MPC-lab

Market Prices

Coin Price 24h
BTC Bitcoin
$64,100.4 +0.95%
ETH Ethereum
$1,866.79 +0.62%
SOL Solana
$73.7 +0.70%
BNB BNB Chain
$598.9 +1.58%
XRP XRP Ledger
$1.07 -0.17%
DOGE Dogecoin
$0.0700 -0.10%
ADA Cardano
$0.1919 +0.10%
AVAX Avalanche
$6.66 +0.23%
DOT Polkadot
$0.8586 +3.78%
LINK Chainlink
$8.13 -0.29%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

18
03
unlock Sui Token Unlock

Team and early investor shares released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

28
03
unlock Arbitrum Token Unlock

92 million ARB released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$64,100.4
1
Ethereum
ETH
$1,866.79
1
Solana
SOL
$73.7
1
BNB Chain
BNB
$598.9
1
XRP Ledger
XRP
$1.07
1
Dogecoin
DOGE
$0.0700
1
Cardano
ADA
$0.1919
1
Avalanche
AVAX
$6.66
1
Polkadot
DOT
$0.8586
1
Chainlink
LINK
$8.13

🐋 Whale Tracker

🔵
0x8136...14f7
1d ago
Stake
3,997 ETH
🔴
0xfd5b...eb0a
12m ago
Out
3,030,274 USDT
🟢
0xfd5c...6133
1d ago
In
3,372 ETH

💡 Smart Money

0xc76d...4846
Institutional Custody
+$1.0M
80%
0x364f...f941
Experienced On-chain Trader
+$0.3M
78%
0x9495...c1be
Top DeFi Miner
+$4.0M
72%

🧮 Tools

All →
Trends

The Fake Interview That Drains Your Wallet: SlowMist Exposes Cross-Platform Malware Targeting Web3 Professionals

LarkLion
We didn’t. That’s the first thought when you read the SlowMist report: a fake AI meeting tool named ‘Relay’ that hollows out your browser cookies, wallet private keys, and Telegram session within minutes. It isn’t a theoretical threat. It’s live. Today, targeting every Web3 professional searching for their next role. The attack chain is devastatingly simple: a recruiter (often impersonating a real employee from a known DeFi protocol) reaches out on LinkedIn or Telegram. The conversation moves to a technical interview. The candidate is asked to install ‘Relay’ – an AI-powered meeting record tool – for the screening. Once installed, the malware exfiltrates credentials from Chrome, Brave, and other browsers, dumps macOS Keychain and Windows Credential Manager, steals Telegram session files (bypassing 2FA), and specifically targets crypto wallets like MetaMask, Phantom, and even browser extensions. SlowMist’s sample analysis reveals the malware is cross-platform – compiled for both Intel and ARM on macOS, and native Windows executables. It uses obfuscation to evade antivirus. The data is sent to a command-and-control server before the user even realises the ‘Relay’ app has no actual features. The victim is left with an empty wallet and a compromised set of enterprise credentials. — Root: The assumption of trust in recruitment processes. I’ve built teams for Web3 projects since 2021. I’ve conducted over a hundred video interviews. Never once did I ask a candidate to install a third-party tool before even speaking. Yet this vulnerability exists because the industry markets itself as ‘trustless’ while every hiring pipeline relies on blind trust: trust in a LinkedIn profile, trust in a Telegram handle, trust in a Zoom link. The attackers weaponise this gap. The technical lesson here is that hot wallets are liabilities during any remote interaction. The moment your browser is compromised, your private keys – even those not stored in a file but accessed via a browser extension – are extractable. Hardware wallets reduce the attack surface, but they don’t protect against session hijacking: if your Telegram session is cloned, the attacker can approve transactions in a wallet connected via WalletConnect or even social engineer your contacts. But the contrarian angle is sharper: while the industry panics about smart contract bugs and exploit pools, the most efficient extraction vector remains the human who trusts a URL. We spend $100 million on audits per quarter, yet a single fake Zoom invite can steal more value than any DeFi hack this year. The real vulnerability is not in the code – it’s in the culture of remote hiring that has no verification standard. — Root: The market’s obsession with protocol security blinds it to operational threats. Third-party recruitment agencies in Web3 often have minimal KYC. I’ve personally seen fake job postings for ‘community managers’ that asked applicants to share their wallet address for ‘test salary distribution’. That was a small-scale scam. This new vector is surgical: it targets senior engineers, security researchers, and ops staff – people with access to multi-sig wallets and vault keys. One compromised hire can drain an entire DAO treasury. SlowMist’s disclosure is a public service, but it raises an uncomfortable question: how many similar tools are already circulating? The team behind ‘Relay’ likely used a stolen identity and a rented VPS. They will spin up a new name tomorrow. The industry needs a systemic fix, not a reactive wipe. What does that fix look like? First, every Web3 company should enforce a ‘sandbox interview’ policy: candidates must run interview software inside a dedicated virtual machine or a container that has no access to host wallets or sessions. Second, hardware wallets should be mandatory for anyone handling funds – disconnect them during meetings. Third, decentralised identity (DID) for professional credentials is no longer a luxury; it’s a lifeboat. If every verified recruiter had a on-chain immutable credential tied to their ENS, the attack surface shrinks dramatically. I’ve started advising portfolio projects to implement a simple rule: no external software installation before the first hire contract is signed. Use only browser-based meeting tools that require no download. The UX friction is negligible compared to losing a five-figure wallet. Takeaway: The next job offer you receive could be the last. Verify the recruiter through at least two independent channels – call their company’s official number, check their ENS, or ask for a signed message. Don’t trust an invite’s legitimacy because the Zoom link looks legit. The code that drains your wallet doesn’t live on-chain. It lives in your trust.