn.ai/app: iOS "GMGN - Meme Track" (seller GraceMatrix Technologies Limited) and Android "GMGN" (package com.gmgn.app, developer GMGN Labs Limited). GMGN documents no browser extension; "GMGN Quant" and similar extensions are unofficial and should be treated as credential-stealers until proven otherwise. Download guidance is in GMGN app download.

How to set up GMGN 2FA with Google Authenticator

Google Authenticator 2FA is mandatory for withdrawals and is the single most effective defense against account phishing. Set it up before you deposit.

  1. Log in at gmgn.ai and open Settings.
  2. Find the security or 2FA section and choose to bind Google Authenticator.
  3. Scan the QR code with Google Authenticator (or any TOTP app). Write down the backup secret and store it offline; if you lose your phone without it, recovery is painful.
  4. Enter the six-digit code to confirm the binding. Note that re-binding 2FA later triggers a 24-hour withdrawal hold.
  5. Add your own self-custody address to the withdrawal whitelist now. The first whitelist starts a 3-hour hold, so doing it before you need it means no delay later.
  6. Never enter a 2FA code into any page other than gmgn.ai, and never read one to anyone.

Withdrawals themselves are website-only; the Telegram bots cannot withdraw, which limits what a compromised Telegram session can do. Walkthrough in GMGN withdraw and export wallet.

GMGN bug bounty and security contact

GMGN runs a bug bounty program that pays in USDT and publishes security@gmgn.ai as its security contact. If you find a vulnerability in the platform, that address is the correct place to report it; do not post exploits publicly or DM team members on X. GMGN does not publish a detailed public reward tier list that we could verify as of September 2026, so do not expect a fixed price schedule.

The existence of a bounty is a modest positive signal. It does not replace the formal third-party audit that GMGN has not published; see is GMGN safe for the broader security picture.

Verified official GMGN domains and handles

Bookmark this list. Anything not on it is unverified.

  • Web: gmgn.ai (app), docs.gmgn.ai (documentation), gmgn.ai/blog, gmgn.ai/app (downloads), gmgn.ai/ai (API keys), gmgn.ai/rewards (referrals), papi.gmgn.ai (API host), gmgn.cc (chart embeds and support).
  • Social: X @gmgnai, Telegram t.me/gmgnai, GitHub github.com/GMGNAI.
  • Telegram bots: @gmgnaibot, @GMGN_sol_bot, @GMGN_bsc_bot, @GMGN_swap_bot, @GMGN_base_bot, @GMGN_tron_bot.
  • Email: security@gmgn.ai for security reports only.
  • Referral links: https://gmgn.ai/r/CODE and https://t.me/gmgnaibot?start=i_CODE are the only legitimate formats.

Not official: gmgn.io, gmgn.com, app-gmgn-ai.com, gmgn-tracker, gmgn-app.at, any "$GMGN" token, any browser extension, any Discord server not linked from the gmgn.ai footer.

Key takeaways

  • The Phishing tag on GMGN is a wallet-behavior flag in holder and trade lists, alongside Smart Degen, Sniper, Fresh wallet and KOL; many flagged holders is a bad sign for the token, but the tag itself is not an alert about your account.
  • The security panel's honeypot, freeze/blacklist, tax, LP burned and mint checks catch mechanical scams; insider and bundler dumps need judgment.
  • Error code B4 means GMGN detected a honeypot or blacklist at sell time; it costs nothing because the transaction never executes.
  • Scammers reach GMGN users through lookalike bot handles, typosquat domains, fake $GMGN airdrops, approval transactions and fake support; GMGN has no token, no airdrop and no browser extension.
  • Google Authenticator 2FA plus a pre-whitelisted withdrawal address is the core defense, and withdrawals are website-only.

For the full security assessment, read is GMGN safe; for how real users describe their experience, see the GMGN review. If you are creating an account, do it only through the official site: Open GMGN.

Frequently asked questions

What does phishing mean on GMGN?

It is a wallet tag. In GMGN's holder list and trade feed, a wallet marked "Phishing" has been flagged for phishing-style behavior, such as sending suspicious tokens or interacting with known scam patterns. It is a warning about that wallet's activity, not a statement that the token you are viewing has stolen from you.

How does GMGN detect honeypots?

GMGN's security panel includes a honeypot check on Ethereum plus related signals on every chain: mint authority, freeze or blacklist authority, buy and sell tax, ownership renounced and contract verification. If you try to sell a token that is actually unsellable, GMGN returns error code B4 (honeypot/blacklist unsellable).

Does GMGN have 2FA?

Yes. Google Authenticator 2FA is mandatory for withdrawals. After binding, withdrawals go only to whitelisted addresses, with a 3-hour hold after the first whitelist or an address change and a 24-hour hold after re-binding 2FA. Withdrawals are website-only; the Telegram bots cannot withdraw.

Does GMGN have a bug bounty?

Yes. GMGN runs a bug bounty program paid in USDT and lists security@gmgn.ai as its security contact. GMGN does not publish a detailed public payout schedule that we could verify as of September 2026.

What are the official GMGN domains and bots?

Official domains are gmgn.ai, docs.gmgn.ai, gmgn.ai/app, gmgn.ai/ai, gmgn.ai/rewards, papi.gmgn.ai and gmgn.cc. Official Telegram bots are @gmgnaibot, @GMGN_sol_bot, @GMGN_bsc_bot, @GMGN_swap_bot, @GMGN_base_bot and @GMGN_tron_bot. There is no gmgn.io or gmgn.com; treat them and typosquats like app-gmgn-ai.com as phishing.

What is a jeet check on GMGN?

"Jeet" is slang for a holder who sells early (paper hands). GMGN does not have a feature literally called "jeet check," but its holder list shows behavior labels and sold status per wallet, which traders use to gauge how much of the supply is held by early sellers versus longer-term holders.

Ready to try the GMGN AI app?

Open the official terminal, install the iOS or Android app, or start with the Telegram bot. Keep only trading capital in the wallet.

Sources: GMGN documentation, DefiLlama, official app store listings and GMGN's public channels. See our methodology. Last reviewed 2026-09-22.