SlowMist has mapped a months-long phishing campaign impersonating multiple Web3 wallet brands to install remote-control software on victims’ computers. The operation targeted Keystone and OneKey users through compliance notices, account-verification requests and fabricated service updates.
The campaign did not rely on a smart contract exploit or direct blockchain vulnerability. Instead, attackers used trusted brands and disguised installation packages to compromise the endpoint from which users accessed wallets, trading platforms and other sensitive services.
Fake Compliance Notices Delivered Remote-Access Software
The attack chain began with emails referencing KYC rules, account restrictions and regulatory deadlines. Recipients were directed to fake DocuSign pages claiming that a desktop application was required to review and sign protected documents.
The download packages appeared in VBS, BAT and EXE formats, with filenames and interfaces adapted to different wallet brands. Despite those surface changes, the payloads ultimately installed preconfigured remote-management clients capable of maintaining access to the affected Windows system.
SlowMist identified multiple GitHub repositories named after wallets and Web3 services, including Dcent, Casa, Ellipal, Xaman, Bifrost, Lace, Nufi and OneKey. Several files carried different names but shared identical hashes and backend configurations, indicating a coordinated distribution system rather than unrelated phishing attempts.
The primary payload installed ScreenConnect in unattended-access mode, connecting compromised devices to a fixed remote server without requiring the victim to approve each session. The malware also established persistence through Windows services, authentication packages, credential providers and Safe Mode startup entries.
Endpoint Access Bypasses On-Chain Defenses
Once installed, the software could expose open wallet applications, browser extensions, trading sessions, chat logs and locally stored configuration data. An attacker controlling the device could also manipulate the user into signing transactions, entering passwords or transferring assets through otherwise legitimate wallet interfaces.
This changes the security model because hardware and smart contract protections cannot fully defend an already compromised operating environment. CISA has separately warned that legitimate remote-monitoring and management software can be abused through phishing to establish persistent access, recommending stronger application controls, user training and monitoring for unauthorized tools.
SlowMist published malicious domains, network addresses, file hashes and host-level traces to support blocking and incident investigation. Security teams should look beyond the original phishing domains because attackers can rotate email addresses and repositories while preserving the same remote-access configuration.
The campaign demonstrates how Web3 attackers are shifting from wallet credential theft toward persistent endpoint control. Anyone who executed one of the identified packages should treat the device as fully compromised, isolate it from sensitive systems and rotate credentials from a separate trusted environment.








