AI scams in crypto approach breaking point – OpenAI’s new image model shows why they could get worse

AI NewsApril 26, 2026·5 min read

OpenAI’s newly released image generation model has dramatically lowered the technical barrier to creating convincing deepfake video calls, enabling social engineers to impersonate verified contacts in the crypto industry with near-perfect authenticity. A Cardano Foundation contact’s compromised Telegram account was weaponized this week to launch a multi-stage attack against a crypto founder, demonstrating that the theoretical risk of AI-assisted social engineering has moved into active deployment against institutional targets.

  • A crypto founder’s laptop was compromised via a spoofed Microsoft Teams call impersonating Pierre Kaklamanos, a known Cardano Foundation contact, using matching video and voice.
  • Microsoft documented February-March 2026 campaigns using malicious files disguised as msteams.exe and zoomworkspace.clientsetup.exe, paired with phishing prompts directing users to run terminal commands.
  • Pierre Kaklamanos confirmed his Telegram account was hacked and used to continue impersonating him after the initial call, signaling an active, ongoing campaign targeting crypto industry relationships.
  • Feb-Mar 2026 Timeframe of Microsoft-documented malware campaigns impersonating workplace software
  • 3 Other industry figures targeted alongside Kaklamanos in coordinated account compromise wave
  • Apr. 24 Date Kaklamanos publicly disclosed his Telegram compromise and warned followers

A technical founder described as “quite technically savvy” accepted what appeared to be a legitimate video call from a Cardano Foundation colleague on Microsoft Teams, only to discover mid-call that the entire interaction was orchestrated social engineering.

The attacker’s video feed and voice matched the contact’s known appearance and manner; two additional participants presented themselves as foundation members. When the call experienced lag and disconnected, a fake update prompt instructed the founder to reinstall Teams software through the Terminal command line.

He executed the command before the laptop battery died, which interrupted the attack and limited system compromise. The incident reveals how video authentication, long treated by security professionals as the final verification layer that users could trust, has become accessible to attackers capable of generating synthetic media.

The attack succeeded precisely because context and familiarity made it credible; the founder had prior contact with the impersonated individual, and the institutional setting removed obvious red flags.

Microsoft Tracks Malware Campaigns Disguised as Workplace Software Updates

Microsoft’s security team documented two parallel waves of attacks during February and March 2026 in which malicious executables were named to mimic legitimate workplace applications. Attackers distributed files labeled msteams.exe and zoomworkspace.clientsetup.exe, paired with social engineering lures that replicated the appearance and messaging of authentic Teams and Zoom meeting invitations.

Once users executed these files, the malware gained initial system access, typically targeting credentials stored locally or in connected services.

A complementary attack pattern, which Microsoft labeled “ClickFix”-style, targeted macOS users with fake system prompts that appeared to originate from the operating system itself. These prompts instructed users to paste pre-written commands into Terminal, claiming that system updates or security patches were required.

The actual commands were designed to extract browser passwords, cryptocurrency wallet credentials, cloud service authentication tokens, and developer API keys from the compromised system.

By combining a fake software update narrative with terminal command injection, attackers bypassed both user hesitation and traditional endpoint detection, since legitimate system administration often involves terminal use on macOS.

The sophistication of these campaigns lies in their multi-layered social engineering structure. The fake update serves as the initial trust anchor; the specific application names (Teams, Zoom) tie the attack to legitimate business workflow; and the terminal command framing makes the execution request appear technical rather than suspicious.

For crypto and blockchain firms, where developers and founders routinely use terminal and often store keys locally, this attack vector is particularly effective.

Google Cloud’s Mandiant Confirms AI-Assisted Deepfake Impersonation in Crypto-Focused Attack

Google Cloud’s Mandiant threat intelligence unit separately analyzed a crypto-industry-focused intrusion that followed an almost identical operational pattern, but with one critical addition: the use of AI-generated video media. The attackers began by compromising a messaging account on Telegram, then used that access to schedule spoofed video meetings on Zoom.

During the call, participants saw what Mandiant described as a “deepfake-style” executive video, likely AI-generated, alongside social engineering dialogue designed to build false urgency and legitimacy.

Mandiant stated it could not independently verify which specific AI model generated the video, or even confirm with absolute certainty that an AI tool was involved in this particular instance.

However, the unit confirmed that the attack group used both fake meetings and AI tools as part of their social engineering arsenal, indicating that AI-assisted impersonation is now a standard tactic rather than a theoretical concern.

The progression from text-based rapport building to account compromise to AI-assisted video impersonation represents an operational escalation in attack sophistication.

The implications for institutional crypto investors are direct: the authentication method most people trust, seeing and hearing a person on video, is no longer a reliable verification layer.

Account compromise of a known contact now translates automatically into the ability to conduct convincing impersonation at scale, without requiring weeks of prior relationship building or access to sophisticated custom video production. An attacker with a stolen Telegram or Teams credential can execute these attacks against dozens of targets in parallel.

Cardano Foundation Contact’s Account Used to Continue Attack After Initial Call

On April 24, 2026, Pierre Kaklamanos, the Cardano Foundation contact whose identity was impersonated in the initial attack, posted publicly on X (formerly Twitter) confirming that his Telegram account had been compromised. He disclosed that someone was actively impersonating him and noted that “a few other people in the industry this week” had also fallen victim to account compromise.

He explicitly warned followers not to click links or accept meeting invitations sent through his Telegram account, and instructed them to verify any contact through LinkedIn direct messages instead.

The timeline is critical for understanding the attack’s sophistication. The founder, after the compromised call ended, attempted to reach the real Kaklamanos by messaging the same Telegram account. The attacker, still controlling the compromised account, responded by saying Kaklamanos had gotten busy and proposed rescheduling.

This continuation of the impersonation after the initial video call ended demonstrates that the attacker’s goal was not a single-shot credential theft, but rather the maintenance of a false relationship over multiple interactions.

This pattern transforms the incident from an isolated attack into evidence of an active campaign.

The account compromise serves as the entry point; the attacker’s knowledge of the victim’s prior relationship with Kaklamanos becomes the weapon; and the ability to persist in false communication even after the initial call creates multiple opportunities for the attacker to extract credentials, deploy malware, or establish lasting backdoor access.

For institutional investors and founders receiving contact from known industry figures via messaging platforms, this reveals a new threat: verification through video call alone is no longer sufficient, because the attacker can generate convincing video content, and the account compromise provides continuity of impersonation across multiple sessions.

The convergence of readily available AI video synthesis tools, commodity malware delivery mechanisms, and account compromise tactics suggests that crypto firms should expect an escalation in these attacks through the second half of 2026. The standard institutional response, verify sensitive requests through a second channel, requires institutional investors to establish offline or out-of-band verification methods with key contacts now, before attackers with compromised accounts attempt to intercept or impersonate those verification channels. The open question is whether crypto exchanges, custodians, and investment firms will implement account-holder verification standards (such as requiring confirmation of large transfers through independently verified phone numbers or pre-registered backup contacts) before the next wave of these attacks targets financial transactions directly.

Get this in your inboxThe Crypto Coin Show newsletter covers the policy and market moves institutional crypto investors are pricing in.

Subscribe