Logo
Cardano Ecosystem

The Crypto Times

today at 12:31 PM

·

0 views


Crypto Users on MacOS Targeted in Sneaky Token Vesting Malware Scam

Key HighlightsMac users face new phishing risks; fake audit emails can steal passwords and install hidden malware.Hackers use disguised AppleScript files and backdoors to control Macs and bypass privacy...

Crypto Users on MacOS Targeted in Sneaky Token Vesting Malware Scam

Key Highlights

  • Mac users face new phishing risks; fake audit emails can steal passwords and install hidden malware.
  • Hackers use disguised AppleScript files and backdoors to control Macs and bypass privacy protections.
  • Phishing and wallet related scams gain as crypto’s popularity grows worldwide.

Blockchain security firm SlowMist warned that a new phishing attack is putting macOS users at high risk. In their latest X post, SlowMist shared that Chainbase Lab has detected a phishing email disguised as an “audit/compliance confirmation.” The emails lured recipients to reveal sensitive information, including system credentials. 

Chainbase also revealed the malicious samples with SlowMist for deeper analysis. Both the firms confirmed that the campaign uses multi-stage, fileless malware specifically targeting Mac devices. 

🚨 Threat Intelligence | Analysis of Token Vesting Phishing Poisoning 🚨

Recently, @ChainbaseHQ detected a phishing email campaign disguised as “audit/compliance confirmation” and shared the sanitized samples with the SlowMist team. We jointly analyzed the campaign and confirmed… pic.twitter.com/0em6y2M1k6

— SlowMist (@SlowMist_Team) February 3, 2026

The attackers initially ask users to “confirm the company’s legal English name,” then share a follow up email titled “FY2025 External Audit” or “Token Vesting Confirmation — deadline.” These messages contain Word or PDF attachments. 

However, these attachments are not regular documents, but rather disguised AppleScript malware. Opening these attachments allows the victims to unknowingly install malware that can steal important information from them. As such, this malware campaign is a mix of social engineering, technical deception, and sophisticated memory-resident malware.

How the malware works on macOS

The malware file is given the name “Confirmation_Token_Vesting.docx.scpt” and is designed to appear as a legitimate document file due to its use of a double extension. Once executed, the malware displays fake progress bars to resemble a system update or repair process. 

At the same time, it will display legitimate-looking password prompt pop-ups to steal system credentials. “When the user enters a password and clicks ‘OK,’ the script invokes the dscl command to verify whether the password is correct,” SlowMist said.

The malware also tries to sneak past Mac’s built-in privacy protections. It quietly gives itself access to your files, camera, screen, and keyboard. On top of that, it installs a hidden program that lets hackers control your Mac and run additional harmful code. The backdoor connects to a remote server to collect information about your Mac and run more harmful programs. Hackers hide their tracks using temporary websites like sevrrhst[.]com.

This is not the first time SlowMist has alerted cryptocurrency users. In January 2026, the company raised awareness regarding a MetaMask scam involving false two-factor authentication messages. The victims were redirected to false sites, leading them to leak their seed phrases. 

🚨 New #metamask phishing scam alert

Attackers are impersonating a “2FA security verification” flow, redirecting users via look-alike domains to fake security warnings with countdown timers and “authenticity checks.”

The final step asks for your wallet recovery phrase — once… pic.twitter.com/3bX9U1wZbs

— SlowMist (@SlowMist_Team) January 5, 2026

In December 2025, a phishing attack occurred on a Solana digital wallet, causing users to sign transactions and resulting in the loss of over $3 million worth of cryptocurrency. The hackers changed the ownership of the digital wallet, giving themselves complete access without the owner’s knowledge. SlowMist explained, “You thought you just connected your crypto wallet to a website, but in reality, you gave all your money to a stranger.”

Besides going after wallets, SlowMist also warned earlier about AI-powered phishing. Hackers tampered with AI search results to show fake imToken wallet links. People who clicked these links risked malware or phishing attacks. Hence, the firm emphasized checking all URLs carefully and only downloading wallets from official sources.

This Mac phishing attack shows how clever hackers are becoming. People should be careful with unexpected emails, check attachments before opening, and make sure links are real.

Also Read: Korea’s FSS Launches VISTA to Combat Crypto Price Rigging

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.


mobile only image
AD

Delegate Your Voting Power to FEED DRep in Cardano Governance.

DRep ID: drep12ukt4ctzmtf6l5rj76cddgf3dvuy0lfz7uky08jfvgr9ugaapz4 | We are driven to register as a DRep by our deep dedication to the Cardano ecosystem and our aspiration to take an active role in its development, ensuring that its progress stays true to the principles of decentralization, security, and community empowerment.DELEGATE VOTING POWER!


Read Original Article on The Crypto Times

ORIGINAL SOURCE

https://www.cryptotimes.io/2026/02/03/cr...

Disclaimer: Cardano Feed is a Decentralized News Aggregator that enables journalists, influencers, editors, publishers, websites and community members to share news about the Cardano Ecosystem. User must always do their own research and none of those articles are financial advices. The content is for informational purposes only and does not necessarily reflect our opinion.


More from The Crypto Times

See more
Shiba Inu Drops to Multi-Year Low: Can It Recover?
The Crypto Times
Shiba Inu Drops to Multi-Year Low: Can It Recover?

today at 12:04 AM

·

19 views

Related News

See more

Featured News

See more



    DEFAULTENGLISH (EN)SPANISH (ES)RUSSIAN (RU)GERMAN (DE)ITALIAN (IT)POLISH (PL)HUNGARIAN (HU)JAPANESE (JA)THAI (TH)ARABIC (AR)VIETNAMESE (VI)PERSIAN (FA)GREEK (EL)INDONESIAN (ID)ROMANIAN (RO)KOREAN (KO)FRENCH (FR)CZECH (CS)PORTUGUESE (PT)TURKISH (TR)