
Other
The OFM Scammer Black Book: Every Flagged Name, Handle, and Pattern You Need to Know
From a $950 chatter payday that never arrived to exit scams under $400 with illegal content left behind — here is every flagged name, what they actually did, and the five patterns that run through all of it.
Updated Aug 2026 · sourced from 7 YouTube creators and 9 operator groups
Key takeaways
- Nine operator groups flagged 17+ named scammers between Dec 2025 and Jun 2026.
- Chatter-payment fraud is the dominant pattern: work delivered, payday ghosted.
- The BTZ impersonator (@btzofficiai) is still active — one letter separates fake from real.
- Fake traffic sellers can trigger $2,000+ in OF chargebacks, not just wasted spend.
- No middleman, no deal — this rule appears across every group that flagged losses.
Someone worked three weeks for @GunnersMA. Generated $9,300 in sales.
Then asked for their $950 cut.
Ghosted.
That is not a one-off horror story. It is the most common transaction in OFM fraud: real labor, real revenue, zero payment.
The names change. The shape of the con does not.
This directory consolidates every flagged handle, tactic, and amount from nine separate operator groups between December 2025 and June 2026. Where sources disagree, we say so.
Where evidence is thin — one group, no corroboration — we label it. Nothing here is presented as settled fact unless multiple distinct groups confirmed it independently.
The Named Roster: Who Got Flagged, and For What
We are organizing by type of fraud rather than alphabetically, because the pattern is more useful than the name.
Chatter-Payment Fraud (Work Done, Money Withheld)
This is the dominant category. Multiple operator groups flagged it repeatedly across late 2025 and into 2026.
@GunnersMA — According to one operator group (mid-2026), this manager generated $9,300 in confirmed sales over three weeks using a chatter, then refused to pay the $950 owed. One group, one report.
Treat it as a serious unverified data point — but $9,300 in documented revenue makes the claim unusually specific.
@noah1zero — Flagged by one group (mid-2026) for the same playbook: let the chatter work, then ghosted on payday and logged them out of the account to cut access. The lockout detail is important — it signals premeditation, not just avoidance.
@DBALB1 — Reportedly runs an AI model called 'Nina Noir.' One group flagged him (early-to-mid 2026) for ghosting chatters on payday. Single-source.
The AI model detail adds texture but doesn't confirm the fraud independently.
Blake Barton (manages model Abigail) — One group reported in mid-2026 that he did not pay for completed work despite follow-ups. Single-source, single group.
Named and attributed — but one unverified data point.
Fake-Contract and Impersonation Fraud
@curl_bryant1 (now reportedly operating as @ofm_davis) — One group flagged this handle in early 2026 for selling fake model contracts, posing as the model to lend credibility, then blocking after payment. Reported loss: approximately €300.
The rebranding to @ofm_davis is the detail to watch — name changes after exposure are a recurring escape tactic.
Fake Traffic and Chargeback Bombs
@tosyme / @mmtosy — This one has a financial sting beyond the upfront fee. One operator group (mid-2026) reported these handles sell fake traffic that triggers OnlyFans chargebacks totaling around $2,000.
They also allegedly use secondary accounts to post fake positive reviews of their own service. Two linked handles, one group — unverified, but the chargeback mechanism is a specific enough claim to take seriously.
Exit Scams and Illegal Content
@Littesttelly — Flagged by one group (early-to-mid 2026) for exit-scamming approximately $350 and allegedly placing illegal content on a model's account before disappearing. If the illegal-content allegation is accurate, this goes beyond financial fraud into legal exposure for the model.
One group, serious allegation — treat with caution but do not ignore.
Fake Account/Crypto Sales
@Philip_R / @Philip_rdg — One group (mid-2026) reported taking $100 in crypto for warmed NSFW accounts plus marketing, delivering nothing, and gaslighting the buyer when pressed. Small dollar amount, but the crypto-for-accounts structure is a clean scam vector that scales.
CHRIS_ACCTS (TikTok account seller) — Flagged by one group (early 2026) for selling fake TikTok accounts. The warning: demand proof of ownership and account metrics before any payment.
Single source.
@Btcusdkuwait / @dirhamOfmm — One group flagged both handles together (early 2026) as scammers. No specific tactic or amount reported.
Two handles, one report — minimal detail, maximum caution.
Fake Traffic / DM Services
igmassdms / Henry (also operates as igmassdm, floan) — One group flagged this in mid-2026 as a scammer with proof available in DMs. The multiple aliases are a red flag in themselves. Single-source report.
@promuke — Named in operator chatter as a flagged handle in the OFM space. No specific tactic documented in the available evidence.
One reference — minimal corroboration.
@OFmrW — Similarly named with minimal detail attached. Single-group mention.
The BTZ Impersonator: A Case Study in One-Letter Fraud
This deserves its own section because it is the most corroborated scam pattern in the data — five separate operator groups confirmed it across December 2025 through May 2026.
The real BTZ marketplace account is @btzofm. The scammer account is @btzofficiai — that last character is a capital I, not a lowercase L.
On most screens, at a glance, they are identical.
The rule, confirmed across all five groups: the real BTZ never DMs you. It never sells directly. The BTZ marketplace is also reportedly inactive (flagged since early 2026).
Any account with BTZ's name or picture that slides into your DMs is an impersonator.
The recommended middleman across multiple groups is @marshal — but verify the username is in the handle, not just the bio, when setting up any escrow.
The same one-letter swap tactic extends beyond BTZ. Operators flagged @iiquidback impersonating @liquidback using the same capital-I trick.
If you are verifying any handle for a transaction, zoom in on every character.
The Five Red-Flag Patterns That Connect All of It
Across all 17+ flagged names and nine operator groups, five structural patterns appear repeatedly.
1. No middleman, no deal. Every group that reported losses also, somewhere in their chatter history, confirmed the same rule: legitimate transactions use a vouched escrow. The operators who got burned skipped it. Two separate groups stated this explicitly in April 2026 — one phrased it as 'no MM = scam,' full stop.
2. Crypto + no delivery. @Philip_R's $100 crypto grab follows the same structure as larger cons. Crypto is irreversible. Small amounts test whether the buyer will escalate. Many don't.
3. Payday ghosting with account lockout. @noah1zero's lockout move is the evolution of simple ghosting — it removes the chatter's leverage entirely. If you cannot access the account, you cannot screenshot revenue data to support a dispute.
4. Fake reviews on secondary accounts. The @tosyme / @mmtosy report includes this detail explicitly. Before paying any traffic or DM service, search their handle in operator communities and specifically look for whether positive reviews cluster around new or low-activity accounts.
5. Rebranding after exposure. @curl_bryant1 reportedly rebranded to @ofm_davis. This is not unique to one operator — it is an industry-wide escape pattern. When a flagged handle goes quiet, search for adjacent names with similar writing styles or claimed models.
Where Operators Disagree
Honesty requires surfacing the conflicts, not just the consensus.
On paying ransom for hijacked accounts: One operator group (mid-2026) said clearly — never pay account-hijack ransom, as paying marks you as a known target and the platform should be contacted with ownership proof instead. No group in this dataset argued the opposite explicitly, but the fact that account hijacking is flagged as a recurring issue suggests some operators do pay, or the extortors would stop trying.
The chatter consensus leans strongly toward non-payment, but the underlying behavior suggests the market for paying exists.
On fake-review verification: The @tosyme allegation about secondary-account fake reviews is single-source. There is no corroborating group that independently confirmed this specific tactic for this specific handle.
It is plausible — fake review seeding is a documented behavior in adjacent industries — but it is one unverified data point about one operator.
On @promuke and @OFmrW: These handles appear in flagged-name discussions but with no specific tactic or victim amount attached in the available evidence. Some operators treat naming alone as sufficient warning; others (reasonably) want documented incidents.
We are not in a position to adjudicate — flag them as low-detail mentions and do your own verification before any transaction.
Practical Verification Protocol
The evidence across all nine groups points to the same operational checklist. None of this is novel — what is notable is how consistently operators who skipped steps reported losses.
- Username character-by-character verification. Capital I versus lowercase L. Zero versus O. Do it every time.
- Search the handle in the bot bouncer subreddit before any account purchase. Operators flagged this resource specifically for checking account history.
- Create the middleman group yourself. Do not accept an escrow group the other party sets up — you cannot verify who else is in it. One group flagged this explicitly: create the group, add the parties, confirm usernames match handles not bios.
- Screenshot everything before blocking. If a deal goes wrong, the first instinct is often to block and move on. Block after you have documented the conversation, timestamps, usernames, and any receipts. (SWCEO, Feb 2026)
- Log every incident. A documented pattern is what you need if you want legal recourse or to make a credible public warning. (SWCEO, May 2025)
- For fake traffic: Never run purchased traffic directly to your main account. One operator group's $2,000 chargeback loss from @tosyme / @mmtosy illustrates the asymmetric downside — you pay for the traffic and absorb the platform penalties.
The Bottom Line
The OFM fraud ecosystem in 2026 is not random. It clusters around three transaction types — chatter-payment agreements, account sales, and traffic/DM services — and it exploits the same two vulnerabilities every time: no middleman, and urgency.
Real opportunities do not rush you. That single sentence, stated independently by one operator group in mid-2026, is the cleanest filter available.
Verify the handle, build the escrow group yourself, and document everything before you block. The $9,300 revenue that @GunnersMA's chatter generated is a number that should haunt every operator who has ever skipped that step.
Sources
On the record (YouTube creators):
- SWCEO — EP 172: Doxxing, Leaks, and Blackmail. How You Can Stay Protected as an Adult Creator, Feb 2026. Watch ↗
- SWCEO — How to Deal with Online Harassment, Stalking & Trolls as an Adult Content Creator | OnlyFans Advice, May 2025. Watch ↗
Community intelligence: 60 operator claims aggregated from 9 separate private OFM groups (Dec 2025–Jun 2026), corroboration counted across groups. Group identities are withheld to protect sources; browse the underlying intel in the Community Intel Wiki.