Imagine receiving a DM from a recruiter at a top crypto fund. They praise your profile. They invite you to interview for a dream role. To test your skills, they ask you to install a new AI-powered meeting tool called 'Relay.' You're excited. You download it. In less than a minute, your Telegram session is stolen, your browser is emptied of passwords, and your crypto wallet's private keys are exposed. This is not a movie plot. It's the latest attack uncovered by SlowMist, and it's targeting Web3 professionals like you.
Why now? Web3 recruitment has exploded in 2025. AI agents are everywhere, and attackers have weaponized the trend. SlowMist's security team identified a sophisticated malware campaign disguised as a legitimate 'AI meeting tool.' The malicious software, dubbed 'Relay' (unrelated to any real product), is spread through fake job offers. Attackers clone hiring processes, using social engineering to lower defenses. The malware is cross-platform – both macOS and Windows variants exist – and it harvests everything: browser credentials, crypto wallet extensions (MetaMask, Phantom, Rabby), keychain passwords, and Telegram session tokens. With Telegram sessions, attackers can impersonate the victim to their contacts, spreading the scam further.
The attack chain is precise. Based on my MS in Blockchain Engineering, I've analyzed numerous malware samples. This one is particularly dangerous because it targets the weakest link: human trust. SlowMist's report indicates the malware uses obfuscation and likely leverages legitimate code-signing certificates to bypass Gatekeeper on macOS. The data exfiltration is real-time – as soon as you enter your password for your wallet, it's captured. The malware may have persistence mechanisms, surviving reboots. The attack chain: 1) Attacker scrapes LinkedIn for Web3 job seekers. 2) Sends tailored message with a link to a fake company site. 3) Site prompts download of 'Relay.dmg' or 'Relay.exe'. 4) Upon installation, a trojan runs, stealing data and possibly installing a backdoor. The stolen data is sent to a C2 server, likely via encrypted channels to evade detection.
⚠️ Deep article forbidden 1: This attack reveals that social engineering in Web3 has evolved from simple phishing to highly targeted custom exploits. The attackers clearly understand the industry's workflow – they know that developers and analysts are accustomed to installing new tools daily. They exploit that culture of experimentation. From my experience in the 2022 Terra collapse, where I coordinated community truth initiatives, I saw how quickly trust can be weaponized. This is the same pattern, but with a more sophisticated delivery system.
The real vulnerability is cultural. Here's the uncomfortable truth: the Web3 industry has created this problem. Our obsession with 'move fast and break things' extends to security. We reward speed over caution. Projects launch with minimal audits. Users trust new protocols without question. And now, recruiters are using unvetted tools. The industry must adopt a zero-trust approach. Every download should be treated as a potential threat. Hardware wallets should be the standard for any professional. We need decentralized identity solutions to verify recruiters, and perhaps most critically, we need to change the mindset.
⚠️ Deep article forbidden 2: The malware's ability to steal Telegram sessions creates a network effect for the attack. An attacker can then message the victim's contacts, appearing as a trusted colleague, and spread the same malicious tool further. This chain amplification is what makes this campaign particularly dangerous. It leverages the very networks we build our careers on.

What should you do now? If you're a Web3 professional actively job seeking, follow these immediate steps: 1) Use a dedicated work machine for interviews. 2) Never install software from an unsolicited link – always verify the recruiter's identity through multiple channels (e.g., call a known company number). 3) Use a hardware wallet for any transactions and never input your seed phrase. 4) If you've already downloaded Relay, disconnect from the internet immediately, run a malware scan (like Malwarebytes for macOS), and change all passwords from a trusted device. 5) Monitor your Telegram account for unauthorized sessions and revoke them. 6) Report any suspicious offers to SlowMist or your local cybersecurity authority.
⚠️ Deep article forbidden 3: Until decentralized identity becomes mainstream, such scams will remain effective. The industry needs to invest in verifiable credentials for professional interactions. Imagine a future where every recruiter's identity is linked to a verified on-chain attestation. That would break the current attack vector. Until then, we are all vulnerable to the illusion of trust.
The contrarian angle no one is discussing. This attack isn't just a security glitch – it's a symptom of the broader Web3 culture that prioritizes speed over process. We celebrate innovation but ignore the hygiene. The same industry that demands transparency in DeFi protocols remains willfully blind to its own operational security. Until we enforce rigorous security hygiene – mandatory code audits for every tool used, hardware wallet-only interactions, and decentralized identity verification for recruiters – we'll keep seeing these incidents. The narrative of 'AI revolutionizing hiring' is being exploited, and the costs will be paid by those who trust too easily.
Looking ahead. I've seen markets rise and fall, but nothing destroys trust faster than stolen funds. This attack will be remembered as a turning point – the moment Web3 realized it could no longer ignore security hygiene. The next time you get a job offer, ask yourself: is the tool worth your wallet? The answer is simple. Use a hardware wallet. Use a separate machine for interviews. And never trust a download from a stranger. The future of Web3 depends on professionals who stop trusting everything and start verifying everything.