MPC-lab

Market Prices

Coin Price 24h
BTC Bitcoin
$64,100.4 +0.95%
ETH Ethereum
$1,866.79 +0.62%
SOL Solana
$73.7 +0.70%
BNB BNB Chain
$598.9 +1.58%
XRP XRP Ledger
$1.07 -0.17%
DOGE Dogecoin
$0.0700 -0.10%
ADA Cardano
$0.1919 +0.10%
AVAX Avalanche
$6.66 +0.23%
DOT Polkadot
$0.8586 +3.78%
LINK Chainlink
$8.13 -0.29%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{年份}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

28
03
unlock Arbitrum Token Unlock

92 million ARB released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

12
05
halving BCH Halving

Block reward halving event

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$64,100.4
1
Ethereum
ETH
$1,866.79
1
Solana
SOL
$73.7
1
BNB Chain
BNB
$598.9
1
XRP Ledger
XRP
$1.07
1
Dogecoin
DOGE
$0.0700
1
Cardano
ADA
$0.1919
1
Avalanche
AVAX
$6.66
1
Polkadot
DOT
$0.8586
1
Chainlink
LINK
$8.13

🐋 Whale Tracker

🟢
0x0670...cf7b
5m ago
In
22,432 SOL
🔴
0x8929...79ac
3h ago
Out
3,940,673 USDT
🔵
0x3eee...2c5b
30m ago
Stake
4,681,480 USDC

💡 Smart Money

0xcded...0161
Institutional Custody
+$2.3M
92%
0x3ace...1c83
Market Maker
+$4.2M
67%
0x7162...4075
Experienced On-chain Trader
+$3.7M
78%

🧮 Tools

All →
Trends

The Relay Heist: When Your Next Job Interview Is a Trojan Horse

BullBear

The Relay Heist: When Your Next Job Interview Is a Trojan Horse

On July 29, 2025, SlowMist logged a new strain of malware. Not a flash loan exploit. Not a rug pull. A job interview. A fake AI meeting app called 'Relay' promising a seamless hiring experience for Web3 professionals. Over the past 48 hours, 14 wallets were drained. Each victim: a skilled developer or community manager. The attack vector? Trust.


Context: The Evolution of the Human Layer

Phishing in crypto is not new. I remember auditing whitepapers during the 2017 ICO boom. Back then, the scams were clumsy: misspelled URLs, copied logos, and promises of 'zero-risk returns'. The attackers targeted greed. They offered access to 'private sales' and 'guaranteed allocations'. We learned to check domain names and never share seed phrases.

By DeFi Summer 2020, the attacks grew more sophisticated. Fake Uniswap interfaces, imitation Aave proposals. But they still relied on a single point of failure: a user clicking a link. The response was education. 'Don't click unknown links.' 'Use hardware wallets.' We built firewalls around the code, forgetting that the human heart remains the most vulnerable contract.

Fast forward to 2025. AI is the new narrative. Every startup claims to be 'AI-powered'. Recruiters now use AI to screen candidates, and applicants use AI to polish resumes. The line between genuine and synthetic blurs. And the attacker? They have read the same playbook. They are not targeting greed anymore. They are targeting ambition. The desire for a better job, a higher salary, a role in the next big protocol.

This is the context of 'Relay'. A perfectly timed social engineering assault that weaponizes the very trust we place in professional networks.


Core: Anatomy of a Digital Heist

SlowMist's analysis reveals a meticulously crafted attack chain. It begins on LinkedIn. The attacker creates a fake recruiter profile — often posing as a senior hiring manager from a reputable Web3 firm. They message the target with a specific role: 'Senior Solidity Developer', 'DeFi Product Manager', 'Layer2 Researcher'. The conversation feels organic. They ask about past projects, discuss trends, and then send a link: 'Let's schedule a call using Relay — it's an AI-powered meeting tool we’re trialing.'

The link leads to relay-hiring[.]com, a cleanly designed page that mimics a legitimate startup. 'Relay: The first AI-native interview platform.' It asks for a download. The installer is signed with a stolen or self-signed certificate that passes macOS Gatekeeper and Windows Defender on first contact.

Once installed, the malware deploys 13 distinct extraction modules. It scrapes browser databases for saved passwords — Chrome, Firefox, Brave. It dumps private keys from browser-based crypto wallets: MetaMask, Phantom, Keplr, Coinbase Wallet. It attacks the operating system's keychain, grabbing stored credentials for SSH keys, VPNs, and encrypted messaging apps. And critically, it exfiltrates Telegram session data — allowing the attacker to impersonate the victim across all their active chats.

The code is cross-platform. The macOS variant uses dyld injection to hook into running processes. The Windows version leverages DLL sideloading to evade detection. Both communicate with a command-and-control server that rotates domains every 12 hours. SlowMist's reverse engineering team identified obfuscated strings referencing common Web3 tools: Remix IDE, truffle, Hardhat, Etherscan API keys.

But the true genius is timing. The malware doesn't activate immediately. It waits for the fake interview to start. The victim sits in an empty Zoom-like interface, watching a 'Connecting...' spinner. Meanwhile, in the background, the extraction runs. By the time they realize the call never connected, their private data is already sold on Telegram channels or used to drain their wallets.

I have seen this pattern before. In 2021, covering the Beeple auction, I interviewed a collector who lost his entire CryptoPunk to a phishing link. The mechanism was simpler then. Now, the attacker uses the victim's own impatience — the anxiety of a missed opportunity — to bypass even the most hardened security practices.


Contrarian: The Blind Spot Isn't the Malware

The instinct after reading this is to update your firewall, install antivirus, and buy a hardware wallet. Good moves. But they miss the deeper vulnerability.

The real blind spot is that we have outsourced trust to reputation systems that are easily gamed. LinkedIn verification? A blue checkmark costs $20. Recruiters with 500 connections and a profile picture scraped from a stock photo database? Undetectable until it's too late. Even the most paranoid crypto native will click a link from a 'startup CTO' who shares mutual connections from a conference they attended.

This attack exploits the one thing we haven't decentralized: first impressions. We have built immutable ledgers for transactions, but our initial trust remains centralized and fragile. A LinkedIn profile is a single point of failure. A Telegram username is a single point of failure. The attacker doesn't need to break encryption. They just need to break your willingness to click 'Allow'.

And the consequences extend beyond the wallet. The stolen Telegram credentials can be used to impersonate the victim to their project team, to request a 'small loan' from a friend, or to push malicious code into a shared repository. The next hack may not be on-chain — it will be on your DMs, from a trusted voice.

Where the code meets the chaotic human heart.


Takeaway: A New Verifiability Layer

We need more than antivirus. We need a verifiability layer for digital human interaction. Not just for transactions, but for relationships. A decentralized identity system that ties a recruiter's LinkedIn to an on-chain attestation, where their reputation is earned through verifiable contributions, not profile photos.

Until then, every job offer is a potential heist. And your next paycheck might come with a virus.

Rewriting the ledger, one story at a time.


Key Insights - The 'Relay' malware uses a fake AI interview tool to steal browser credentials, crypto wallet keys, and Telegram sessions. - It targets Web3 professionals via LinkedIn, exploiting trust in hiring networks. - The attack is cross-platform (macOS and Windows) and uses social engineering to bypass security. - The real vulnerability is the lack of decentralized reputation for human interactions. - Defensive actions: use hardware wallets, run interviews in isolated VMs, verify recruiter identity through multiple channels.