DEV Community

Cover image for Inside a Suspected Fake CoinDesk Podcast Funnel Targeting Web3 Founders
Frantz GALINIER-STEFANI
Frantz GALINIER-STEFANI

Posted on Originally published at github.com

Inside a Suspected Fake CoinDesk Podcast Funnel Targeting Web3 Founders

On 15 August 2026, I received a LinkedIn message inviting me to discuss my personal crypto journey for a supposed CoinDesk podcast.

At first glance, the approach looked credible.

The sender used a polished LinkedIn profile presenting as a Venture Scout at TheForms Ventures. The pitch was simple, professional, and low-friction. There was no wallet request, no investment offer, no suspicious download, and no obvious phishing page.

That is exactly why I think this case is worth documenting.

The suspicious part did not appear at the beginning. It emerged gradually through identity claims, scheduling, a promised translation setup, and finally a technical discussion about operating-system compatibility.

I preserved the evidence and published a redacted incident report here:

https://github.com/FrantzGS/theforms-coindesk-impersonation-report

The initial lure

The LinkedIn account used the name Denys Kovalov and presented as a Venture Scout at TheForms Ventures.

The message invited me to a CoinDesk podcast about personal crypto journeys.

When I asked for more information, the account named the series:

"Why Crypto Became Personal"

I was told it would be a short audio conversation focused on how guests entered crypto, what they were building, and why crypto had become personally meaningful to them.

Because my spoken English is limited, I asked whether the conversation could work in French.

The answer was that real-time AI translation would handle the language barrier.

So far, nothing required me to install anything.

I asked for an official CoinDesk link

Before scheduling, I asked for a public CoinDesk page or a link to the series.

No public link was provided.

Instead, I was told that it was a fresh series and that the first episodes were still in production.

A new production can legitimately have no public page. That fact alone is not evidence of fraud.

The problem is what happened when this was compared with an independent incident from July 2026.

The booking remained TheForms-branded

The introductory call was scheduled through a TheForms Calendly page:

calendly.com/contact-theforms/30min

The booking flow did not independently authenticate CoinDesk.

Later, the meeting was rescheduled. The LinkedIn account attributed the change to the "CoinDesk team".

Before the replacement meeting, I was told that a producer "on the CoinDesk team" would create the Google Meet invitation and join the call.

I also reconfirmed that French-English translation would be available.

The response was:

"Yes, everything is prepared, no worries."

The Google Meet was real

On 25 August 2026, I received a genuine meet.google.com URL.

This distinction matters.

Google Meet itself was not malicious. Legitimate infrastructure can be used inside a social-engineering workflow.

The participant in the meeting was displayed under the name "Jiawei Zhu".

A display name is not identity verification, so I do not claim that the participant was any particular real-world person with that name.

The meeting was short and the promised translation did not work as expected.

Read AI later recorded the session as a "French English Translation Test".

Then the conversation shifted to Windows, macOS, and Linux

This was the most security-relevant moment.

During the failed translation test, the discussion moved to the computer environment.

Windows and macOS were raised.

I explained that my ThinkPad runs Linux.

The planned setup could not proceed as expected. I recall being told that another call or another platform would be arranged.

I was also told that a person called "Valerie" would contact me on LinkedIn.

No installer was delivered during the completed call.

No .exe, .dmg, package, browser extension, alternate conferencing application, or second-stage domain was sent to me.

Therefore I am not claiming that malware was actually delivered in my specific interaction.

The narrower conclusion is that the operating-system pivot was consistent with known Web3 social-engineering techniques and justified further investigation.

The strongest corroboration came from another founder

This case became significantly more concerning when I found a public report published on 2 July 2026 by Byte Exchange founder Ismail Koseoglu.

His account described:

  • LinkedIn outreach
  • a person presenting as a Venture Scout at The Forms Ventures
  • a supposed CoinDesk editorial series
  • a series titled "How Crypto Became Personal"

That title is strikingly close to the one used in my case:

"Why Crypto Became Personal"

According to Koseoglu's report, he contacted CoinDesk independently.

He quotes CoinDesk as responding:

"None of this is legitimate."

His article says CoinDesk did not have the claimed podcast and was not partnered with the parties mentioned.

That is the strongest external corroboration currently available.

Security Alliance documented a related class of tactics

Security Alliance / SEAL Intel has documented cold-reachout campaigns targeting the crypto ecosystem using tactics such as:

  • fake podcast invitations
  • fake VC identities
  • polished professional profiles
  • trust-building before the malicious step
  • custom conferencing or communication software
  • Windows and macOS malware payloads

Their research also includes a separate cluster called FormsVC and a domain written as theforms[.]vc.

Important caveat:

theforms[.]vc is not the same domain as theforms.ventures.

I am not claiming they share an operator, infrastructure, or ownership.

The relevance is behavioral and useful for threat hunting, not proof of attribution.

What I did not do

No compromise is currently known.

I did not:

  • install software from the contact
  • install a browser extension
  • run a shell or PowerShell command
  • connect a crypto wallet
  • sign a transaction
  • sign an arbitrary wallet message
  • share a seed phrase or private key
  • share passwords or API secrets
  • provide remote desktop access
  • transfer funds

That matters because this report documents a pre-compromise social-engineering chain, not a completed theft.

Attribution discipline matters

One of the easiest ways to damage a useful security report is to overstate what the evidence proves.

For that reason, the public report distinguishes between observed facts, corroborated information, assessment, and unknowns.

For example, I refer to:

  • "the LinkedIn account using the name Denys Kovalov"
  • "the Google Meet participant displayed as Jiawei Zhu"

I do not claim that those display identities independently prove who controlled the accounts.

Why publish this?

The goal is not to create drama around individual names.

The goal is to make the playbook searchable.

A future founder who searches for:

  • TheForms Ventures CoinDesk
  • Why Crypto Became Personal
  • How Crypto Became Personal
  • CoinDesk podcast scam
  • fake crypto podcast interview

should have a chance to find evidence before installing anything.

Public evidence

The repository contains a full English report, a French report, a detailed timeline, redacted screenshots, SHA-256 hashes, methodology and confidence labels, observed identifiers, and external sources.

Public report:

https://github.com/FrantzGS/theforms-coindesk-impersonation-report

The original unredacted evidence remains private and can be provided to legitimate investigators when necessary.

Reports submitted

The incident has been reported to:

  • CoinDesk Fraud
  • Security Alliance / SEAL Intel
  • Calendly Trust & Safety

A Chainabuse submission was considered but deliberately not forced because no malicious wallet address, transaction, or second-stage payload was received in this case.

That distinction is important. Threat reporting becomes less useful when investigators are given indicators that were never actually observed in the incident.

Defensive takeaway

If someone approaches you for a crypto podcast, VC interview, conference, or media opportunity:

  1. Independently verify the organization through its official website.
  2. Ask for a verifiable editorial or corporate contact.
  3. Treat professional social profiles as context, not identity proof.
  4. Be cautious when the process moves toward custom conferencing or translation software.
  5. Never run commands or install software just because a call "requires" it.
  6. Never connect or sign with a wallet for identity verification.
  7. Preserve evidence before confronting the sender.
  8. Keep legitimate infrastructure separate from malicious indicators.

The most dangerous social-engineering campaigns are often not the ones that look obviously malicious.

They are the ones that look professional until the final step.

Top comments (0)