The Fake Interview That Drains Your Wallet: SlowMist Exposes Cross-Platform Malware Targeting Web3 Professionals
LarkLion
We didn’t. That’s the first thought when you read the SlowMist report: a fake AI meeting tool named ‘Relay’ that hollows out your browser cookies, wallet private keys, and Telegram session within minutes. It isn’t a theoretical threat. It’s live. Today, targeting every Web3 professional searching for their next role.
The attack chain is devastatingly simple: a recruiter (often impersonating a real employee from a known DeFi protocol) reaches out on LinkedIn or Telegram. The conversation moves to a technical interview. The candidate is asked to install ‘Relay’ – an AI-powered meeting record tool – for the screening. Once installed, the malware exfiltrates credentials from Chrome, Brave, and other browsers, dumps macOS Keychain and Windows Credential Manager, steals Telegram session files (bypassing 2FA), and specifically targets crypto wallets like MetaMask, Phantom, and even browser extensions.
SlowMist’s sample analysis reveals the malware is cross-platform – compiled for both Intel and ARM on macOS, and native Windows executables. It uses obfuscation to evade antivirus. The data is sent to a command-and-control server before the user even realises the ‘Relay’ app has no actual features. The victim is left with an empty wallet and a compromised set of enterprise credentials.
— Root: The assumption of trust in recruitment processes.
I’ve built teams for Web3 projects since 2021. I’ve conducted over a hundred video interviews. Never once did I ask a candidate to install a third-party tool before even speaking. Yet this vulnerability exists because the industry markets itself as ‘trustless’ while every hiring pipeline relies on blind trust: trust in a LinkedIn profile, trust in a Telegram handle, trust in a Zoom link. The attackers weaponise this gap.
The technical lesson here is that hot wallets are liabilities during any remote interaction. The moment your browser is compromised, your private keys – even those not stored in a file but accessed via a browser extension – are extractable. Hardware wallets reduce the attack surface, but they don’t protect against session hijacking: if your Telegram session is cloned, the attacker can approve transactions in a wallet connected via WalletConnect or even social engineer your contacts.
But the contrarian angle is sharper: while the industry panics about smart contract bugs and exploit pools, the most efficient extraction vector remains the human who trusts a URL. We spend $100 million on audits per quarter, yet a single fake Zoom invite can steal more value than any DeFi hack this year. The real vulnerability is not in the code – it’s in the culture of remote hiring that has no verification standard.
— Root: The market’s obsession with protocol security blinds it to operational threats.
Third-party recruitment agencies in Web3 often have minimal KYC. I’ve personally seen fake job postings for ‘community managers’ that asked applicants to share their wallet address for ‘test salary distribution’. That was a small-scale scam. This new vector is surgical: it targets senior engineers, security researchers, and ops staff – people with access to multi-sig wallets and vault keys. One compromised hire can drain an entire DAO treasury.
SlowMist’s disclosure is a public service, but it raises an uncomfortable question: how many similar tools are already circulating? The team behind ‘Relay’ likely used a stolen identity and a rented VPS. They will spin up a new name tomorrow. The industry needs a systemic fix, not a reactive wipe.
What does that fix look like? First, every Web3 company should enforce a ‘sandbox interview’ policy: candidates must run interview software inside a dedicated virtual machine or a container that has no access to host wallets or sessions. Second, hardware wallets should be mandatory for anyone handling funds – disconnect them during meetings. Third, decentralised identity (DID) for professional credentials is no longer a luxury; it’s a lifeboat. If every verified recruiter had a on-chain immutable credential tied to their ENS, the attack surface shrinks dramatically.
I’ve started advising portfolio projects to implement a simple rule: no external software installation before the first hire contract is signed. Use only browser-based meeting tools that require no download. The UX friction is negligible compared to losing a five-figure wallet.
Takeaway: The next job offer you receive could be the last. Verify the recruiter through at least two independent channels – call their company’s official number, check their ENS, or ask for a signed message. Don’t trust an invite’s legitimacy because the Zoom link looks legit. The code that drains your wallet doesn’t live on-chain. It lives in your trust.