A new breed of predator is stalking the Web3 talent pool. They are not hackers in hoodies. They are recruiters—or rather, they pose as recruiters. The bait? A shiny AI-powered meeting tool called "Relay." The trap? A cross-platform info-stealer that empties wallets, hijacks Telegram sessions, and walks out with your browser credentials. Speed is the only hedge in a real-time world, and today I am breaking this down before the next victim clicks "Install."
SlowMist, the security firm that has become the canary in the crypto coal mine, dropped the sample analysis hours ago. They caught a new social engineering campaign targeting Web3 professionals. The attack chain is elegant in its brutality: a fake job interview invitation, a custom-built malware disguised as an AI meeting assistant, and a payload that speaks both macOS and Windows. Over the past week, I have seen chatter about suspicious LinkedIn messages, but now we have the code. This is not a drill.
Context: Why now? We are in a sideways market—July 2025, choppy consolidation. Traders are bored. Job seekers are hungry. The AI narrative is at peak hype. Attackers understand this. They know that a Web3 developer who just saw a 30% portfolio dip is more likely to click a link promising a $300k salary at a top DeFi protocol. The timing is exquisite. Remote work is the norm. Video interviews are standard. And AI tools are the new fetish. So they built "Relay"—a name that sounds innocuous, almost helpful.
From my days modeling ICO supply shocks in 2017, I learned one thing: the most dangerous attacks are the ones that look like normal traffic. This is financial phishing, weaponized with psychology. The malware targets both operating systems, which tells me the attacker team has serious engineering chops. They are not script kiddies. They built this with intent.
Core: What the malware does (and what it means for your portfolio) Let me strip away the marketing. This is not a run-of-the-mill Trojan. The sample SlowMist analyzed exfiltrates: - Browser credentials (cookies, saved passwords, autofill data) - Cryptocurrency wallet extensions (MetaMask, Phantom, Ledger Live—any seed phrase stored in plaintext) - macOS Keychain (iCloud tokens, app passwords, SSH keys) - Telegram session files (full access to your DMs, groups, and channels)
Think about that last one. If an attacker takes over your Telegram, they can impersonate you to your colleagues, your project's community, even your exchange support contacts. I have seen secondary attacks where compromised Telegram accounts are used to request wallet transfers or share malicious links to other team members. The real target is not just your assets—it is your trust network.
Based on my experience auditing DeFi protocols during the Summer of 2020, I know that the most valuable data is not the code—it is the connections. A single breached Telegram account can unravel a whole team's operational security. The chart whispers, but the volume screams, and here the volume is a full-spectrum data grab.
How does the attack work? Step by step: 1. The victim receives a LinkedIn message or email from a fake recruiter (often with a stolen identity from a real Web3 company). 2. The recruiter pitches an AI-powered interview tool called "Relay" that supposedly records and transcribes meetings. 3. Victim downloads the installer from a fake website (or a direct link). The installer looks legitimate—proper code signing, clean UI. 4. On execution, the malware deploys a persistent backdoor and begins credential harvesting immediately. 5. Within minutes, the attacker has access to wallets, exchanges, and communication channels.
The malware evades basic antivirus by using encrypted payloads and delayed execution. SlowMist's report includes specific hashes and C2 domains. If you or your team have downloaded any suspicious "meeting" software in the last 72 hours, immediately rotate all passwords, revoke Telegram sessions, and sweep wallets to a new hardware address.
Contrarian: The real blind spot is the hiring process itself Counter-intuitive take: The danger is not the malware. It is the assumption that Web3 hiring is trustless. We spend so much time securing smart contracts and multi-sigs that we forget the human layer is held together by duct tape and LinkedIn endorsements.
Every Web3 company I have consulted for uses some version of a remote interview workflow. Most rely on the same tools—Zoom, Google Meet, Telegram, Discord—all connected through a single identity. An attacker does not need to exploit a zero-day in a smart contract. They just need to exploit a person's desire for a better job.
Here is the blind spot that most security guides miss: the malware is a distraction from the deeper problem—identity verification in the Web3 job market is virtually nonexistent. There is no decentralized identifier (DID) standard for recruiters. No blockchain-based credential check for job postings. The attacker is not breaking cryptography; they are breaking trust.
I see a parallel to the early ICO days, where a fake team could raise millions with a white paper and a photo of a rented office. Now the scam is more surgical: target the people who build the future. And in a sideways market, when fear is high and opportunity feels scarce, the desperation to get hired makes the perfect bait.
Regulation angle: The EU's MiCA framework focuses on stablecoin reserves and CASP compliance, but it does nothing to stop a fake recruiter in Latvia from sending a Mac executable. The regulation is fighting the last war. This attack is the new frontier, and it will take at least 6–12 months before any oversight body even acknowledges the problem. Meanwhile, the attackers iterate.
Takeaway: The next phase is already being coded Liquidity flows where fear turns into opportunity—and right now, the opportunity is in security infrastructure. Hardware wallet sales will spike. Companies will rush to deploy endpoint detection on employee machines. A new niche will emerge: "Web3 interview security"—isolated virtual machines, disposable browser profiles, and biometric verification for hiring calls. I predict within six months we will see a startup offering a dedicated OS for job applications, sandboxed from the main wallet environment.
But the immediate action is personal. Do not trust any unsolicited interview invitation that asks you to install software. Even if the LinkedIn profile looks perfect, even if the company is real, verify through a separate channel. Call the company's HR line directly. Ask for a meeting on a standard platform where you control the link.
And for the love of Satoshi, use a hardware wallet and never store your seed phrase digitally. The attacker won this round because they understood human nature better than we did. The chart whispers, but the volume screams, and the volume today is a warning: your next job offer might be your last mistake.
Stay sharp. The market is sideways, but the predators are moving fast.