FrantzGS/theforms-coindesk-impersonation-report

OSINT incident report documenting a suspected CoinDesk podcast impersonation and social-engineering campaign targeting Web3 founders.

0

stars

2

commits

Aug 25, 2026

updated

coindesk
crypto-security
impersonation
incident-response
osint
phishing
social-engineering
threat-intelligence
web3
web3-security

README

TheForms Ventures / CoinDesk Podcast Impersonation Investigation

Public incident report documenting a suspected Web3 social engineering funnel that used the CoinDesk brand, a LinkedIn account presenting as a Venture Scout at TheForms Ventures, and a claimed podcast titled "Why Crypto Became Personal".

Status: Open investigation - public report v1.0 - 25 August 2026
Reporter: Frantz GALINIER-STEFANI
Primary language: English
French version: README.fr.md

Executive warning

On 15 August 2026, a LinkedIn account using the name Denys Kovalov and presenting as a Venture Scout at TheForms Ventures contacted me about a supposed CoinDesk podcast focused on personal crypto journeys.

The process later included:

  • A claimed CoinDesk series titled "Why Crypto Became Personal".
  • TheForms-branded Calendly scheduling.
  • A genuine Google Meet link.
  • A participant displayed as "Jiawei Zhu".
  • A promised French-English AI translation setup that did not work as expected.
  • A discussion about Windows, macOS, ThinkPad and Linux.
  • A proposed follow-up call or platform after Linux was identified as my operating system.
  • A promised follow-up contact named "Valerie".

No software was installed, no wallet was connected, no credentials or private keys were shared, and no financial loss is known.

Why this case matters

A separate founder, Ismail Koseoglu, published a report on 2 July 2026 describing a near-identical approach involving:

  • A person presenting as a Venture Scout at The Forms Ventures.
  • A claimed CoinDesk editorial podcast.
  • A title almost identical to mine: "How Crypto Became Personal".

He says he verified the opportunity directly with CoinDesk and quotes CoinDesk as saying: "None of this is legitimate."

Security Alliance / SEAL Intel has also documented crypto-targeting social engineering campaigns that use fake podcasts, fake VC identities, polished professional profiles and malicious or attacker-controlled conferencing software.

This repository does not claim that any named natural person has been proven to be a criminal actor. It documents observable accounts, claims, communications, public-source anomalies and tactical correlations.

Key findings

  • The CoinDesk brand and a personal crypto journey podcast were used as the initial lure.
  • The claimed series title was "Why Crypto Became Personal".
  • A prior founder documented a highly similar The Forms Ventures / CoinDesk lure in July 2026.
  • The July founder says CoinDesk rejected that podcast and partnership as illegitimate.
  • The booking flow in my case remained TheForms-branded rather than independently CoinDesk-verified.
  • A claimed CoinDesk producer was never independently authenticated before the call.
  • The promised translation failed and the discussion shifted to operating system compatibility.
  • Windows and macOS became relevant after I said I was using Linux.
  • Multiple public LinkedIn profiles display the same long Udemy credential ID for the same course while showing different issue dates. At least three of those profiles are associated with TheForms Ventures. The same credential ID also appears on at least one unrelated Web3 profile, so it must not be treated as a unique TheForms linkage.
  • The identity of the Google Meet participant displayed as "Jiawei Zhu" remains unverified.
  • Security Alliance documents a separate "FormsVC" cluster containing theforms[.]vc. This is not the same domain as theforms.ventures, so no common ownership is asserted here.

Read the report

Attribution discipline

Preferred language in this repository:

  • "the LinkedIn account using the name Denys Kovalov"
  • "the profile presenting as a Venture Scout at TheForms Ventures"
  • "the Google Meet participant displayed as Jiawei Zhu"

This repository does not state that a named natural person has been proven to control an account or to have committed a crime unless independently established by authoritative evidence.

Defensive guidance

If you receive a similar invitation:

  • Verify the media outlet independently using contact details from its official website.
  • Do not treat a polished LinkedIn profile, company page, logo, mutual connection or job title as identity proof.
  • Do not install conferencing, translation or collaboration software supplied through an unsolicited outreach without independent verification.
  • Do not run shell, terminal or PowerShell commands supplied during the process.
  • Do not connect a wallet or sign a transaction or message to "verify" your identity.
  • Preserve screenshots, URLs, timestamps and hashes before confronting the sender.
  • If CoinDesk is being impersonated, CoinDesk currently asks users to report the incident to fraud@coindesk.com.

Search terms

This repository intentionally includes exact terms that future targets may search:

TheForms Ventures CoinDesk
The Forms Ventures CoinDesk
Denys Kovalov TheForms
Why Crypto Became Personal
How Crypto Became Personal
CoinDesk podcast scam
CoinDesk impersonation Web3
TheForms Ventures podcast
Valeriia Kurylo TheForms
Jiawei Zhu CoinDesk
fake crypto podcast interview
Web3 fake VC malware
Windows macOS podcast malware

Public evidence policy

Only redacted evidence belongs in evidence/redacted/.

Private email addresses, meeting codes, Calendly cancellation or rescheduling tokens, raw audio, credentials, wallet secrets and other sensitive artifacts must remain outside the public repository.

Contributors

FrantzGS

2 commits

FrantzGS/theforms-coindesk-impersonation-report

OSINT incident report documenting a suspected CoinDesk podcast impersonation and social-engineering campaign targeting Web3 founders.

0

stars

2

commits

Aug 25, 2026

updated

coindesk
crypto-security
impersonation
incident-response
osint
phishing
social-engineering
threat-intelligence
web3
web3-security

README

TheForms Ventures / CoinDesk Podcast Impersonation Investigation

Public incident report documenting a suspected Web3 social engineering funnel that used the CoinDesk brand, a LinkedIn account presenting as a Venture Scout at TheForms Ventures, and a claimed podcast titled "Why Crypto Became Personal".

Status: Open investigation - public report v1.0 - 25 August 2026
Reporter: Frantz GALINIER-STEFANI
Primary language: English
French version: README.fr.md

Executive warning

On 15 August 2026, a LinkedIn account using the name Denys Kovalov and presenting as a Venture Scout at TheForms Ventures contacted me about a supposed CoinDesk podcast focused on personal crypto journeys.

The process later included:

  • A claimed CoinDesk series titled "Why Crypto Became Personal".
  • TheForms-branded Calendly scheduling.
  • A genuine Google Meet link.
  • A participant displayed as "Jiawei Zhu".
  • A promised French-English AI translation setup that did not work as expected.
  • A discussion about Windows, macOS, ThinkPad and Linux.
  • A proposed follow-up call or platform after Linux was identified as my operating system.
  • A promised follow-up contact named "Valerie".

No software was installed, no wallet was connected, no credentials or private keys were shared, and no financial loss is known.

Why this case matters

A separate founder, Ismail Koseoglu, published a report on 2 July 2026 describing a near-identical approach involving:

  • A person presenting as a Venture Scout at The Forms Ventures.
  • A claimed CoinDesk editorial podcast.
  • A title almost identical to mine: "How Crypto Became Personal".

He says he verified the opportunity directly with CoinDesk and quotes CoinDesk as saying: "None of this is legitimate."

Security Alliance / SEAL Intel has also documented crypto-targeting social engineering campaigns that use fake podcasts, fake VC identities, polished professional profiles and malicious or attacker-controlled conferencing software.

This repository does not claim that any named natural person has been proven to be a criminal actor. It documents observable accounts, claims, communications, public-source anomalies and tactical correlations.

Key findings

  • The CoinDesk brand and a personal crypto journey podcast were used as the initial lure.
  • The claimed series title was "Why Crypto Became Personal".
  • A prior founder documented a highly similar The Forms Ventures / CoinDesk lure in July 2026.
  • The July founder says CoinDesk rejected that podcast and partnership as illegitimate.
  • The booking flow in my case remained TheForms-branded rather than independently CoinDesk-verified.
  • A claimed CoinDesk producer was never independently authenticated before the call.
  • The promised translation failed and the discussion shifted to operating system compatibility.
  • Windows and macOS became relevant after I said I was using Linux.
  • Multiple public LinkedIn profiles display the same long Udemy credential ID for the same course while showing different issue dates. At least three of those profiles are associated with TheForms Ventures. The same credential ID also appears on at least one unrelated Web3 profile, so it must not be treated as a unique TheForms linkage.
  • The identity of the Google Meet participant displayed as "Jiawei Zhu" remains unverified.
  • Security Alliance documents a separate "FormsVC" cluster containing theforms[.]vc. This is not the same domain as theforms.ventures, so no common ownership is asserted here.

Read the report

Attribution discipline

Preferred language in this repository:

  • "the LinkedIn account using the name Denys Kovalov"
  • "the profile presenting as a Venture Scout at TheForms Ventures"
  • "the Google Meet participant displayed as Jiawei Zhu"

This repository does not state that a named natural person has been proven to control an account or to have committed a crime unless independently established by authoritative evidence.

Defensive guidance

If you receive a similar invitation:

  • Verify the media outlet independently using contact details from its official website.
  • Do not treat a polished LinkedIn profile, company page, logo, mutual connection or job title as identity proof.
  • Do not install conferencing, translation or collaboration software supplied through an unsolicited outreach without independent verification.
  • Do not run shell, terminal or PowerShell commands supplied during the process.
  • Do not connect a wallet or sign a transaction or message to "verify" your identity.
  • Preserve screenshots, URLs, timestamps and hashes before confronting the sender.
  • If CoinDesk is being impersonated, CoinDesk currently asks users to report the incident to fraud@coindesk.com.

Search terms

This repository intentionally includes exact terms that future targets may search:

TheForms Ventures CoinDesk
The Forms Ventures CoinDesk
Denys Kovalov TheForms
Why Crypto Became Personal
How Crypto Became Personal
CoinDesk podcast scam
CoinDesk impersonation Web3
TheForms Ventures podcast
Valeriia Kurylo TheForms
Jiawei Zhu CoinDesk
fake crypto podcast interview
Web3 fake VC malware
Windows macOS podcast malware

Public evidence policy

Only redacted evidence belongs in evidence/redacted/.

Private email addresses, meeting codes, Calendly cancellation or rescheduling tokens, raw audio, credentials, wallet secrets and other sensitive artifacts must remain outside the public repository.

Contributors

FrantzGS

2 commits