A Sophisticated Crypto Scam & The Power of Social Engineering

We've all heard the warnings: "Don't click suspicious links!" "Be wary of unsolicited emails!" But what happens when the scam isn't a glaring red flag, but a carefully woven web of trust and delayed tactics? What happens when a seemingly innocuous catch-up call nearly compromises your digital life?

That's precisely what happened to me recently, and it was a chilling reminder of how vulnerable we all are to sophisticated social engineering. You never think you'll be the target – until you are. And when that feeling hits, the panic that you're about to lose everything is very, very real.

From Conference Connect to Cyberattack

It all started innocuously enough. Back in February 2024, I went to EthDenver and amidst the networking, I met a "Zoie Zhang", who worked for a VC firm, “Paramita”. We exchanged contact info on Telegram, snapped a quick photo to remember each other, and that was that. A crypto-standard conference connection.

Fast forward almost two years to November 2025. Out of the blue, Zoie reached out on Telegram to catch up. A friendly message, a Calendly link to schedule a Google Meet – all perfectly normal. We set a time.

The Subtle Twist: When "Normal" Becomes Dangerous

Five minutes before our scheduled Google Meet, a new message popped up from Zoie: "Here's the Zoom link instead." A minor change, and not out of the ordinary, some people prefer Zoom. But it was the first subtle deviation. I clicked, and it took me to a web-based "Zoom" interface. My audio wasn't working, which can happen. Then, a pop-up appeared: "You need to download a 'Zoom SDK Update'."

This was the first genuine jolt of unease. Why would a web version need an "SDK Update," especially when I already had the full Zoom app installed? Yet, the thought flickered: "Maybe the web version is different?" Zoie's quick Telegram message – "Someone just had this problem, the update fixes it" – served to calm my rising suspicion. It also doesn’t help that Zoom almost always requires an update when starting up.

So I downloaded the file. My stomach dropped as I looked at it: a .scpt file. For those unfamiliar, that's an AppleScript file – an executable script, not a standard software update. The instructions then told me to click a "play" button.

The Moment of Truth

At this point, the warning sirens were going off, this was NOT normal. I did not click "play" but it felt like I had already lost, I had been tricked. Had I been tricked? A frantic online search quickly confirmed my fears: .scpt files used in this context are a known vector for sophisticated malware, often linked to state-sponsored hacking groups like North Korea's BlueNoroff, specifically targeting the crypto space (here’s a great technical article on the attack). My suspicion was confirmed.

I immediately disconnected my laptop from Wi-Fi. On Telegram, I suggested rescheduling, citing the late hour. Zoie's persistence – claiming coworkers were already in this meeting and even sending an image of how to install the "update" – only solidified my conviction. I had been targeted. Now I had to assess the damage.

Luckily, I got enough of a whiff to escape right before the attack unloaded its malicious payload. But just barely. 

The Power of Social Engineering: Why It Almost Worked

This incident perfectly illustrates the insidious power of social engineering:

  • Building Trust: The initial, legitimate conference connection created a foundation of trust. Zoie wasn't a random stranger; she was someone I had met, albeit briefly.

  • Leveraging Brand Familiarity: The use of well-known platforms like Calendly, Google Meet, and Zoom created a veneer of normalcy.

  • Exploiting Urgency & Convenience: The last-minute "Zoom link" change and the immediate "fix" for the audio problem pressured me to act quickly without overthinking.

  • Social Pressure: I was heading into a business meeting, and having technical difficulties is not a great impression to give. So I felt pressure to fix the issue right away and get the meeting back on track.

  • Minimizing Suspicion: Zoie's quick message about "someone else having this problem" was a classic tactic to normalize the unusual request.

  • The "Slow Burn" Attack: The most chilling aspect was the nearly two-year delay. Who would suspect a scam from someone you met, in person no less, from so long ago? 

So why me, and what to make of all this? My best guess, there is a sophisticated crime ring that sends real people to all of these crypto/tech conferences (there’s a lot of them), who portray themselves to be VCs, because who doesn’t want to talk to potential investors?, and establish connections with as many people as possible. This set of contacts becomes the hit list that the attackers go after. I just happened to meet the wrong person and get on the list.

Stay frosty conference goers! And now I have more reasons to not attend work conferences.

Popular posts from this blog

Why Watch The NFL

The Water Scale