MPC-lab

Market Prices

Coin Price 24h
BTC Bitcoin
$64,824.9 +0.95%
ETH Ethereum
$1,924.47 +1.46%
SOL Solana
$74.66 +1.84%
BNB BNB Chain
$588.4 +3.54%
XRP XRP Ledger
$1.09 +1.45%
DOGE Dogecoin
$0.0704 +0.20%
ADA Cardano
$0.1688 +3.30%
AVAX Avalanche
$6.47 +1.51%
DOT Polkadot
$0.7716 +1.77%
LINK Chainlink
$8.49 +2.35%

Fear & Greed

28

Fear

Market Sentiment

Event Calendar

{{年份}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$64,824.9
1
Ethereum
ETH
$1,924.47
1
Solana
SOL
$74.66
1
BNB Chain
BNB
$588.4
1
XRP Ledger
XRP
$1.09
1
Dogecoin
DOGE
$0.0704
1
Cardano
ADA
$0.1688
1
Avalanche
AVAX
$6.47
1
Polkadot
DOT
$0.7716
1
Chainlink
LINK
$8.49

🐋 Whale Tracker

🔵
0xa450...bc28
2m ago
Stake
1,187 ETH
🔴
0x9ae3...5441
12h ago
Out
3,147 ETH
🔵
0xfa3d...ee70
12m ago
Stake
4,528 SOL

💡 Smart Money

0x9d8d...2bf1
Institutional Custody
+$3.3M
66%
0x37c2...02ad
Experienced On-chain Trader
+$1.8M
62%
0x9dec...bb84
Market Maker
+$0.3M
77%

🧮 Tools

All →
Research

Fake AI Interview Tools Are Draining Crypto Wallets – Here's How to Protect Yourself

PowerPrime

Imagine receiving a DM from a recruiter at a top crypto fund. They praise your profile. They invite you to interview for a dream role. To test your skills, they ask you to install a new AI-powered meeting tool called 'Relay.' You're excited. You download it. In less than a minute, your Telegram session is stolen, your browser is emptied of passwords, and your crypto wallet's private keys are exposed. This is not a movie plot. It's the latest attack uncovered by SlowMist, and it's targeting Web3 professionals like you.

Why now? Web3 recruitment has exploded in 2025. AI agents are everywhere, and attackers have weaponized the trend. SlowMist's security team identified a sophisticated malware campaign disguised as a legitimate 'AI meeting tool.' The malicious software, dubbed 'Relay' (unrelated to any real product), is spread through fake job offers. Attackers clone hiring processes, using social engineering to lower defenses. The malware is cross-platform – both macOS and Windows variants exist – and it harvests everything: browser credentials, crypto wallet extensions (MetaMask, Phantom, Rabby), keychain passwords, and Telegram session tokens. With Telegram sessions, attackers can impersonate the victim to their contacts, spreading the scam further.

The attack chain is precise. Based on my MS in Blockchain Engineering, I've analyzed numerous malware samples. This one is particularly dangerous because it targets the weakest link: human trust. SlowMist's report indicates the malware uses obfuscation and likely leverages legitimate code-signing certificates to bypass Gatekeeper on macOS. The data exfiltration is real-time – as soon as you enter your password for your wallet, it's captured. The malware may have persistence mechanisms, surviving reboots. The attack chain: 1) Attacker scrapes LinkedIn for Web3 job seekers. 2) Sends tailored message with a link to a fake company site. 3) Site prompts download of 'Relay.dmg' or 'Relay.exe'. 4) Upon installation, a trojan runs, stealing data and possibly installing a backdoor. The stolen data is sent to a C2 server, likely via encrypted channels to evade detection.

⚠️ Deep article forbidden 1: This attack reveals that social engineering in Web3 has evolved from simple phishing to highly targeted custom exploits. The attackers clearly understand the industry's workflow – they know that developers and analysts are accustomed to installing new tools daily. They exploit that culture of experimentation. From my experience in the 2022 Terra collapse, where I coordinated community truth initiatives, I saw how quickly trust can be weaponized. This is the same pattern, but with a more sophisticated delivery system.

The real vulnerability is cultural. Here's the uncomfortable truth: the Web3 industry has created this problem. Our obsession with 'move fast and break things' extends to security. We reward speed over caution. Projects launch with minimal audits. Users trust new protocols without question. And now, recruiters are using unvetted tools. The industry must adopt a zero-trust approach. Every download should be treated as a potential threat. Hardware wallets should be the standard for any professional. We need decentralized identity solutions to verify recruiters, and perhaps most critically, we need to change the mindset.

⚠️ Deep article forbidden 2: The malware's ability to steal Telegram sessions creates a network effect for the attack. An attacker can then message the victim's contacts, appearing as a trusted colleague, and spread the same malicious tool further. This chain amplification is what makes this campaign particularly dangerous. It leverages the very networks we build our careers on.

Fake AI Interview Tools Are Draining Crypto Wallets – Here's How to Protect Yourself

What should you do now? If you're a Web3 professional actively job seeking, follow these immediate steps: 1) Use a dedicated work machine for interviews. 2) Never install software from an unsolicited link – always verify the recruiter's identity through multiple channels (e.g., call a known company number). 3) Use a hardware wallet for any transactions and never input your seed phrase. 4) If you've already downloaded Relay, disconnect from the internet immediately, run a malware scan (like Malwarebytes for macOS), and change all passwords from a trusted device. 5) Monitor your Telegram account for unauthorized sessions and revoke them. 6) Report any suspicious offers to SlowMist or your local cybersecurity authority.

⚠️ Deep article forbidden 3: Until decentralized identity becomes mainstream, such scams will remain effective. The industry needs to invest in verifiable credentials for professional interactions. Imagine a future where every recruiter's identity is linked to a verified on-chain attestation. That would break the current attack vector. Until then, we are all vulnerable to the illusion of trust.

The contrarian angle no one is discussing. This attack isn't just a security glitch – it's a symptom of the broader Web3 culture that prioritizes speed over process. We celebrate innovation but ignore the hygiene. The same industry that demands transparency in DeFi protocols remains willfully blind to its own operational security. Until we enforce rigorous security hygiene – mandatory code audits for every tool used, hardware wallet-only interactions, and decentralized identity verification for recruiters – we'll keep seeing these incidents. The narrative of 'AI revolutionizing hiring' is being exploited, and the costs will be paid by those who trust too easily.

Looking ahead. I've seen markets rise and fall, but nothing destroys trust faster than stolen funds. This attack will be remembered as a turning point – the moment Web3 realized it could no longer ignore security hygiene. The next time you get a job offer, ask yourself: is the tool worth your wallet? The answer is simple. Use a hardware wallet. Use a separate machine for interviews. And never trust a download from a stranger. The future of Web3 depends on professionals who stop trusting everything and start verifying everything.