Official MASTR logo MASTR
Menu
Read the publication

Phishing, exploits & privacy

BlockLayerPod and BeaconLayerPod: the phishing network

A detailed investigation of interview invitations, impersonated podcasts and the attempt to compromise creators’ devices.

Original publication · 19 Jun 2026. Figures, claims and opinions reflect the original publication date.

The original publications are in English. Navigation is available in seven languages.

Original article cover
Original article cover Open full-size image ↗

Originally published as “The CT BlockLayerPod and BeaconLayerPod Phishing Ring on X”

A Coordinated Crypto Twitter Scam Targeting Creators, Builders and Artists

A sophisticated phishing operation has been targeting people across Crypto Twitter for months. The attackers approach creators, builders, researchers, artists and influencers with personalised invitations to appear on a podcast. The accounts contacting them often look credible. They have old registration dates, verification badges, professional branding, large follower counts and convincing posting histories.

The podcast does not exist in any meaningful sense. The interview is bait.

Behind the polished messages, scheduling links and recording instructions is an attempt to install malware, steal browser credentials, compromise devices and drain cryptocurrency wallets. The operation has repeatedly appeared under the names BlockLayerPod and BeaconLayerPod, although community investigations suggest that the same people may have used other brands before adopting these identities.

The campaign is dangerous because it does not resemble the usual low effort crypto scam. The messages are written specifically for each target.

They mention recent artwork, projects, posts or professional interests. The attackers spend time building trust and do not immediately ask for a wallet connection, seed phrase or payment.

They behave like podcast producers because that is exactly what they want the victim to believe.

The First Public Warnings:

Public warnings began spreading in April 2026, although the infrastructure and methods behind the operation appear to go back much further.

On 17 April, @Trail2Crypto described receiving a message from @KieranSolberg inviting him to participate in a two part episode for @BlockLayerPod. Nothing about the initial approach looked obviously fraudulent. The account had existed since 2009. BlockLayerPod presented itself as a professional media company based in New York, had more than 113,000 followers and published content that appeared consistent with a legitimate crypto podcast.

The account also posted job advertisements and maintained the kind of professional facade that usually discourages further scrutiny.

The supposed interview was cancelled shortly before it was scheduled to begin. An .ics calendar file had also been sent during the process. After seeing similar reports involving other people, @Trail2Crypto became suspicious and publicly warned the community.

Several days later, the scale of the operation became clearer.

On 20 and 21 April, @ZhugeLyang published details about what he described as a fake podcast operation involving compromised accounts, impersonation and potentially AI generated material. He had received a Calendly link and professional looking emails connected to several suspicious profiles, including @BlockLayerPod, @TheaKaage, @kenzixbt, @punk5268 and an account using the name @SachiTakahara.

The last account appeared to be impersonating a real person associated with SentientAGI, whose genuine account was reportedly @0xsachi.

When the profiles were examined together, a pattern emerged. They followed one another, interacted with the same central podcast account and appeared to operate as part of the same network. Some of the supposed podcast episodes attracted repetitive or unnatural comments from accounts that looked automated. Audio and guest material also raised questions about whether any real interviews had taken place.

@ZhugeLyang publicly tagged X safety personnel, including @nikitabier, and asked the platform to investigate.

Nothing.

Around the same time, @BenSyne reported the network to X after discovering that targets were being instructed to run terminal commands to access a supposed streaming platform. No legitimate podcast requires a guest to paste unknown commands into a terminal. That instruction alone revealed the real purpose of the operation: remote code execution and malware installation.

The Operation Continued

The warnings did not stop the campaign.

During May and June, more creators reported receiving similar messages. The branding changed, backup accounts appeared and new identities were introduced, but the basic script remained almost identical.

On 12 June, @Crypto_Preston described a near miss after receiving a highly personalised invitation referencing his Christian artwork. The message was designed to anticipate suspicion. The sender reassured him that no wallet connection or seed phrase would ever be required, then attempted to move the conversation towards Calendly and the supposed interview process.

That reassurance was not accidental. Crypto users are trained to recognise direct requests for seed phrases and wallet connections. The attackers therefore addressed those concerns before the victim could raise them. The goal was to make the interaction feel safer than an ordinary crypto transaction while directing the victim towards a different attack surface.

@Crypto_Preston identified several other creators who had reportedly been targeted, including @0xRoses0x, @AVOID_TheArtist, @N3on_Samurai, @GuidoDisalle and @nft_dreww.

On 13 June, bro @zubic_eth published a broader warning connecting the campaign to earlier podcast scams and documenting its apparent rebranding history. On 19 June, @nft_dreww listed accounts that were allegedly still involved and called for their removal from X.

Despite repeated public reports, parts of the network appeared to remain active. At least 1 person stated that X had reviewed a report and found nothing wrong with the account involved.

Every day a compromised or fraudulent account remains active gives it more time to approach new victims while benefiting from the credibility created by its follower count, age and verification status.

How the Scam Works

The operation follows a carefully constructed sequence.

It begins with research. The attackers identify people who are active in crypto, particularly those involved in art, NFTs, trading, research, token projects or public commentary. They examine recent posts and use that information to write a message that feels specific rather than automated.

An artist might be contacted about a particular collection. A researcher might be praised for a recent thread. A builder might be invited to discuss a project launch or technical development. The message is designed to create the impression that the podcast team already understands the target’s work.

Once contact has been established, the attackers begin constructing legitimacy.

They send Calendly invitations, professional emails, proposed interview questions, episode structures and requests for photographs or biographies. They may discuss editing, promotion, recording quality or publication dates. Every additional detail makes the interaction feel more like an ordinary media booking.

The social media accounts reinforce the illusion. Many have old creation dates, large follower counts, verification badges and polished biographies. Some advertise open positions or link to websites that appear professional at first glance. Closer inspection has reportedly revealed placeholder text, incomplete pages and other signs that the businesses behind them may not be genuine.

The attackers may also publish supposed podcast clips or previous episodes. Community investigators have alleged that some of this material was assembled from stolen audio, edited recordings or synthetic content. In certain cases, people presented as former guests reportedly denied ever being interviewed.

The attack itself usually arrives after trust has already been established.

The victim receives a recording invitation, a calendar file, a Zoom or StreamYard link, a browser extension, an application download or instructions for accessing a custom streaming platform. Some victims were reportedly told to run a command in their terminal because the recording software required a particular configuration.

That is the point where the social engineering becomes malware delivery.

The file, link or command may install an information stealer capable of collecting browser sessions, passwords, authentication cookies, cryptocurrency wallet data and other sensitive information. On macOS, similar campaigns have distributed malware related to AMOS Stealer. Other variants may target Windows systems or use remote access tools.

The attackers do not necessarily need the victim to type a seed phrase into a phishing page. If they compromise the browser, steal active sessions, access local wallet files or obtain remote control of the device, they may be able to reach the same result without ever asking the obvious question.

This is why the campaign is more dangerous than a basic wallet drainer. The target believes they are preparing for a professional interview, not authorising a cryptocurrency transaction.

The Accounts Around the Network

The main account repeatedly named in public warnings is @BlockLayerPod, sometimes appearing as @BlockLayerPods. At the time of several reports, it reportedly had more than 113,000 followers and presented itself as a professional crypto media brand.

A second identity, @BeaconLayerPod, has been described as a backup account or later rebrand.

Other accounts mentioned across the warnings include @TheaKaage, @kenzixbt, @SachiTakahara, @SachiMiyasaki, @kenzimori, @DikshaWells and @KieranSolberg.

Several accounts using names based on “punk” have also appeared, including @punk5268, @punk0439, @punk6583 and @punk3626. Additional variants have reportedly surfaced as older accounts attracted attention or were restricted.

The exact relationship between every account has not been publicly established. Some may be compromised accounts whose original owners lost access. Others may be fabricated identities, impersonators or profiles purchased specifically for the campaign.

What connects them is their repeated interaction with the same podcast brands, their overlapping follower networks and their involvement in nearly identical interview approaches.

The network gives the impression of a broader organisation. One account acts as the host. Another appears to be a producer. A third presents itself as a previous guest, employee or industry contact. Each identity supports the credibility of the others.

In reality, the entire structure may be controlled by a small number of operators.

Investigators have also reported connections routed through VPN infrastructure, including German exit locations, although an IP address or VPN location does not establish where an attacker is physically based. Supporting accounts frequently use NFT profile pictures and produce generic replies that make the podcast pages appear more active than they really are.

AI may also be helping the attackers scale their work. Personalised emails, tailored invitations and convincing professional messages can now be produced quickly from a target’s public posts. Synthetic audio and edited clips can make a nonexistent podcast appear to have an established history.

The technology improves the presentation. The underlying crime remains ordinary credential theft and wallet extraction.

Who Is Being Targeted

The campaign appears to focus on people whose public activity signals access, influence or cryptocurrency exposure.

Crypto researchers and alpha accounts may hold valuable wallets or have access to private communities. Builders may control project funds, deployment keys or administrative accounts. NFT artists may hold valuable collections or receive regular cryptocurrency payments. Influencers and content creators often manage several social media profiles, wallets and communication platforms from the same device.

A single successful compromise can therefore provide more than access to 1 wallet.

It may expose private messages, unpublished project information, customer data, authentication tokens, cloud accounts and contact lists. A stolen X account can then be used to approach the victim’s followers, promote malicious links or continue the fake interview campaign under another trusted identity.

This creates a cycle. One compromised account becomes the credibility layer for the next attack.

The exact financial damage attributed specifically to BlockLayerPod and BeaconLayerPod is not publicly known. Victims may remain silent because they are embarrassed, fear reputational damage or are cooperating with private investigators and law enforcement.

Community reports nevertheless indicate that people have lost funds to operations using this method.

The absence of a confirmed total should not be mistaken for the absence of victims.

The Earlier Version of the Scam

Fake podcast scams have been targeting the crypto industry since at least 2025.

Previous operations impersonated recognised media companies or created professional looking podcast brands, then invited crypto figures to interviews hosted through malicious websites or fake recording platforms. Some campaigns used links designed to steal wallet credentials. Others distributed information stealing malware directly.

A widely reported operation involving a fake podcast called Empire reportedly targeted crypto influencers with macOS malware associated with AMOS Stealer. Other campaigns impersonated CoinDesk or used similar media branding to make phishing links appear legitimate.

According to the investigation published by @zubic_eth, the people behind BlockLayerPod and BeaconLayerPod may previously have operated under the name Web3Unchained. That earlier campaign allegedly used the same sequence of podcast invitations followed by malware delivery and was linked to more than $100,000 in stolen funds.

That connection has not been independently proven in this summary, but the similarities are difficult to ignore. The social engineering structure, account relationships, interview process and final malware stage all follow the same pattern.

The names change because the names are disposable.

Once a podcast brand becomes searchable alongside warnings and scam reports, the operators can move to a new account, modify the design and repeat the process. Compromised profiles with established histories give them an almost unlimited supply of new identities.

Why This Operation Works

Most crypto users expect scams to look like scams.

They expect spelling mistakes, fake giveaways, suspicious token promotions, wallet connection requests and strangers promising impossible returns. They do not necessarily expect a patient, professionally written conversation that develops over several days.

The BlockLayerPod approach exploits ambition rather than greed.

Creators want exposure. Artists want their work discussed. Builders want to explain their projects. Researchers want recognition for their analysis. A credible podcast invitation feels like an opportunity, especially when the sender demonstrates familiarity with the target’s work.

The attackers weaponise that desire without immediately introducing money.

By the time the malicious file or recording instruction arrives, the victim may already have exchanged several messages, answered interview questions, shared photographs and placed the appointment in their calendar. Every completed step creates additional psychological commitment.

The account’s follower count then replaces actual verification. People assume that an account followed by 113,000 users must have been examined by someone else. They treat the verification badge, old registration date and mutual followers as evidence that the organisation is real.

None of those signals proves who currently controls the account.

An old account can be hacked. Followers can be purchased. Verification can be obtained under false pretences. Mutual followers may be bots, compromised profiles or people who never investigated the account themselves.

Credibility on social media can be manufactured, inherited or stolen.

The Situation in June 2026

As of June 2026, the operation appeared to remain active.

New warnings continued to emerge, backup identities were still being identified and creators were still receiving personalised podcast invitations. Several accounts associated with the network remained visible despite repeated reports.

The lack of decisive platform enforcement increases the burden on users to investigate every approach themselves. That is particularly difficult when an invitation comes from an account that appears established and has interacted publicly with recognised figures.

The safest assumption is no longer that a professional looking account is legitimate until something suspicious happens. In crypto, the account itself may already be the compromised asset.

Protecting Yourself

An unsolicited podcast invitation should never be trusted solely because the sender has a verification badge, an old account or a large audience.

Verify the organisation independently. Search for the podcast outside X. Check whether its website contains real company information, previous episodes and verifiable guests. Contact former guests through separate channels and ask whether they actually participated.

Do not rely on links provided by the person inviting you.

A Calendly link is not proof of legitimacy. Anyone can create a scheduling page. An .ics file is not automatically harmless. Calendar files can contain links, meeting instructions and other content intended to move the victim towards the next stage of an attack.

Never install software, browser extensions or recording tools provided through a direct message. Never paste commands into Terminal, PowerShell or Command Prompt because a supposed producer claims they are required for an interview.

Legitimate recording platforms do not need random guests to execute unknown code.

Use a separate device or isolated browser profile for interviews and unfamiliar communication platforms. Keep cryptocurrency wallets away from the computer used for routine social media activity. Hardware wallets reduce some risks, but they cannot protect users who approve malicious transactions or expose credentials through a compromised device.

Enable strong 2 factor authentication, preferably through a hardware security key. Review active sessions regularly and remove browser extensions that are no longer required. Store valuable assets across separate wallets rather than concentrating everything in the same browser environment.

Anyone who has already opened a suspicious file or executed a command should disconnect the device from the internet, stop using it for wallet activity and assume that stored passwords and browser sessions may be compromised. Passwords should be changed from a clean device, active sessions should be revoked and cryptocurrency assets should be moved using a system that has not been exposed.

Victims should preserve messages, email headers, files, wallet addresses, transaction hashes and screenshots. Evidence disappears quickly when accounts are renamed, deleted or suspended.

Final Words from me

The BlockLayerPod and BeaconLayerPod campaign shows how far crypto phishing has moved beyond obvious wallet connection traps.

The attackers are building complete professional identities around the scam. They use established accounts, personalised research, fake media brands, scheduling systems, convincing emails and supposed podcast material to lower the target’s defences before introducing malware.

The interview is not the attack. It is the story used to guide the victim towards the attack.

The people exposing this network have done work that the platform itself should have done much earlier. Their warnings have helped creators recognise the pattern, compare accounts and avoid potentially catastrophic compromises.

But public warnings only work when people take them seriously.

A large follower count proves nothing. A verification badge proves very little. An account created in 2009 may still be controlled by someone who obtained access yesterday.

In crypto, trust should never be inherited from the appearance of an account. It must be verified independently, every single time.

-By MASTR;

https://linktr.ee/askmastr.xyz

Thank you for your support.

MASTR will continue tracking this network, documenting new accounts and warning the community as long as the operation remains active. Do not trust an account because it is old, verified or followed by thousands of people. Those signals can be bought, stolen or manufactured.


Verify every interview request independently. Never install software, open unknown files or run terminal commands for anyone claiming to represent a podcast. If you have been contacted by these accounts, preserve the evidence, report them and warn others. Silence protects the scammers. Exposure makes their operation harder, more expensive and far less effective.

Sources & original posts

Original evidence (1)
MASTR

Support independent research

The investigations, original evidence and guides here are free to read. Voluntary donations help fund the research and keep MASTR’s tools available.

Open wallet