OFM Databank
Middleman Protocol: How to Structure Any OFM Deal So You Can't Get Robbed

Other

Middleman Protocol: How to Structure Any OFM Deal So You Can't Get Robbed

One wrong Telegram username cost an operator $300 and a deleted group chat — here's the exact protocol that prevents it.

Updated Aug 2026 · sourced from 6 YouTube creators and 8 operator groups

Key takeaways

  • The BUYER picks the middleman and creates the group — never the seller.
  • Verify the MM's exact @username, not their bio or display name.
  • Trusted vouched MMs across multiple groups: @marshal, @laugh, @bluemm, @henri77.
  • Anyone pushing an unknown MM mid-deal is almost certainly running a scam.
  • A fake username is one character — uppercase I for lowercase l — and it costs real money.

Someone in your DMs has an account for sale. The numbers look right.

The seller seems legit. You're about to send crypto.

Stop.

A buyer in one operator community did exactly this — paid a 'middleman' who appeared in the group, then watched the group disappear and the MM's account vanish. Gone. $300.

The seller claimed innocence. The fake MM had been planted.

This is not a rare edge case; it's the standard playbook.

The middleman protocol exists specifically to close this hole. But the protocol only works if you run it correctly, every single time.

Why 'Just Use a Middleman' Is Not Enough

The advice you'll hear in every OFM community is 'always use a MM.' True. Necessary.

Also wildly incomplete.

Because the scam has evolved. Fraudsters don't skip the middleman step anymore — they become it.

Multiple operators across several separate groups (Dec 2025–Jun 2026) report the same mechanic: a fake MM joins or is suggested mid-negotiation, collects payment from the buyer, then deletes the group. The seller walks away clean.

The fake MM was never a real party.

So the real rule is not 'use a middleman.' It's 'control who the middleman is and how they enter the deal.'

Step 1: The Buyer Picks the MM

This is the single most important structural rule, and operators in multiple groups are consistent on it: the buyer selects the middleman, and the buyer creates the group.

Not the seller. Not 'whoever suggests one first.' The buyer.

Why? Because if the seller nominates the MM, you have no idea whether that account is real, vouched, or a burner the seller spun up twenty minutes ago.

A $300 loss documented in one community came from exactly this — an MM nominated by the seller who deleted the group after payment cleared. Multiple separate groups corroborate this pattern across the Dec 2025–Jun 2026 window.

When you create the group yourself, you control who gets added. That matters more than any other single step.

Step 2: Verify the Exact @Username — Not the Bio, Not the Display Name

Here's where the character-level trickery happens, and it is more sophisticated than most buyers expect.

Scammers exploit a simple fact: in most fonts, an uppercase I and a lowercase l are visually identical. So @iiquidback looks like @liquidback.

One operator community flagged this specific pair (Dec 2025–Jun 2026). Another documented the same trick applied to a widely-trusted market account: @btzofficiai — that's a capital I in place of the final lowercase l — impersonating @btzofm.

The fake account copies the profile picture. It copies the display name.

The only tell is the username itself, one character deep.

What to do: - Ask the MM to confirm their @username in the group chat. - Manually type the username into Telegram search yourself — do not click a link. - Check the username field, not the bio. Operators across multiple groups (Dec 2025–Jun 2026) are emphatic on this: bio text is decoration anyone can write; the @username is the canonical identifier.

One more layer: real, reputable accounts in this space do not cold-DM you. Multiple separate operator groups (Dec 2025–Jun 2026) note that the real @btzofm account never DMs users and never initiates sales.

If an account with that name or picture slides into your DMs unprompted, it is a fake. Full stop.

Step 3: Use the Vouched MM List

Operators across multiple separate groups consistently name the same four handles as vouched middlemen for OFM deals: @marshal, @laugh, @bluemm, and @henri77. This convergence — the same names appearing across distinct, unconnected communities from Dec 2025 through Jun 2026 — is the strongest signal the chatter evidence produces.

That said, this is operator chatter, not a certified registry. It can be wrong.

It can be gamed if a scammer builds enough fake reputation. Treat it as a starting point that narrows the field, not a guarantee.

@marshal is the most frequently cited across the evidence — appearing in more separate group references than the others. But corroboration across four names, from multiple distinct sources, is meaningful.

When you're at the MM-selection step, start with this list.

Step 4: What to Do When Someone Pushes an Unknown MM

This is your single clearest in-the-moment red flag.

If a seller — or anyone in the negotiation — tries to redirect you to a middleman not on your vouched list, or objects to your choice of MM, treat that as a near-certain scam signal. Operators across multiple groups (Dec 2025–Jun 2026) are direct about this: anyone pushing an unknown MM is likely a scammer.

The correct response is not to negotiate. It is to:

  1. Decline to proceed with the suggested MM.
  2. Name your preferred MM from the vouched list.
  3. If the seller refuses or disappears, the deal is dead — and you're ahead by whatever you didn't lose.

A legitimate seller has no rational objection to a buyer-nominated, vouched MM. Friction at this step is information.

The Full Protocol, Assembled

Here it is as a checklist you can run before any account, model, or channel deal:

  • Buyer selects the MM from the vouched list (@marshal, @laugh, @bluemm, @henri77).
  • Buyer creates the Telegram group and adds the seller and MM.
  • Verify MM @username by typing it manually — check the username field, not the bio.
  • Confirm no unsolicited DM preceded the deal (real MMs don't cold-DM).
  • Nothing is released by the MM until the buyer confirms receipt and access.
  • If anyone pushes an alternative MM, exit the deal.

No exceptions. The protocol is only effective when applied consistently.

One shortcut is one attack surface.

The Known Scam Taxonomy (So You Recognize Them)

Operators across multiple groups have documented the recurring patterns. None of these are hypothetical:

  • Fake MM planted in negotiation. Seller or a colluder adds a fake MM who collects funds, then deletes the group. Loss documented: $300 (one community, Dec 2025).
  • Lookalike username. Uppercase I substituted for lowercase l. Documented pairs: @iiquidback vs @liquidback; @btzofficiai vs @btzofm (multiple groups, Dec 2025–Jun 2026).
  • PayPal friends/family fraud. Seller requests F&F payment, claims funds 'on hold,' demands more, then blocks. No MM involved — the absence of MM is the exploit (one group, Mar 2026).
  • Pay-before-access. Buyer sends payment, seller sends nothing, then blocks. Documented on Reddit account deals (one group, Dec 2025).
  • Fake vouch channel. @marbal operated a fake middleman identity with a fabricated vouch channel. Loss: $300 (one group, Dec 2025).
  • Named bad actors reported by operators in the Dec 2025–Jun 2026 window include handles associated with: a reported $1,400 loss, a $900 loss via a fake account, a $100 crypto loss with no delivery, and a case of payment-then-block on a model deal. These are unverified chatter — single-source or near-single-source reports — but the pattern is consistent enough to surface.

Notice the dollar amounts: $100, $300, $900, $1,400. And separately, one operator group flagged unban services with a reported structure of roughly $200 to trigger a ban and $2,000 to reverse it — with re-bans following shortly after to generate repeat fees.

These are chatter-tier figures, not audited data, but the directional logic is consistent with how recurring-fee scams work.

Where Operators Actually Disagree

The evidence is not unanimous on everything, and you deserve both sides.

On how much to trust vouched lists: Most groups treat the @marshal citation as essentially settled. A minority position — implicit in some chatter — is that any public vouched list becomes a target: scammers study it and build lookalike accounts optimized against exactly those names.

Both are true simultaneously. The list narrows your exposure; it doesn't eliminate it.

Verification protocol has to do the remaining work.

On whether buyers should always verify directly: The dominant position is yes — message the MM yourself before any deal proceeds, confirm the username matches, confirm they're aware of and part of the deal. This is corroborated across multiple groups.

There's no meaningful counter-position in the evidence, but it's worth noting: one single data point about a specific MM being 'this group's vouched middleman' (one group, Mar 2026) is not the same as cross-community consensus. The cross-community names — @marshal, @laugh, @bluemm, @henri77 — have stronger corroboration than any single-group endorsement.

On the scope of fake accounts: Some operators treat every unsolicited DM as automatically fraudulent. Others allow that there may be legitimate outreach that happens to be unsolicited.

The evidence tilts heavily toward the more paranoid position — every documented impersonation case in the Dec 2025–Jun 2026 window involved an unsolicited or unexpected contact.

One Line Worth Memorizing

*The buyer picks the MM. The buyer creates the group.

Everything else flows from that.*

The Bottom Line

Middlemen exist because trustless transactions between pseudonymous parties require a trusted escrow layer. That layer only functions if you control who fills it.

The protocol is not complicated. Buyer picks.

Buyer creates the group. Username verified character-by-character.

Vouched list consulted. Any deviation from this sequence — seller nominates the MM, someone pushes an unknown handle, the MM appeared in your DMs first — is the scam revealing itself before it completes.

The $300 loss, the $900 loss, the $1,400 loss: none of them required a sophisticated attack. They required one moment where the buyer let the other party control the middleman step.

Don't give them that moment.

Sources

Community intelligence: 34 operator claims aggregated from 8 separate private OFM groups (Dec 2025–Jun 2026), corroboration counted across groups. Group identities are withheld to protect sources; browse the underlying intel in the Community Intel Wiki.