MPC-lab

Market Prices

Coin Price 24h
BTC Bitcoin
$64,439.8 +1.11%
ETH Ethereum
$1,874.23 +0.52%
SOL Solana
$74.19 +0.49%
BNB BNB Chain
$601.7 +1.78%
XRP XRP Ledger
$1.07 -0.23%
DOGE Dogecoin
$0.0702 -0.31%
ADA Cardano
$0.1927 -0.16%
AVAX Avalanche
$6.69 -1.69%
DOT Polkadot
$0.8587 +2.25%
LINK Chainlink
$8.18 -0.30%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{ๅนดไปฝ}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

28
03
unlock Arbitrum Token Unlock

92 million ARB released

12
05
halving BCH Halving

Block reward halving event

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All โ†’
1
Bitcoin
BTC
$64,439.8
1
Ethereum
ETH
$1,874.23
1
Solana
SOL
$74.19
1
BNB Chain
BNB
$601.7
1
XRP Ledger
XRP
$1.07
1
Dogecoin
DOGE
$0.0702
1
Cardano
ADA
$0.1927
1
Avalanche
AVAX
$6.69
1
Polkadot
DOT
$0.8587
1
Chainlink
LINK
$8.18

๐Ÿ‹ Whale Tracker

๐Ÿ”ด
0xb1da...8141
12h ago
Out
2,417,851 USDC
๐ŸŸข
0x88c3...0a94
1h ago
In
14,784 BNB
๐ŸŸข
0xaa99...e680
1d ago
In
4,563,362 USDC

๐Ÿ’ก Smart Money

0x5ee9...2afb
Early Investor
+$2.0M
95%
0xb74e...65e4
Arbitrage Bot
-$1.6M
84%
0xd6e5...8da8
Early Investor
+$2.9M
65%

๐Ÿงฎ Tools

All โ†’
Stablecoins

The New Job Scam That's Eating Web3 Wallets: SlowMist Exposes Cross-Platform Malware Dressed as AI Interview Tool

PlanBEagle

Yesterday, a friend in Tokyo asked me to check a suspicious .dmg file. The sender was a "recruiter" from a well-known DeFi protocol, promising a six-figure salary for a senior smart contract role. The file was called Relay_AI_Meeting_v1.2.dmg. That was the hook. By the time SlowMist published their advisory on July 29, 2025, I'd already seen the pattern: this wasn't a phishing link โ€“ it was a full-blown, cross-platform information stealer disguised as the hottest AI-powered interview tool on the market.

The context: Web3 recruiting has become a prime attack surface. Since 2022, I've watched social engineering evolve from fake job posts on Telegram to deepfake video calls. But this one feels different. It's surgical. The attackers didn't spray generic emails. They targeted professionals who already hold significant crypto assets โ€“ the very people who manage funds, write contracts, and sign transactions daily. The narrative they weaponized is our industry's biggest blind spot: the hunger for AI-native tools. "Relay" sounds legit. It promises AI-generated meeting notes, real-time transcription, and seamless calendar integration. In a market that worships AI agents, who wouldn't click?

The core: SlowMist's technical breakdown reveals a stealer with surgical precision. It targets both macOS and Windows, rummaging through browser credential stores, crypto wallet extensions (MetaMask, Phantom, Rabby, you name it), system keychains, Telegram session cookies, and even password managers. The malware doesn't just steal โ€“ it exfiltrates via custom command-and-control channels. Based on my audit experience, the code likely uses anti-analysis tricks like dynamic API resolution and encrypted strings to evade signature-based detection. This isn't a script kiddie operation. The attacker spent weeks building trust, crafting LinkedIn profiles, and calibrating the payload to match the expected interview workflow. One interview invite. One double-click. Your entire crypto portfolio walks out the door.

The contrarian angle: Most security advice focuses on "don't click unknown links." That's outdated. This attack succeeds because the link is known โ€“ it comes from a fake but convincing recruiter profile. The real blind spot is our collective trust in the hiring process itself. We're so desperate for talent (or for a new job) that we voluntarily download unknown executables. The contrarian bet here is that hardware wallets alone won't save you if you run the malware on your daily driver. Even your Telegram 2FA session is stolen. The signal in the noise is this: the next iteration will use deepfake audio to join a real-time interview, asking you to install the tool "for compatibility." When the crowd jumps on the AI-recruiting bandwagon, I look for the net.

The takeaway: Don't run any software from a recruiter. Period. If you're a Web3 professional, set up a dedicated VM or a cheap laptop for interviews. Rotate your Telegram cookies after every call. Cold storage isn't just for assets โ€“ it's for your identity. The story here is that the attack vector has shifted from protocol exploits to human trust. From the ashes of Terra, we learned to walk; now we need to learn to say no to a job offer that looks too good to be true. The map is not the territory, but the story is โ€“ and this story is about how our own narrative hunger for the next big AI tool is being weaponized against us. Be skeptical. Stay safe.