
CoinDesk Podcast Network The Blockspace Pod: How North Korean Hackers Stole $300M+ Via Telegram w/ Taylor Monahan
Jan 31, 2026
Taylor Monahan, MetaMask security lead and crypto researcher known for tracking Lazarus Group hacks. She walks through a $300M Telegram phishing scam, how hijacked accounts and fake Zoom calls deliver stealthy malware, which wallets are most at risk, and practical steps for recovery and stronger digital hygiene.
AI Snips
Chapters
Transcript
Episode notes
Victim Account Used To Deliver Fake Zoom
- Taylor Monahan described joining a fake Zoom call served from a hijacked Telegram account that prompted her to run an AppleScript.
- The call showed a recorded video of the contact and convinced her to run Terminal commands that installed persistent malware.
Hijacked Accounts Are High-Trust Vectors
- Attackers prefer hijacked Telegram accounts because message history and real contacts make the outreach extremely convincing.
- They mass DM contacts, schedule calls, then use legitimate-looking Calendly and video UI to lower suspicion.
Stop, Verify, And Isolate Before Running Code
- If you join a suspicious call that asks you to run scripts, refuse and pause the interaction to verify independently.
- Turn off Wi‑Fi and wipe the device immediately if you suspect the malware executed.
