Crypto Times Logo Black
Google News Follow Banner
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • DeFi News
    • Blockchain News
    • Industry
  • Exclusive
    ExclusiveShow More
    CLARITY Act Clears Senate Banking Committee 15-9 Here’s What Every Crypto Leader Is Saying
    CLARITY Act Clears Senate Banking Committee 15-9: Here’s What Every Crypto Leader Is Saying
    GENIUS Act stablecoin regulation 2026 — US Treasury, OCC, FDIC and NCUA rulemaking on federal vs state oversight
    GENIUS Act at 10 Months: Inside America’s New Stablecoin Rulebook
    $10.8 Million Drained Inside the THORChain Exploit That Froze Cross-Chain DeFi for 13 Hours
    $10.8 Million Drained: Inside the THORChain Exploit That Froze Cross-Chain DeFi for 13 Hours
    BG Wealth and DSJ Exchange collapse exposes 2026 crypto scam pipeline
    How BG Wealth and DSJ Exposed the New Pipeline Model Behind 2026 Crypto Fraud
    Chainalysis’ Regional Director on Asia’s Crypto Growth and Stablecoin Revolution
    Exclusive: Chainalysis’ Regional Director on Asia’s Crypto Growth and Stablecoin Revolution
  • Opinion
    OpinionShow More
    The CLARITY Act The Final Hand — Everyone's Bluffing, Nobody's Folding, and Thursday Changes Everything
    The CLARITY Act: The Final Hand — Everyone’s Bluffing, Nobody’s Folding, and Thursday Changes Everything
    WazirX Debuts ‘Guardians of Trust’ Hub Security Pivot or Distraction from the 15% Debt
    WazirX Debuts ‘Guardians of Trust’ Hub: Security Pivot or Distraction from the 15% Debt?
    What Does Bitcoin Become in a World Questioning the Dollar?
    What Does Bitcoin Become in a World Questioning the Dollar?
    What Happens to the One Asset Designed to Escape Control
    What Happens to the One Asset Designed to Escape Control?
    A System Built on Control, and a Question That Refuses to Settle
    A System Built on Control, and a Question That Refuses to Settle
  • Learn
    • Explained
    • How To
    • Insights
  • Podcasts
  • More
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
The Crypto TimesThe Crypto Times
  • All News
  • Market
  • Bitcoin
  • Ethereum
  • Altcoins
  • Regulations & Policies
  • Blockchain
  • DeFi
  • Industry
  • Exclusive
  • Opinion
Search
  • News
    • Market
    • Bitcoin
    • Ethereum
    • Altcoins
    • Regulations & Policies
    • Blockchain
    • DeFi
    • Industry
    • Exclusive
    • Opinion
  • Learn
    • Explained
    • How To
    • Insights
  • Quick Links
    • About Us
    • Our Authors
    • Contact Us
    • Editorial Policy
    • AI Policy
    • Sponsored & Advertorial Policy
  • Podcasts
Follow US
© 2026 By Crypto Times. All Rights Reserved.
Industry

Crypto Users on MacOS Targeted in Sneaky Token Vesting Malware Scam

The attachments shared in email to victims seem regular documents, but it all was disguised AppleScript malware.

Written By:
Kenrodgers Fabian

Reviewed By:
Gopal Solanky

Last updated: February 4, 2026 11:00 AM
Published February 3, 2026 12:31 PM
Share
Last updated: February 4, 2026 11:00 AM
Published February 3, 2026 12:31 PM
Crypto Users on MacOS Targeted in Sneaky Token Vesting Malware Scam

Key Highlights

  • Mac users face new phishing risks; fake audit emails can steal passwords and install hidden malware.
  • Hackers use disguised AppleScript files and backdoors to control Macs and bypass privacy protections.
  • Phishing and wallet related scams gain as crypto’s popularity grows worldwide.

Blockchain security firm SlowMist has warned that a new phishing attack is putting macOS users at high risk. In a latest post, the firm shared that Chainbase Lab has detected a phishing email disguised as an “audit/compliance confirmation.” The emails lured recipients to reveal sensitive information, including system credentials. 

Chainbase also revealed the malicious samples with SlowMist for deeper analysis. Both the firms confirmed that the campaign uses multi-stage, fileless malware specifically targeting Mac devices. 

🚨 Threat Intelligence | Analysis of Token Vesting Phishing Poisoning 🚨

Recently, @ChainbaseHQ detected a phishing email campaign disguised as “audit/compliance confirmation” and shared the sanitized samples with the SlowMist team. We jointly analyzed the campaign and confirmed… pic.twitter.com/0em6y2M1k6

— SlowMist (@SlowMist_Team) February 3, 2026

The attackers initially ask users to “confirm the company’s legal English name,” then share a follow up email titled “FY2025 External Audit” or “Token Vesting Confirmation — deadline.” These messages contain Word or PDF attachments. 

However, these attachments are not regular documents, but rather disguised AppleScript malware. Opening these attachments allows the victims to unknowingly install malware that can allow hackers to steal important information from them. As such, this malware campaign is a mix of social engineering, technical deception, and sophisticated memory-resident malware.

How the malware works on macOS

The malware file is given the name “Confirmation_Token_Vesting.docx.scpt” and is designed to appear as a legitimate document file due to its use of a double extension. Once executed, the malware displays fake progress bars to resemble a system update or repair process. 

At the same time, it will display legitimate-looking password prompt pop-ups to steal system credentials. “When the user enters a password and clicks ‘OK,’ the script invokes the dscl command to verify whether the password is correct,” SlowMist said.

The malware also tries to sneak past Mac’s built-in privacy protections. It quietly gives itself access to your files, camera, screen, and keyboard. On top of that, it installs a hidden program that lets hackers control your Mac and run additional harmful code. The backdoor connects to a remote server to collect information about your Mac and run more harmful programs. Hackers hide their tracks using temporary websites like sevrrhst[.]com.

Connection to broader crypto phishing trends

This is not the first time SlowMist has alerted cryptocurrency users. In January 2026, the company raised awareness regarding a MetaMask scam involving false two-factor authentication messages. The victims were redirected to false sites, leading them to leak their seed phrases. 

🚨 New #metamask phishing scam alert

Attackers are impersonating a “2FA security verification” flow, redirecting users via look-alike domains to fake security warnings with countdown timers and “authenticity checks.”

The final step asks for your wallet recovery phrase — once… pic.twitter.com/3bX9U1wZbs

— SlowMist (@SlowMist_Team) January 5, 2026

In December 2025, a phishing attack occurred on a Solana digital wallet, causing users to sign transactions and resulting in the loss of over $3 million worth of cryptocurrency. The hackers changed the ownership of the digital wallet, giving themselves complete access without the owner’s knowledge. SlowMist explained, “You thought you just connected your crypto wallet to a website, but in reality, you gave all your money to a stranger.”

Besides going after wallets, SlowMist also warned earlier about AI-powered phishing. Hackers tampered with AI search results to show fake imToken wallet links. People who clicked these links risked malware or phishing attacks. Hence, the firm emphasized checking all URLs carefully and only downloading wallets from official sources.

🚨SlowMist Security Alert🚨

Beware of AI Pollution! We tested mainstream AI assistants for @imTokenOfficial's official website — some returned phishing links!🎣

✅The official website of imToken is: https://t.co/LnehWwXDE0

⚠️AI boosts productivity, but many treat it as a… pic.twitter.com/m3FQ9TkbbG

— SlowMist (@SlowMist_Team) April 3, 2025

This Mac phishing attack shows how clever hackers are becoming. People should be careful with unexpected emails, check attachments before opening, and make sure links are real.

Also Read: Korea’s FSS Launches VISTA to Combat Crypto Price Rigging

Disclaimer: The information researched and reported by The Crypto Times is for informational purposes only and is not a substitute for professional financial advice. Investing in crypto assets involves significant risk due to market volatility. Always Do Your Own Research (DYOR) and consult with a qualified Financial Advisor before making any investment decisions.

Follow The Crypto Times on Google News to Stay Updated!      Google News
Google News Banner

TAGGED:BlockchainCrypto Scam
Share This Article
Whatsapp Whatsapp LinkedIn Telegram Copy Link
Fabian is Crypto Journalist at The Crypto Times
By Kenrodgers Fabian
Follow:
Kenrodgers Fabian is a Content Writer with over 3 years of experience in crypto news, data analysis, and IT. With a degree in Health Records and Information Technology, he brings a structured and analytical approach to digital reporting. Kenrodgers focuses on delivering accurate, informative content that helps readers stay updated on the latest trends in crypto and emerging technologies.
Gopal Solanky - Crypto Research Analyst at The Crypto Times
By Gopal Solanky Sr. Crypto Journalist
Follow:
Gopal Solanky is a Research Analyst and Reporter with over 5 years of experience in DeFi, blockchain, crypto, IT, and financial markets. With a Bachelor's in Computer Applications, he brings a strong technical foundation to his analysis and reporting. Gopal focuses on breaking down complex topics for both seasoned investors and curious readers. His work has been referenced by publications like Business Insider and Vulture.com, highlighting his contributions to industry stories around topics like Huwak Tuah Memecoin and the FTX collapse.

Latest News

Fed Payment Account Plan Could Open Settlement Rails to Crypto Firms
Fed Payment Account Plan Could Open Settlement Rails to Crypto Firms
MAP Bridge Exploit 1 Quadrillion MAPO Minted in Cross-Chain Attack
MAP Bridge Exploit: 1 Quadrillion MAPO Minted in Cross-Chain Attack
DASH Price Rallies 14% in 24 Hours Amid 100% Jump in Trading Volume
DASH Price Rallies 14% in 24 Hours Amid 100% Jump in Trading Volume
Plume Gets Bermuda Green Light for On-Chain Vault Model
Plume Gets Bermuda Green Light for On-Chain Vault Model
Hyperliquid ETFs Show Stronger Early Demand Than Bitcoin Funds
Hyperliquid ETFs Show Stronger Early Demand Than Bitcoin Funds

Find Us on Socials

You may also like

Securitize Q1 Revenue Hits $19.5M as Tokenized AUM Reaches $3.2B

Securitize Q1 Revenue Hits $19.5M as Tokenized AUM Reaches $3.2B

LayerZero Details Single-Verifier Flaw Behind $292M KelpDAO Exploit

LayerZero Details Single-Verifier Flaw Behind $292M KelpDAO Exploit

$6.7M Stolen From Kraken and Coinbase User, Funds Mixed On-Chain

$6.7M Stolen From Kraken and Coinbase User, Funds Mixed On-Chain

Tether Tightens Grip on Twenty One Capital After SoftBank Exit

Tether Tightens Grip on Twenty One Capital After SoftBank Exit

The Crypto Times Logo PNG

Providing real-time, accurate Crypto reporting. Your trusted source for Crypto News and Research.

Stay Updated

All News
Exclusive
Opinions
Learn
Podcasts

Company

About Us
Our Authors
Editorial Policy
AI Policy
Advertorial Policy

Get In Touch

Contact Us
Career

Find Us on Socials

X-twitter Linkedin Telegram Youtube Instagram

© 2026 The Crypto Times | A BITROCK TECHNOLOGIES L.L.C. Company.

DMCA.com Protection Status
  • Terms and Conditions
  • Disclaimer
  • Privacy Policy
  • Cookie policy
Do Not Sell or Share My Personal Information