Yesterday, a friend in Tokyo asked me to check a suspicious .dmg file. The sender was a "recruiter" from a well-known DeFi protocol, promising a six-figure salary for a senior smart contract role. The file was called Relay_AI_Meeting_v1.2.dmg. That was the hook. By the time SlowMist published their advisory on July 29, 2025, I'd already seen the pattern: this wasn't a phishing link โ it was a full-blown, cross-platform information stealer disguised as the hottest AI-powered interview tool on the market.
The context: Web3 recruiting has become a prime attack surface. Since 2022, I've watched social engineering evolve from fake job posts on Telegram to deepfake video calls. But this one feels different. It's surgical. The attackers didn't spray generic emails. They targeted professionals who already hold significant crypto assets โ the very people who manage funds, write contracts, and sign transactions daily. The narrative they weaponized is our industry's biggest blind spot: the hunger for AI-native tools. "Relay" sounds legit. It promises AI-generated meeting notes, real-time transcription, and seamless calendar integration. In a market that worships AI agents, who wouldn't click?
The core: SlowMist's technical breakdown reveals a stealer with surgical precision. It targets both macOS and Windows, rummaging through browser credential stores, crypto wallet extensions (MetaMask, Phantom, Rabby, you name it), system keychains, Telegram session cookies, and even password managers. The malware doesn't just steal โ it exfiltrates via custom command-and-control channels. Based on my audit experience, the code likely uses anti-analysis tricks like dynamic API resolution and encrypted strings to evade signature-based detection. This isn't a script kiddie operation. The attacker spent weeks building trust, crafting LinkedIn profiles, and calibrating the payload to match the expected interview workflow. One interview invite. One double-click. Your entire crypto portfolio walks out the door.
The contrarian angle: Most security advice focuses on "don't click unknown links." That's outdated. This attack succeeds because the link is known โ it comes from a fake but convincing recruiter profile. The real blind spot is our collective trust in the hiring process itself. We're so desperate for talent (or for a new job) that we voluntarily download unknown executables. The contrarian bet here is that hardware wallets alone won't save you if you run the malware on your daily driver. Even your Telegram 2FA session is stolen. The signal in the noise is this: the next iteration will use deepfake audio to join a real-time interview, asking you to install the tool "for compatibility." When the crowd jumps on the AI-recruiting bandwagon, I look for the net.
The takeaway: Don't run any software from a recruiter. Period. If you're a Web3 professional, set up a dedicated VM or a cheap laptop for interviews. Rotate your Telegram cookies after every call. Cold storage isn't just for assets โ it's for your identity. The story here is that the attack vector has shifted from protocol exploits to human trust. From the ashes of Terra, we learned to walk; now we need to learn to say no to a job offer that looks too good to be true. The map is not the territory, but the story is โ and this story is about how our own narrative hunger for the next big AI tool is being weaponized against us. Be skeptical. Stay safe.