🚨 Something happened during a job search that I sat on for months. I'm talking about it now — because we built something about it.
I was contacted for a blockchain role. Professional communication. Real company name. Proper GitHub repo. All the right signals.
They sent a take-home technical task.
I ran it on a cloud instance instead of my laptop. Good instinct, as it turned out.
The actual code ended at line 46. Everything beyond that — all the way to line 258 — was a hidden payload:
🔑 SSH keys
🌍 Environment variables
🔐 Credentials and API keys
💀 Anything it could reach on a local machine
Designed to look like nothing. Designed to run the moment I opened it on my own machine.
I flagged it to the "recruiter." No response.
And then I kept thinking: what if I'd just run it locally, like most people would?
That question didn't go away.
This attack pattern has a name. It's documented. It's ongoing. It specifically targets blockchain and Web3 developers — because running code during a technical interview is completely normal behaviour, and that normality has been weaponised.
I wasn't the first. I won't be the last.
So we built a response to it.
@RTindex — the Risk & Threat Index — is live today.
Paste a suspicious repo link or a recruiter conversation. Get a risk verdict in under 2 minutes — with a clear explanation of why, not just a flag.
The full story, the technical breakdown, and the case that started all of this are on the blog.
🔗
rtidx.com
This wouldn't exist without
@piotrdz (product vision and trust) and
@jan_defdone , who engineered RTIdx end-to-end. Jan's work is the product.
The platform's analytical foundations draw from research by Prof.
@ameerrahmati and Abisheka Pitumpe PhD at Stony Brook University's Ethos Security & Privacy Lab — connecting serious academic research on recruitment scam ecosystems to a tool developers can actually use in the moment.
If you're in Web3, blockchain, or any developer community — share this. Someone in your network may already be targeted.
The index gets stronger with every report.
🔗
rtidx.com
#cybersecurity #web3 #blockchain #developerprotection #infosec #recruitmentscam #rtidx