You receive a LinkedIn message from a respected firm. They want to interview you for a blockchain role. They send a link to an AI-powered meeting tool called 'Relay'. You download and install it. Your wallet empties within the hour.
This isn't a hypothetical. Over the past week, SlowMist published a detailed sample analysis of this exact attack chain. The malware targets Web3 professionals specifically. It's cross-platform—macOS and Windows. And it doesn't just steal your crypto; it steals your entire digital identity.
Context: The New Social Engineering
The crypto bear market of 2025 has shifted the attack surface. During bull runs, phishing targets FOMO—fake airdrops, malicious DEX links. In a bear market, attackers prey on survival instincts: the need for a job. Recruiters are trusted gatekeepers. When a 'recruiter' sends a custom link, the guard drops.
SlowMist's report confirms the vector: impersonators pose as headhunters for top Web3 companies. They request an 'AI-assisted interview' and provide a download link for a software called 'Relay'. Once installed, the malware executes silently. It harvests browser credentials (including session cookies), crypto wallet extension data, macOS keychain passwords, Windows credential manager, and Telegram session tokens. Everything gets exfiltrated to a command-and-control server.
Core: The Forensic Breakdown
Let's dissect the technicals. The malware is not a simple script kiddie tool. It's compiled for both operating systems, suggesting a developer with cross-platform experience. On macOS, it uses a signed .app bundle (likely with a stolen developer certificate) to bypass Gatekeeper. On Windows, it uses a standard MSI installer with embedded executables. Both versions employ anti-debugging techniques—checking for VMWare and VirtualBox processes—to evade sandbox analysis.
The exfiltration scope is what makes this lethal. It doesn't just target hot wallets like MetaMask or Phantom. It scrapes all browser-stored passwords, cookies, and autofill data. This means the attacker can log into any web service the victim uses: email, cloud storage, exchange accounts. The Telegram session token theft is particularly dangerous. Once stolen, the attacker can impersonate the victim in real-time, sending phishing messages to their contacts—including colleagues and other recruiters.
I've audited hundreds of smart contracts over the past seven years, from the 2017 ICO crucible through DeFi Summer and the Terra collapse. The most dangerous code isn't a flawed AMM or a reentrancy bug. It's the code you voluntarily execute on your own machine. Code is law until the audit reveals the trap. Here, the audit is too late—the trap is already on your desktop.
Contrarian: The Real Risk Is Trust, Not Wallets
The standard advice is 'use a hardware wallet' or 'don't click links'. Both are correct, but they miss the supply chain vulnerability. The attacker isn't breaking into your Ledger; they're breaking into your trust in the recruiting process. In a bear market, every job opportunity feels like a lifeline. That desperation is the exit liquidity. Yield is the bait; exit liquidity is the hook. In this case, the 'yield' is a salary, but the hook is your entire wallet.
Another blind spot: even if you use a hardware wallet, the malware can steal your seed phrase if you've ever typed it into a browser or stored it in a notes app. And the Telegram session token means the attacker can bypass 2FA on exchanges that use Telegram for verification. The compromised session is more valuable than a single private key.
Sweep the floor, not the FOMO. In bear markets, the floor isn't a price level; it's your security hygiene. The contrarian play isn't to avoid all job applications—it's to isolate the interview environment entirely.
Takeaway: Actionable Levels
Here are the price levels for your own safety. Not for a token, but for your career and capital.
- Isolate your interview machine. Use a dedicated laptop or a virtual machine with no personal accounts logged in. Treat any recruiter-sent software as a potential zero-day.
- Hardware wallets only. Keep all significant funds on cold storage. If you need to move assets for a job-related transaction (e.g., receiving a token airdrop as part of a test), use a separate hot wallet with minimal balance.
- Rotate Telegram sessions. Go to Settings > Privacy and Security > Active Sessions. Terminate all sessions except your phone. Enable 2FA with a strong password.
- Verify the recruiter. Call the company directly using a phone number from their official website. Do not use the contact info from the LinkedIn message.
- Don't execute unverified binaries. If a recruiter insists on installing a specific tool, ask for an alternative. Real recruiters will accommodate; attackers will pressure.
Forward-Looking Thought
This is the new frontier of crypto crime. The next iteration will incorporate deepfake video interviews to bypass verification. The blockchain industry prides itself on trustless systems, but human trust remains the weakest link. As community founders and traders, we need to build decentralized identity protocols into hiring pipelines. Otherwise, the biggest rug pull in 2026 won't be a DeFi protocol—it will be your own career.
Patience is for traders; timing is for killers. The timing to act is now, before the next wave of these traps hits your inbox.