MPC-lab

Market Prices

Coin Price 24h
BTC Bitcoin
$64,108.2 +0.51%
ETH Ethereum
$1,866.35 +0.24%
SOL Solana
$73.8 +0.33%
BNB BNB Chain
$598.2 +1.22%
XRP XRP Ledger
$1.07 -0.83%
DOGE Dogecoin
$0.0697 -0.92%
ADA Cardano
$0.1908 -2.15%
AVAX Avalanche
$6.62 -3.75%
DOT Polkadot
$0.8462 +0.17%
LINK Chainlink
$8.11 -0.84%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

18
03
unlock Sui Token Unlock

Team and early investor shares released

28
03
unlock Arbitrum Token Unlock

92 million ARB released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$64,108.2
1
Ethereum
ETH
$1,866.35
1
Solana
SOL
$73.8
1
BNB Chain
BNB
$598.2
1
XRP Ledger
XRP
$1.07
1
Dogecoin
DOGE
$0.0697
1
Cardano
ADA
$0.1908
1
Avalanche
AVAX
$6.62
1
Polkadot
DOT
$0.8462
1
Chainlink
LINK
$8.11

🐋 Whale Tracker

🟢
0xd609...b6f4
1h ago
In
4,848.98 BTC
🔴
0x92aa...21d9
1h ago
Out
30,543 SOL
🔴
0x6ba9...de2d
12h ago
Out
29,277 SOL

💡 Smart Money

0x3c11...9d27
Market Maker
+$4.4M
76%
0x0a0c...6e88
Top DeFi Miner
+$3.7M
92%
0x6613...43a3
Institutional Custody
+$1.0M
62%

🧮 Tools

All →
Layer2

The Fake AI Interview That’s Hunting Web3 Wallets: SlowMist’s Code Dump Shows How

MetaMeta
SlowMist just dropped the sample. The code doesn’t lie: a cross-platform info-stealer, disguised as an AI meeting tool called “Relay,” is now hunting Web3 professionals. For the first time, we have the IOCs—hashes, C2 domains, file paths. And the target list? Browsers, keychains, Telegram sessions, and crypto wallets. All of it. In one download. Context: The bull market is in full swing. Hiring is hot. Every week, another project posts “We’re hiring a Solidity dev” on LinkedIn, X, or Discord. Attackers know this. So they skip the exploit—they target the person. The narrative is familiar: a recruiter reaches out, schedules a video interview, and sends a link to download an AI-powered meeting app. You’re excited. You install it. And then—poof. Your wallet is gone, your Telegram compromised, your keychain cracked. This isn’t theory. SlowMist’s forensic analysis confirms: the malware sits on both macOS and Windows. It steals browser credentials (think: saved passwords for email, exchanges, DeFi dashboards). It scrapes Telegram session files—meaning the attacker can now impersonate you to your network. It grabs keychain data on macOS. And yes, it targets wallet extensions—MetaMask, Phantom, Rabby, you name it. Based on my 2017 audit sprint, I’ve seen social engineering evolve from phishing emails to fake airdrop sites. This is the next logical step: weaponize the hiring process. The attackers didn’t need a zero-day—they just needed a story that fits the bull market’s hype. Core insight: Let’s break the attack chain. Step one: reconnaissance. The attacker builds a fake LinkedIn profile—usually with a convincing photo, crypto-related job, and recent activity. They target Web3 professionals—engineers, founders, community managers—anyone with access to sensitive wallets. Step two: the hook. A message like “We’re impressed by your background—could you try our new AI interview tool?” The link leads to a landing page that mimics a legitimate startup. Step three: execution. The downloaded app (“Relay”) appears to launch a video interface but instead silently runs a Python-based stealer. SlowMist’s sample analysis shows the stealer uses obfuscated scripts to evade AV, then exfiltrates data via HTTPS to a hardcoded C2 server. The code doesn’t lie: it’s not a generic malware kit—it’s custom-built for this specific scam. What did they steal? According to the IOC list: browser SQLite databases (cookies, saved logins), Chrome’s “Login Data” files, Telegram’s tdata folder, macOS keychain entries, and wallet extension private keys from the browser’s local storage. The scope is terrifying because it doesn’t just target one asset—it targets your entire digital identity. If you lose your Telegram session, the attacker can message your colleagues, join your private groups, and launch a second wave of scams. “Smart contracts are smart; humans are the bug.” That quote hits different now. Contrarian angle: Most security alerts focus on “don’t open suspicious links” or “use a hardware wallet.” Both are true—but insufficient. The real blind spot here is the professional network itself. We’ve trained ourselves to trust LinkedIn DMs, Twitter introductions, and Discord cold messages. The bull market has made everyone desperate for talent. Attackers exploit that urgency. The unreported angle? This isn’t just an individual loss event—it’s a systemic risk to Web3 hiring. Every project that posts “we’re hiring” is now broadcasting attack surface. And the response from platforms like LinkedIn? Slow. They rely on user reports. By the time a fake profile is flagged, the data is already leaked. What does this mean for the market? In the short term, expect Fear, Uncertainty, and Doubt (FUD) around hiring channels. Projects may freeze external interviews for a week or two. But the smart money—those who understand that “liquidity leaves fast, but the smart money stays”—will double down on security protocols. I’ve already heard whispers of companies creating isolated virtual machines specifically for candidate interviews. That’s the kind of adaptation that separates survivors from victims. Takeaway: The next variant will be worse. Deepfake video calls. Personalized spear-phishing based on stolen Telegram history. Don’t wait for your CEO to issue a memo. Right now, do three things: (1) Enable hardware wallet signing for every transaction—no exceptions. (2) Audit your Telegram session list and revoke all unknown sessions. (3) Never run an executable sent by a recruiter. Instead, use a burner VM or a dedicated device. The bull market will keep pumping, but your private keys don’t care about market sentiment. They care about the one click you shouldn’t have made. “Arbitrage is just patience wearing a speed suit.” Sometimes patience means pausing to verify who’s on the other end of the line. The code is out. The samples are circulating. Now the question is: will you be the one who clicked, or the one who read the report first?