Community Management
🔑 Key Takeaway: Community channels are high-trust broadcast paths. Compromised operator accounts and weak platform configuration turn that trust into phishing scale.
Communities are often the foundation of Web3 projects and the primary connection between organizations and users. They are also a large attack surface. Community members, moderators, founders, and executives can be targeted with social engineering, phishing, impersonation, account compromise, malware, and related attacks across Discord, Telegram, X (formerly Twitter), shared workspaces, and more.
When a community channel is compromised—whether through a malicious link, a compromised team account, a fraudulent support interaction, or a coordinated social engineering campaign—it can become a launch point for wider attacks that impact users, project assets, and organizational reputation.
This framework orients teams to platform-specific pages and the broader security domains that constrain community risk. Deep, step-by-step controls live in the linked account-management guides.
What this framework covers
- Discord: server permissions, role hygiene, raid protection, bot vetting, and anti-impersonation (hub into the Discord guide).
- X (Twitter): account security, SIM-swap failure modes, OAuth token hygiene, and official-channel practices.
- Telegram: two-step verification, phone-number privacy, admin permissions, and man-in-the-group style threats.
Related security domains
| Domain | What it covers | Framework |
|---|---|---|
| Authentication and passwords | Unique credentials, hardware-backed multi-factor authentication (MFA), linked email protection | Operational Security |
| Phishing and social engineering | Official channel verification, DM policy, impersonation recognition | Security Awareness |
| Operational security | Device hygiene, update discipline, reduced attack surface for operators | Operational Security |
| Emergency response | Compromise playbooks, access revocation, community notification | Incident Management |
Related frameworks
- Guides — Account Management: platform hardening procedures referenced by each child page
- User and Team Security: staff-facing security postures (when expanded)
- Awareness: phishing and social-engineering education for operators and members
- OpSec: credentials, MFA, and device hygiene for people who run community tools
- Incident Management: response when a community channel is compromised
Further Reading
- Platform pages above and their linked guides under
/guides/account-management/ - Discord Safety Center
- X Help Center — How to protect your account
- Telegram FAQ — Two-Step Verification
