Unchained - How a Fake Podcast Invite Nearly Hacked Laura Shin
Episode Date: July 2, 2026Laura Shin has reported on crypto scams since the early days and wrote one of the first stories on sim swaps. That did not stop a spear-phishing attempt from getting her to download software and run a... terminal command before she caught it. Austin Campbell, Ram Ahluwalia, and Chris Perkins turn her near miss into a practical defense playbook, then debate whether self-custody still makes sense for anyone with a public crypto profile. Hosts: Austin Campbell, Host of Bits + Bips, Founder of Zero Knowledge Group, and Adjunct Professor at NYU Stern Ram Ahluwalia, Co-host of Bits + Bips and CEO of Lumida Chris Perkins, Co-host of Bits + Bips and Head of Franklin Crypto Guest: Laura Shin - Founder and Host of Unchained This clip is from a longer conversation on crypto security and social engineering. Full episode here: https://youtube.com/live/yKHaE6xMZsE We go live every Monday - subscribe to catch it live. Sponsors: 👉 Cape: Your biggest crypto vulnerability isn't your wallet, it's your phone number. Cape is America's privacy-first mobile carrier that rotates your SIM identity daily and blocks SIM swaps before they happen. Get 33% off your first six months at https://cape.co/unchained (use code: UNCHAINED). Chapters: 🎣 00:00 The fake podcast invite that nearly caught Laura Shin 💻 00:26 How far it went: a download, then a terminal command 🛡️ 05:02 Austin's hard rules for when someone puts time pressure on you 🏦 06:36 Why Ram says ETFs now beat self-custody for public figures 🥷 07:39 Chris on getting hacked and losing his Snoop Dogg NFT 🤖 10:41 Why the same playbook is coming for banks via AI voice clones 🦅 11:33 Chris on letting the private sector recover stolen crypto Learn more about your ad choices. Visit megaphone.fm/adchoices
Transcript
Discussion (0)
Today, we want to start with something contemporaneous that just happened with regard to unchained
to explain to people exactly how things are still working in crypto and how to keep yourself safe,
which is somebody tried you spearfish Laura earlier today.
So, Laura, can I have you tell the story of what we were talking about before we went live and what happened?
Yeah, so it wasn't today.
It was last week.
but I had agreed to do a podcast with somebody.
And when I logged in, the link wasn't working.
And I was getting this notice saying that I had to download some software.
And so it's so funny because they did actually convince me to download the software.
And I even got to the point where I even executed a terminal command.
And here's the crazy part.
The whole time, like if you look at the screenshots of my conversation with this person,
the whole time I kept saying, oh, this is how people get hacked.
Because initially I kept refusing to do all the things.
And I have covered hacks.
I've covered, you know, fishing attempts.
I've covered just all kinds of scams in crypto.
I was, I think, the first person to write about sim swaps back in 2016.
And even before crypto, I covered personal finance.
I covered identity theft.
I covered so much about scams and social engineering.
Like I interviewed the main social engineering people well before I ever got into crypto.
So it's just so funny because I keep saying to this person, oh, but, you know, I would refuse
and then I would be like, this is how people get hacked.
So here's the thing.
Like now I realize, okay, here is how this person got me to override all of my internal
forum bells and all my learnings.
They said, oh, well, it's a special crypto podcasting.
platform and they sent me the link to the X account. And I looked at this, you know, X account and
153 people that I follow are following this account. And I was like, oh, I guess it's a crypto
podcasting platform I've never heard of. And so then the notion that like maybe I actually needed to
download some special software was no longer so strange. But I also remember that I had this moment
where I was like, I feel like I should tweet to ask my followers if this is, you know, like,
But then because this person kept messaging that, so I just kind of like didn't do these things that floated through my head.
And then when the software, of course, didn't work, then he was like, oh, well, there is these like terminal instructions.
And even that, I was like, what the hell?
Like I just was.
And I think I said no, again, multiple times.
But then they were like, no, no, no, I swear, like all these people use it.
And I think they, again, use the X account.
So anyway, point is the good news is I don't think I lost anything. I didn't have, like, I have to, there's a lot of things I have to do because I had to reset my computer to factory settings. I had to take it offline. Like, there were just a lot of things I had to do. And so even today, I'm still downloading apps that I use. I'm still logging into them. Like there's, I'm still changing passwords. There's kind of like a lot that's going on. But yeah, it's just funny. And it's just funny. And it's,
embarrassing because it's like I knew all the things. I knew. I had so much knowledge. I'm literally
trying to teach the guy about social engineering and how, you know, and anyway. So yeah, I still,
I still didn't listen to myself. And that's exactly how social engineering works. It's exactly,
it preys upon your desire to be a nice person. And oh, and by the way, you know, this quote
quote podcast. Like, of course, you know, I looked it up on YouTube and yeah, it's a legit podcast.
But is that account that was trying to get me to do all those things where they really connected
to, you know, that group? Probably not. In fact, like 99.99% not. So, yeah, last thing I'll say
is just seal 911. They've been on the show so many times. Everybody always talks about them,
but they truly are an amazing resource. And they helped me, you know, over the weekend and
Yeah, they yelled at me a little bit too, but I deserved it.
So that's basically the story.
No, and I think you raised some interesting threads in there, which is if you think about,
like this is something the banking industry struggles with as well, right?
If you think about the threat vector of social engineering attacks, even people who are
informed about how they work do fall for them because the attackers are trying to prey on you
at the exact moment where your mind is occupied with other things and you are not fully aware.
And that's one reason they always try to create time pressure.
Like, we need you to log in for this podcast.
Oh, the cutoff is coming at 4 p.m.
Oh.
So rule number one for anybody.
When you have somebody on any form of social communication or even texts, applying time
pressure to you and you're not certain about something, the first question you ask is,
is this truly catastrophic if I don't do it?
And if the answer is no, just don't do it.
It'll be fine.
Like, let that go.
Number two, from some of the good security researchers,
I've been told the easiest rubric to not fall for these things
is have a set of rules that you never, ever, ever violate ever.
Like, sorry, I don't download programs or click clicks, like at all.
If that is what your podcast requires, I cannot do it.
Go tell everybody right now.
The answer is never.
And then, by the way, always blame your Infosec people.
If you want to be a nice person, you don't need to own this decision.
You can be like, I'm not allowed to.
I don't have the authority to, like, punt it.
But like, don't ever for that reason.
Because once you create a rule with yourself that you're internally consistent on
that you cannot violate, it makes those tactics work less well.
Three, one thing I do individually, because like there have been a bunch of compromised,
like telegram attacks recently.
where I have people trying to get me to click on things and download things and join meetings and
whatever, just always put the link into an AI model and ask, is this a scam? You'd be shocked at
how good they are, being like, yeah, I don't trust that. Like, that's definitely never real.
And don't copy the text, copy the actual link and put it in there and very frequently they will shut
you down. But like, I want to raise one other thing that I was saying that Rom reacted to.
Rom, I was telling people part of the way that I've become semi-immune to these attacks now is I looked at the value of self-custody compared to the risk and I hold all of my crypto and ETF flow now.
Like, what would you have to say to that?
What do you advise people at least?
Yeah, 100%.
100%.
ETS are safe, secure.
You've got the implicit backing of BlackRock and their net equity.
You get liquidity.
You get cross-margining.
you get convenience of an integrated statement.
So, yes, the vast majority of people should be using ETFs to manage their digital
asset exposure.
Is it only BlackRock?
I digress.
Anyway, I think there's a couple other hygiene things you can do to the extent that you
want to have self-custody, that's fine.
You know, really advise people to use a hardware wallet where you can.
And there's some amazing ones out there.
I'm going to admit something to you guys.
never told anybody before, but I got hacked.
I hacked a couple of years ago.
It was a Friday, had a couple beers.
And the good news was that I kept good hygiene.
I'd put most of the stuff that was, that I wanted to on that hardware wallet.
But I was messing around, clicked on something, and they stole my Snoop Dog NFT.
And, you know, it still hurts to this day.
But it was, I'm glad it happened because it was such a stark reminder.
Like, you're in the big leagues.
You cannot mess around.
I also think that this is going to get much worse going forward on the social engineering.
We need solutions.
We need tech solutions.
You know, anytime you're on the, anytime you're, you know, your voice is out there.
They've got your voice.
They've got your likeness.
It's going to get much, much tougher.
And so while I do think security across crypto is actually going to exponentially improve as we
start finding age-old vulnerabilities, I do worry about the,
the social engineering attack
factor. That's why I'm bullish on
like proof of human type
solutions out there that can
really identify humanness.
So a lot to take away
from this one, guys. Last fun of that,
the re-through could be negative
for crypto brokerage firms
because ETS
are an implicit form of competition because the
security benefits they confer.
Well, yeah, with an ETF,
you're outsourcing a lot
of the security, the cyber,
I'm seeing this in real time right now with my transition.
And it's there's, you know, when you look at crypto,
decentralization is something we all believe in,
we all think is wonderful.
And it's really important that that persists.
But that doesn't mean intermediaries are going away.
And the question is, is do you want to pay them?
Do you want to handle over some of that sovereignty or some of the value that they can give you?
And for many people, the answers, yes.
And that's fine.
I think that's what we're talking about.
I mean, I think for anybody prominent, like, you know, where you have a public persona that is associated with crypto, it makes a lot of sense to have somebody else in charge of your crypto.
And so that's why, yeah, like for me, like, I don't know why they were targeting me.
Maybe they don't know that I just don't really even have that much.
But, yeah, I would say, you know, I know people who, you know, they'll like, well,
I don't know how public they are about this.
I don't want to get into too much detail.
But there are people that you all know in crypto who go to extremely great lengths to not have anything.
Even if their face is known, they try to not have anything with their name that would identify where they live or what other accounts.
They have like, you know, so just there's so many ways, you know, to kind of get around this.
Like you don't have to just become a hermit.
but these are things that if you are publicly affiliated with crypto, you should definitely be thinking
about.
And I think that has broader implications, Laura, to bring this all the way back around to
where you started with fraud and identity theft writ large.
Because these same tactics are going to be happening with banks, right, with payments companies,
with you get that phone call that is using the perfect AI voice of your kid like, hey, I had a car crash,
I need money.
right, like we've all heard these stories.
And I would just remind people, we're in a threat space where this stuff gets more intense.
They're going to try to use your own emotions and, like, behaviors against you.
And awareness really matters.
Recovery matters.
But this is one area where, as Rom was saying, there's going to be a market opportunity for people who figure out how to interdict these things as well.
Like, that might be a positive use case of AI for the world, but we will see.
So speaking of interdictions, we are coming up on the 250th anniversary of the United States.
And I do still think there's a strong policy response that we should see, which is to allow the private sector to recover, to recover these assets.
And so I'll keep speaking about it until I'm blue in the face.
But give me the privateers.
So whoever recovers Laura's money that was lost in this crypto.
I don't think I lost any.
If any, we'll have you on this show to explain how you did it.
There we go.
We can promote our privateering right there.
But no, joking aside, Laura, we were talking about that.
I just think it's good for the world to occasionally get the reminder on security and like how sophisticated these schemes are and what can happen.
So thank you very much for explaining that.
Remember, everybody, assume the account is compromised.
Do not click the link.
Yeah.
Well, thanks for inviting me last minute.
just pop in and talk about my
tail, which, yeah, is definitely
a lesson for everyone. It really does
matter, though. Like, every incremental
gain we get here, like, I want to remind
people of the scale of this problem is
tens of billions of dollars are scammed
like annually just out of America.
If you look at, like, the taxonomy
of the pig butchering scammers who
are operating out of Cambodia
or like some of the Russian scam
farms and things like that, this is,
a very severe problem that's destroying lives. So if you're in this space at all, you need to think
about this. You need to act on this stuff. You need to take it seriously. Yeah. All right. All right. Well,
have a great show. Thanks so much. And I will catch you later. If you like this segment,
please like, subscribe, and tune in every Monday at 4.30 p.m. Eastern Time. I'm Austin Campbell,
the host of Bips and Bips, along with my friends Rahm Alawalia and Chris Perkins and our slate of exceptional guests.
Every week, we're going to discuss macro, crypto, and the collision of worlds, covering topics that move markets and shape the financial landscape.
If you hold crypto on your phone, your biggest vulnerability isn't your wallet. It's your carrier.
AT&T, Verizon, and T-Mobile have been breached again and again.
And sim swaps are still one of the easiest ways for attack.
to drain accounts. That's where Cape comes in, America's Privacy First mobile carrier. Same
premium service, but Cape rotates the identifier on your SIM every 24 hours, deletes your call
and text metadata after a day, and protects against SIM swaps with a 24-word recovery phrase
that only you control. You also get two middle-to-end encrypted secondary numbers for banking and
sign-ups, so you stop handing your real number to every app that asks. Go to cape.co slash
unchained and use code unchained for 33% off your first six months.
