<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: Frantz GALINIER-STEFANI</title>
    <description>The latest articles on DEV Community by Frantz GALINIER-STEFANI (@frantzgs).</description>
    <link>https://dev.to/frantzgs</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4094670%2Fc8bbf36d-1818-4f8d-a21e-8e8a988255c5.png</url>
      <title>DEV Community: Frantz GALINIER-STEFANI</title>
      <link>https://dev.to/frantzgs</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/frantzgs"/>
    <language>en</language>
    <item>
      <title>Inside a Suspected Fake CoinDesk Podcast Funnel Targeting Web3 Founders</title>
      <dc:creator>Frantz GALINIER-STEFANI</dc:creator>
      <pubDate>Tue, 25 Aug 2026 19:27:50 +0000</pubDate>
      <link>https://dev.to/frantzgs/inside-a-suspected-fake-coindesk-podcast-funnel-targeting-web3-founders-3k43</link>
      <guid>https://dev.to/frantzgs/inside-a-suspected-fake-coindesk-podcast-funnel-targeting-web3-founders-3k43</guid>
      <description>&lt;p&gt;On 15 August 2026, I received a LinkedIn message inviting me to discuss my personal crypto journey for a supposed CoinDesk podcast.&lt;/p&gt;

&lt;p&gt;At first glance, the approach looked credible.&lt;/p&gt;

&lt;p&gt;The sender used a polished LinkedIn profile presenting as a Venture Scout at TheForms Ventures. The pitch was simple, professional, and low-friction. There was no wallet request, no investment offer, no suspicious download, and no obvious phishing page.&lt;/p&gt;

&lt;p&gt;That is exactly why I think this case is worth documenting.&lt;/p&gt;

&lt;p&gt;The suspicious part did not appear at the beginning. It emerged gradually through identity claims, scheduling, a promised translation setup, and finally a technical discussion about operating-system compatibility.&lt;/p&gt;

&lt;p&gt;I preserved the evidence and published a redacted incident report here:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/FrantzGS/theforms-coindesk-impersonation-report" rel="noopener noreferrer"&gt;https://github.com/FrantzGS/theforms-coindesk-impersonation-report&lt;/a&gt;&lt;/p&gt;

&lt;h2&gt;
  
  
  The initial lure
&lt;/h2&gt;

&lt;p&gt;The LinkedIn account used the name &lt;strong&gt;Denys Kovalov&lt;/strong&gt; and presented as a &lt;strong&gt;Venture Scout at TheForms Ventures&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;The message invited me to a CoinDesk podcast about personal crypto journeys.&lt;/p&gt;

&lt;p&gt;When I asked for more information, the account named the series:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"Why Crypto Became Personal"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I was told it would be a short audio conversation focused on how guests entered crypto, what they were building, and why crypto had become personally meaningful to them.&lt;/p&gt;

&lt;p&gt;Because my spoken English is limited, I asked whether the conversation could work in French.&lt;/p&gt;

&lt;p&gt;The answer was that real-time AI translation would handle the language barrier.&lt;/p&gt;

&lt;p&gt;So far, nothing required me to install anything.&lt;/p&gt;

&lt;h2&gt;
  
  
  I asked for an official CoinDesk link
&lt;/h2&gt;

&lt;p&gt;Before scheduling, I asked for a public CoinDesk page or a link to the series.&lt;/p&gt;

&lt;p&gt;No public link was provided.&lt;/p&gt;

&lt;p&gt;Instead, I was told that it was a fresh series and that the first episodes were still in production.&lt;/p&gt;

&lt;p&gt;A new production can legitimately have no public page. That fact alone is not evidence of fraud.&lt;/p&gt;

&lt;p&gt;The problem is what happened when this was compared with an independent incident from July 2026.&lt;/p&gt;

&lt;h2&gt;
  
  
  The booking remained TheForms-branded
&lt;/h2&gt;

&lt;p&gt;The introductory call was scheduled through a TheForms Calendly page:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;calendly.com/contact-theforms/30min&lt;/code&gt;&lt;/p&gt;

&lt;p&gt;The booking flow did not independently authenticate CoinDesk.&lt;/p&gt;

&lt;p&gt;Later, the meeting was rescheduled. The LinkedIn account attributed the change to the "CoinDesk team".&lt;/p&gt;

&lt;p&gt;Before the replacement meeting, I was told that a producer "on the CoinDesk team" would create the Google Meet invitation and join the call.&lt;/p&gt;

&lt;p&gt;I also reconfirmed that French-English translation would be available.&lt;/p&gt;

&lt;p&gt;The response was:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"Yes, everything is prepared, no worries."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;h2&gt;
  
  
  The Google Meet was real
&lt;/h2&gt;

&lt;p&gt;On 25 August 2026, I received a genuine &lt;code&gt;meet.google.com&lt;/code&gt; URL.&lt;/p&gt;

&lt;p&gt;This distinction matters.&lt;/p&gt;

&lt;p&gt;Google Meet itself was not malicious. Legitimate infrastructure can be used inside a social-engineering workflow.&lt;/p&gt;

&lt;p&gt;The participant in the meeting was displayed under the name &lt;strong&gt;"Jiawei Zhu"&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;A display name is not identity verification, so I do not claim that the participant was any particular real-world person with that name.&lt;/p&gt;

&lt;p&gt;The meeting was short and the promised translation did not work as expected.&lt;/p&gt;

&lt;p&gt;Read AI later recorded the session as a &lt;strong&gt;"French English Translation Test"&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  Then the conversation shifted to Windows, macOS, and Linux
&lt;/h2&gt;

&lt;p&gt;This was the most security-relevant moment.&lt;/p&gt;

&lt;p&gt;During the failed translation test, the discussion moved to the computer environment.&lt;/p&gt;

&lt;p&gt;Windows and macOS were raised.&lt;/p&gt;

&lt;p&gt;I explained that my ThinkPad runs Linux.&lt;/p&gt;

&lt;p&gt;The planned setup could not proceed as expected. I recall being told that another call or another platform would be arranged.&lt;/p&gt;

&lt;p&gt;I was also told that a person called "Valerie" would contact me on LinkedIn.&lt;/p&gt;

&lt;p&gt;No installer was delivered during the completed call.&lt;/p&gt;

&lt;p&gt;No &lt;code&gt;.exe&lt;/code&gt;, &lt;code&gt;.dmg&lt;/code&gt;, package, browser extension, alternate conferencing application, or second-stage domain was sent to me.&lt;/p&gt;

&lt;p&gt;Therefore I am not claiming that malware was actually delivered in my specific interaction.&lt;/p&gt;

&lt;p&gt;The narrower conclusion is that the operating-system pivot was consistent with known Web3 social-engineering techniques and justified further investigation.&lt;/p&gt;

&lt;h2&gt;
  
  
  The strongest corroboration came from another founder
&lt;/h2&gt;

&lt;p&gt;This case became significantly more concerning when I found a public report published on 2 July 2026 by Byte Exchange founder &lt;strong&gt;Ismail Koseoglu&lt;/strong&gt;.&lt;/p&gt;

&lt;p&gt;His account described:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;LinkedIn outreach&lt;/li&gt;
&lt;li&gt;a person presenting as a Venture Scout at &lt;strong&gt;The Forms Ventures&lt;/strong&gt;
&lt;/li&gt;
&lt;li&gt;a supposed CoinDesk editorial series&lt;/li&gt;
&lt;li&gt;a series titled &lt;strong&gt;"How Crypto Became Personal"&lt;/strong&gt;
&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That title is strikingly close to the one used in my case:&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;"Why Crypto Became Personal"&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;According to Koseoglu's report, he contacted CoinDesk independently.&lt;/p&gt;

&lt;p&gt;He quotes CoinDesk as responding:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"None of this is legitimate."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;His article says CoinDesk did not have the claimed podcast and was not partnered with the parties mentioned.&lt;/p&gt;

&lt;p&gt;That is the strongest external corroboration currently available.&lt;/p&gt;

&lt;h2&gt;
  
  
  Security Alliance documented a related class of tactics
&lt;/h2&gt;

&lt;p&gt;Security Alliance / SEAL Intel has documented cold-reachout campaigns targeting the crypto ecosystem using tactics such as:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;fake podcast invitations&lt;/li&gt;
&lt;li&gt;fake VC identities&lt;/li&gt;
&lt;li&gt;polished professional profiles&lt;/li&gt;
&lt;li&gt;trust-building before the malicious step&lt;/li&gt;
&lt;li&gt;custom conferencing or communication software&lt;/li&gt;
&lt;li&gt;Windows and macOS malware payloads&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Their research also includes a separate cluster called &lt;strong&gt;FormsVC&lt;/strong&gt; and a domain written as &lt;code&gt;theforms[.]vc&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;Important caveat:&lt;/p&gt;

&lt;p&gt;&lt;code&gt;theforms[.]vc&lt;/code&gt; is &lt;strong&gt;not&lt;/strong&gt; the same domain as &lt;code&gt;theforms.ventures&lt;/code&gt;.&lt;/p&gt;

&lt;p&gt;I am not claiming they share an operator, infrastructure, or ownership.&lt;/p&gt;

&lt;p&gt;The relevance is behavioral and useful for threat hunting, not proof of attribution.&lt;/p&gt;

&lt;h2&gt;
  
  
  What I did not do
&lt;/h2&gt;

&lt;p&gt;No compromise is currently known.&lt;/p&gt;

&lt;p&gt;I did not:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;install software from the contact&lt;/li&gt;
&lt;li&gt;install a browser extension&lt;/li&gt;
&lt;li&gt;run a shell or PowerShell command&lt;/li&gt;
&lt;li&gt;connect a crypto wallet&lt;/li&gt;
&lt;li&gt;sign a transaction&lt;/li&gt;
&lt;li&gt;sign an arbitrary wallet message&lt;/li&gt;
&lt;li&gt;share a seed phrase or private key&lt;/li&gt;
&lt;li&gt;share passwords or API secrets&lt;/li&gt;
&lt;li&gt;provide remote desktop access&lt;/li&gt;
&lt;li&gt;transfer funds&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;That matters because this report documents a &lt;strong&gt;pre-compromise social-engineering chain&lt;/strong&gt;, not a completed theft.&lt;/p&gt;

&lt;h2&gt;
  
  
  Attribution discipline matters
&lt;/h2&gt;

&lt;p&gt;One of the easiest ways to damage a useful security report is to overstate what the evidence proves.&lt;/p&gt;

&lt;p&gt;For that reason, the public report distinguishes between observed facts, corroborated information, assessment, and unknowns.&lt;/p&gt;

&lt;p&gt;For example, I refer to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;"the LinkedIn account using the name Denys Kovalov"&lt;/li&gt;
&lt;li&gt;"the Google Meet participant displayed as Jiawei Zhu"&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;I do not claim that those display identities independently prove who controlled the accounts.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why publish this?
&lt;/h2&gt;

&lt;p&gt;The goal is not to create drama around individual names.&lt;/p&gt;

&lt;p&gt;The goal is to make the playbook searchable.&lt;/p&gt;

&lt;p&gt;A future founder who searches for:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;&lt;code&gt;TheForms Ventures CoinDesk&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;Why Crypto Became Personal&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;How Crypto Became Personal&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;CoinDesk podcast scam&lt;/code&gt;&lt;/li&gt;
&lt;li&gt;&lt;code&gt;fake crypto podcast interview&lt;/code&gt;&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;should have a chance to find evidence before installing anything.&lt;/p&gt;

&lt;h2&gt;
  
  
  Public evidence
&lt;/h2&gt;

&lt;p&gt;The repository contains a full English report, a French report, a detailed timeline, redacted screenshots, SHA-256 hashes, methodology and confidence labels, observed identifiers, and external sources.&lt;/p&gt;

&lt;p&gt;Public report:&lt;/p&gt;

&lt;p&gt;&lt;a href="https://github.com/FrantzGS/theforms-coindesk-impersonation-report" rel="noopener noreferrer"&gt;https://github.com/FrantzGS/theforms-coindesk-impersonation-report&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;The original unredacted evidence remains private and can be provided to legitimate investigators when necessary.&lt;/p&gt;

&lt;h2&gt;
  
  
  Reports submitted
&lt;/h2&gt;

&lt;p&gt;The incident has been reported to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;CoinDesk Fraud&lt;/li&gt;
&lt;li&gt;Security Alliance / SEAL Intel&lt;/li&gt;
&lt;li&gt;Calendly Trust &amp;amp; Safety&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;A Chainabuse submission was considered but deliberately not forced because no malicious wallet address, transaction, or second-stage payload was received in this case.&lt;/p&gt;

&lt;p&gt;That distinction is important. Threat reporting becomes less useful when investigators are given indicators that were never actually observed in the incident.&lt;/p&gt;

&lt;h2&gt;
  
  
  Defensive takeaway
&lt;/h2&gt;

&lt;p&gt;If someone approaches you for a crypto podcast, VC interview, conference, or media opportunity:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Independently verify the organization through its official website.&lt;/li&gt;
&lt;li&gt;Ask for a verifiable editorial or corporate contact.&lt;/li&gt;
&lt;li&gt;Treat professional social profiles as context, not identity proof.&lt;/li&gt;
&lt;li&gt;Be cautious when the process moves toward custom conferencing or translation software.&lt;/li&gt;
&lt;li&gt;Never run commands or install software just because a call "requires" it.&lt;/li&gt;
&lt;li&gt;Never connect or sign with a wallet for identity verification.&lt;/li&gt;
&lt;li&gt;Preserve evidence before confronting the sender.&lt;/li&gt;
&lt;li&gt;Keep legitimate infrastructure separate from malicious indicators.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;The most dangerous social-engineering campaigns are often not the ones that look obviously malicious.&lt;/p&gt;

&lt;p&gt;They are the ones that look professional until the final step.&lt;/p&gt;

</description>
      <category>security</category>
      <category>web3</category>
      <category>cybersecurity</category>
      <category>osint</category>
    </item>
  </channel>
</rss>
