Today’s Field Note
SlowMist has flagged macOS malware that hijacks Telegram sessions, decrypts local wallet files, and serves fake apps to phish recovery phrases. In parallel, The Hacker News documents ACR Stealer using ClickFix lures (paste-this-command-into-Run) to walk off with saved browser passwords, live session tokens, and OneDrive/SharePoint files. Neither breaks a cipher. Both rely on you executing something or trusting a session that is already stolen, which is exactly how the largest losses on record actually happen. If your keys, seed, or signing session live on the same machine you browse and Telegram on, treat that machine as hostile.
Today’s Move
- Move any real balance to a hardware wallet or an air-gapped signer today. Stop keeping seed phrases in plaintext, Notes, or synced cloud folders that ACR Stealer scrapes.
- Kill and reauthenticate all Telegram sessions (Settings, Devices, Terminate All Other Sessions), then enable a Telegram cloud password.
- Never paste a command into Run, Terminal, or a “verification” box because a site or “support” told you to. That is the entire ClickFix delivery chain.
- On macOS, audit installed apps for fake wallet or Telegram clones, and only reinstall wallets from official signed sources.
- Rotate browser-stored passwords and revoke live login tokens for any exchange or email that shares the infected device.
Resources
- https://cointelegraph.com/news/macos-malware-crypto-investors-slowmist?utm_source=rss_feed&utm_medium=rss_tag_hacks&utm_campaign=rss_partner_inbound
- https://thehackernews.com/2026/07/acr-stealer-uses-clickfix-lures-to.html
- Incident trackers (reference standard): Rekt leaderboard · SlowMist Hacked
Related
More: Issues · Field Notes · RTFM
Daily field notes, weekly Issues. Follow @ItsAlreadyPrice or subscribe via RSS.