The crypto industry faces a persistent and evolving threat from state-sponsored malware campaigns that bypass traditional security perimeters by exploiting professional trust. On May 28, 2026, Wiz researchers confirmed the discovery of JINX-0164, a previously undocumented threat cluster actively stealing private keys and seed phrases from 51 browser-based cryptocurrency wallet extensions and 26 desktop wallets through a sophisticated fake LinkedIn recruiter campaign. With Bitcoin trading near $73,200 and Ethereum below $2,000 amid a broader market selloff, the timing of this disclosure amplifies concerns about portfolio vulnerability during periods of heightened volatility.
The Exploit Mechanics
JINX-0164 deploys a malware payload called AUDIOFIX that masquerades as a macOS system audio driver (coreaudiod). The attack chain begins with a convincing LinkedIn recruiter profile that invites a target — typically someone working at a crypto exchange, DeFi protocol, or blockchain development firm — to a virtual business meeting on a spoofed domain. Confirmed spoofing domains include teams.live.us[.]org (impersonating Microsoft Teams), bitget-meeting[.]com (impersonating Bitget exchange), and live[.]ong.
During the call, a staged technical fault — a frozen screen, failed audio, or camera error — creates the pretext for the victim to download a troubleshooting script or driver update. This file is fetched from delivery domains such as apple.driver-store[.]com, apple.driver-update[.]io, and driver-updater[.]net. The malware is architecture-aware, running natively on both Intel and Apple Silicon Macs, which significantly broadens its attack surface across the macOS-using crypto workforce.
Once executed, AUDIOFIX conducts an automated credential sweep targeting 51 browser-based cryptocurrency wallet extensions and 26 desktop wallet applications. It harvests credential stores across seven browsers including Chrome, Firefox, Safari, Brave, Edge, and Chromium variants. Beyond wallet data, it exfiltrates SSH private keys, AWS and GCP authentication tokens, Discord tokens, Slack workspace data, Telegram directory contents, and clipboard history with timestamps.
Affected Systems
The scope of compromised systems extends far beyond individual wallets. In April 2026, JINX-0164 operators trojanized the @velora-dex/sdk npm package (version 4.9.1), injecting three lines of code into the package dist/index.js file that silently installed a Go-based backdoor called MiniRAT. This gave the threat actor a second persistent access channel into developer CI/CD pipelines with file upload, download, compression, and shell execution capabilities.
The campaign targets professionals at cryptocurrency exchanges, DeFi protocols, and blockchain development firms. Wiz researchers assess the behavioral patterns as consistent with North Korean financially motivated groups including BlueNoroff, Contagious Interview, and UNC1069, though JINX-0164 maintains distinct infrastructure without confirmed overlap. North Korean threat actors collectively stole $1.3 billion in cryptocurrency in 2024 according to Chainalysis, and the precision targeting of wallet credential stores reflects the same operational doctrine.
Stolen data is exfiltrated to command-and-control domains including datahub[.]ink, cloud-sync[.]online, and byte-io[.]us. AUDIOFIX also supports remote Python code execution, arbitrary shell commands, file deletion, and additional payload retrieval, effectively transforming an infected machine into a persistent remote access foothold.
The Mitigation Strategy
Organizations and individuals must adopt a multi-layered defense posture against JINX-0164 and similar social engineering campaigns. First, verify all recruiter contacts through secondary channels before accepting meeting invitations. Never download software or drivers prompted during a video call, regardless of how legitimate the error appears. Second, audit all npm dependencies for unexpected modifications — particularly packages that have recently changed maintainers or published rapid version updates. Third, deploy endpoint detection that monitors for processes masquerading as coreaudiod that are not signed by Apple. Fourth, use hardware wallets for significant holdings and never store seed phrases in digital format accessible to browser-based malware.
For teams running CI/CD pipelines, implement lockfiles and integrity checks on all third-party packages. The @velora-dex/sdk compromise demonstrates that supply chain attacks remain one of the most effective vectors for gaining access to developer infrastructure.
Lessons Learned
The JINX-0164 campaign reinforces several critical lessons for the crypto security community. The attack exploits no software vulnerabilities — it exploits professional trust and social norms around remote collaboration. As the crypto industry increasingly operates in distributed, remote-first environments, the attack surface for social engineering campaigns grows proportionally. The convergence of AI-generated deepfakes and increasingly convincing fake profiles will only amplify these threats in the coming months.
The trojanization of the @velora-dex/sdk package also underscores the fragility of the open-source software supply chain. A single compromised package can propagate backdoor access across dozens of downstream projects and their production environments.
User Action Required
If you work in cryptocurrency, DeFi, or crypto-adjacent software development and use macOS, take immediate action. Check your installed browser extensions for unrecognized wallet add-ons. Rotate credentials for any wallet that was accessible on a machine that may have been compromised. Audit your npm lockfiles for the @velora-dex/sdk package version 4.9.1. Enable two-factor authentication on all exchange accounts and consider migrating funds to hardware wallets until the full scope of JINX-0164 infections is understood. Report any suspicious LinkedIn recruiter contacts to your security team immediately.
Disclaimer: This article is for informational purposes only and does not constitute financial or security advice. Always consult with qualified cybersecurity professionals for incident response.
51 browser extensions AND 26 desktop wallets. this thing was casting the widest net ive seen all year
51 browser extensions and 26 desktop wallets hit by AUDIOFIX in seconds via JINX-0164, that net is insane
77 wallets in a single malware payload. whoever built this was building for maximum coverage not targeting one specific protocol
The fake LinkedIn recruiter angle is exactly how Bybit got hit in February. When are crypto firms going to stop letting engineers use personal machines for anything work-related?
fake linkedin recruiters pushing this to devs is wild, exactly like the bybit feb hit
Mia R. exact same playbook as Bybit. spoofed meeting domain plus social engineering. crypto firms need dedicated airgapped work laptops, period
bybit got hit the exact same way in feb. fake recruiter, malicious meeting link, compromised machine. crypto firms need dedicated locked down work devices
Kira M. the budget excuse is insane. bybit lost $1.46B to the same social engineering playbook and firms still complain a locked down laptop costs too much. what does a single drainer incident cost vs a thinkpad
coreaudiod spoofing is nasty. even technical users wont kill it because it might break audio. malware author understood macOS psychology perfectly
coreaudio_rat exact same playbook as the Bybit hack. spoofed meeting domain plus social engineering. firms keep making the same mistake
coreaudiod impersonation on macOS is nasty. most people would never check if that process is legit
JINX-0164 hitting 51 browser extensions and 26 desktop wallets from one fake recruiter campaign is unprecedented coverage
77 wallets in one payload. this was built for maximum coverage not a single target. the fake LinkedIn recruiter net is massive
coreaudiod is a legit macOS system process. even tech savvy users would glance at it in activity monitor and think nothing of it. really clever social engineering
Tanaka Y. activity monitor doesnt show code signing certificates either. youd need to run codesign -dv on the binary path to even start checking. no regular user is doing that
coreaudiod spoofing is genius honestly. even suspicious users would second guess killing it because it might break audio. perfect hiding spot
kernel_panic_ exactly. killing coreaudiod feels destructive even to technical users. the malware author understood macOS user psychology better than most security trainers
77 wallets compromised in seconds and crypto startups still wont spring for dedicated work laptops. a $1500 chromebook for signing transactions would have stopped this entire attack chain
77 wallets in one payload and firms still let devs use personal macbooks for key signing. the $1500 chromebook take is correct and underdiscussed
Defne Y. the 1500 chromebook argument is peak security theater savings. one drainer incident costs more than equipping every dev with a dedicated laptop for the next decade
teams.live.us[.]org is such a clean spoof. even the subdomain structure matches Microsoft naming conventions. only way to catch it is reading the TLD and who does that on a meeting invite
bitget-meeting.com spoofing domain is crazy. someone registered that specifically because people type it fast without checking. social engineering at industrial scale