CoinDesk Podcast Network

The Blockspace Pod: How North Korean Hackers Stole $300M+ Via Telegram w/ Taylor Monahan

Jan 31, 2026
Taylor Monahan, MetaMask security lead and crypto researcher known for tracking Lazarus Group hacks. She walks through a $300M Telegram phishing scam, how hijacked accounts and fake Zoom calls deliver stealthy malware, which wallets are most at risk, and practical steps for recovery and stronger digital hygiene.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Victim Account Used To Deliver Fake Zoom

  • Taylor Monahan described joining a fake Zoom call served from a hijacked Telegram account that prompted her to run an AppleScript.
  • The call showed a recorded video of the contact and convinced her to run Terminal commands that installed persistent malware.
INSIGHT

Hijacked Accounts Are High-Trust Vectors

  • Attackers prefer hijacked Telegram accounts because message history and real contacts make the outreach extremely convincing.
  • They mass DM contacts, schedule calls, then use legitimate-looking Calendly and video UI to lower suspicion.
ADVICE

Stop, Verify, And Isolate Before Running Code

  • If you join a suspicious call that asks you to run scripts, refuse and pause the interaction to verify independently.
  • Turn off Wi‑Fi and wipe the device immediately if you suspect the malware executed.
Get the Snipd Podcast app to discover more snips from this episode
Get the app