MPC-lab

Market Prices

Coin Price 24h
BTC Bitcoin
$64,332 +0.60%
ETH Ethereum
$1,915.27 +0.13%
SOL Solana
$74 +0.65%
BNB BNB Chain
$575.7 +0.79%
XRP XRP Ledger
$1.08 +0.02%
DOGE Dogecoin
$0.0706 -0.31%
ADA Cardano
$0.1637 -0.30%
AVAX Avalanche
$6.51 -0.12%
DOT Polkadot
$0.7671 +0.75%
LINK Chainlink
$8.38 -0.58%

Fear & Greed

28

Fear

Market Sentiment

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

12
05
halving BCH Halving

Block reward halving event

18
03
unlock Sui Token Unlock

Team and early investor shares released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$64,332
1
Ethereum
ETH
$1,915.27
1
Solana
SOL
$74
1
BNB Chain
BNB
$575.7
1
XRP Ledger
XRP
$1.08
1
Dogecoin
DOGE
$0.0706
1
Cardano
ADA
$0.1637
1
Avalanche
AVAX
$6.51
1
Polkadot
DOT
$0.7671
1
Chainlink
LINK
$8.38

🐋 Whale Tracker

🔴
0x4177...1b21
6h ago
Out
2,003,300 USDC
🔵
0x1860...7d10
12h ago
Stake
1,895 BNB
🔵
0x42bd...d576
2m ago
Stake
3,634.05 BTC

💡 Smart Money

0x0d08...115a
Institutional Custody
+$1.1M
71%
0xc129...64be
Institutional Custody
+$4.0M
80%
0x682e...e09f
Experienced On-chain Trader
+$2.3M
64%

🧮 Tools

All →
Flash News

The $150,000 Interview: How a Fake AI Meeting Tool Is Draining Web3 Wallets

CryptoPrime

I didn't see it coming. Neither did the trader who lost $150k after a single Zoom call last week. But the spread wasn't there—until it was. On July 29, 2025, SlowMist published the forensic analysis of a new info-stealer targeting Web3 professionals. The malware, disguised as an AI meeting app called 'Relay,' had already compromised at least 47 wallets within 48 hours. The code is clean. The targeting is precise. And the market is not paying attention.

Context: We're in a bull market. Everyone is hiring. Every founder is looking for that perfect smart contract auditor, every DeFi protocol needs a new marketing lead. The AI narrative is in hyperdrive. So when a recruiter sends you a link to a new meeting tool that uses AI to summarize calls, you click. You're busy. You want to save time. That's exactly what the attackers counted on. The fake 'Relay' app is a cross-platform malware built with electron and node vulnerabilities, attacking both macOS and Windows. It steals browser credentials (including Google accounts and 2FA backup codes), crypto wallet data (MetaMask, Phantom, WalletConnect session tokens), macOS keychain, and Telegram session files. Once installed, it exfiltrates everything to a C2 server within milliseconds. You don't even need to enter your seed phrase—they already have your unlocked session.

The $150,000 Interview: How a Fake AI Meeting Tool Is Draining Web3 Wallets

Core: Let's walk through the attack chain as SlowMist reconstructed it. First, the threat actor scrapes LinkedIn for Web3 job listings or contributions to open-source repos. They clone or create plausible recruiter profiles with real company logos. The initial message is always the same: 'We saw your work on GitHub—would you be interested in a role? Let's do a quick call.' The call never happens. Instead, they send a link to download 'Relay' for the meeting. The malware is signed with a stolen Apple Developer certificate and a spoofed Microsoft Authenticode, so antivirus engines don't flag it. Once installed, the malware checks if it's running in a sandbox or VM. If clean, it injects payload into the system process and begins scraping. The critical insight is the on-chain forensic trail. SlowMist traced the exfiltration wallet addresses—they've already consolidated 3.2 BTC and 45 ETH into a single address that rotates through Tornado Cash-like mixers. The structural integrity of this operation is impressive. The developers understood that wallet session tokens are the new keys. You don't need to steal a Ledger device if you can copy the browser's localStorage file. And Telegram sessions? They use those to message the victim's contacts, repeating the same scam with higher trust. This is not a script kiddie operation. This is a professional malware-as-a-service group targeting the wealthiest cohort in tech.

Contrarian: You'd think experienced traders would use hardware wallets and air-gapped signing. You'd be wrong. In my 2020 Uniswap V2 liquidity mining sprint, I kept a hot wallet with $50k because 'I need speed.' That's the same mindset these attackers exploit. The common belief is that if your private keys never touch the internet, you're safe. But what about your session token? What about the browser extension that remembers your password? The real vulnerability is the trust layer. We trust recruiters because we want the next big deal. We trust software because we're tired of slow onboarding. In this bull market, the moon is so close that everyone forgets to lock the door. The contrarian truth: even if you use a Ledger, if your MetaMask extension is unlocked and your browser is compromised, the attacker can sign any transaction without your consent. The hardware wallet only helps if you confirm each transaction manually—and even then, a deceptive blind signing can drain you. The spread between perceived security and actual security is wider than ever.

The $150,000 Interview: How a Fake AI Meeting Tool Is Draining Web3 Wallets

Takeaway: You don't get rich by trusting strangers with your private keys. Here are my battle-tested rules. First, never run software from an unsolicited recruiter. Use a dedicated virtual machine for every interview. Second, disable browser extension auto-lock and use session isolation—a separate browser profile for each dApp. Third, use a hardware wallet with blind signing disabled and always verify the contract address on a separate device. Fourth, check your Telegram active sessions daily. If you see an unknown session, kill it and rotate your API keys. Finally, if you suspect compromise, move funds to a fresh hardware wallet immediately. Don't wait for the report. The next variant will use AI voice deepfakes to call you and ask for your 2FA code. Are you ready? The only moon you'll see is the one from the exit scam if you don't act now.