Got targeted today by what looks like a fake audit/recruitment campaign.
They opened the conversation by linking my Cantina profile and asking if I was looking for new opportunities.
At first it looked like a normal audit lead. They said they were building an RWA protocol and needed a smart contract auditor.
I asked what chain.
“EVM”
I told them I mainly audit Solana/Rust, so I probably wasn’t a good fit.
A minute later it became “actually multi-chain,” and they sent me a tech stack full of Solana/Rust, Anchor, SPL, PDA/CPI, Metaplex, etc.
They were also very pushy about getting on a call immediately, followed by NDA signing and private GitHub access.
I kept asking for the company/project details first.
Eventually they gave me
chainvisita.tech.
ChainVisita has already been publicly documented in a fake developer recruitment campaign where targets were given malicious repositories that downloaded a second-stage stealer targeting browser credentials and crypto wallets.
So if you get a similar audit offer, especially one tailored around your public security profile and quickly leading to a private repo, be careful.
blog.nivel4.com/investigacio…