The Silent Recruitment Trap: How a Fake AI Interview Tool Is Draining Web3 Wallets
On July 29, 2025, SlowMist published a sample analysis of a new information-stealing malware disguised as an AI meeting tool called 'Relay'—targeting Web3 professionals actively seeking jobs. The attack chain is clean: a fake recruiter reaches out on LinkedIn or Telegram, schedules an interview, and sends a link to download 'Relay', a supposed AI-powered interview assistant. The victim installs it, and within minutes, their browser credentials, crypto wallet data, keychain entries, and Telegram session tokens are exfiltrated to a remote server. This is not a phishing email; it is a tailored, cross-platform trojan designed to empty the digital pockets of those who build the decentralized economy.
The context here is critical. We are in a sideways market, where consolidation drives many professionals to explore new opportunities. The job-seeking mindset lowers guard: people are eager to trust a recruiter who offers a promising role at a reputable project. Attackers exploit this psychological window. The 'Relay' malware exists in both macOS and Windows variants, indicating a development team with cross-platform competence and a clear understanding of the Web3 workforce, which is heavily Mac-based. The scope of data theft—browser cookies, password managers, hardware wallet companion apps, Telegram sessions—shows the attackers know exactly where private keys live and how to access them. They are not after your email; they are after your seed phrase.
Now, let's examine the core technical architecture. The malware, as per SlowMist's analysis, is not a simple keylogger. It uses modular components: a dropper that fetches the payload from a remote C2, a credential stealer that hooks browser processes, and a Telegram session hijacker that copies the local session database. The macOS version likely exploits the TCC (Transparency, Consent, and Control) framework permissions, tricking the user into granting accessibility access under the guise of 'screen sharing for the interview'. Once granted, the malware can read keystrokes, capture screen content, and access the keychain where many users store private keys. On Windows, it uses similar techniques, targeting Chrome, Firefox, and Edge profile directories. The code does not lie, but it can be misunderstood—here, the code reveals a professional operation.
Based on my own experience auditing 45 smart contracts during the 2017 ICO frenzy, I have seen social engineering evolve from simple phishing to this level of precision. The attack leverages the same trust mechanisms that make decentralized communities thrive: open communication, remote collaboration, and a shared belief in autonomy. But trust is earned in drops and lost in buckets. This incident is a bucket. The attackers have weaponized the very tools we use to build the future: LinkedIn, Telegram, and Zoom alternatives. They have studied the ecosystem and found the weakest link—the human being behind the screen.
Here is the contrarian angle. Conventional wisdom says that the biggest risks in crypto are smart contract bugs, oracle manipulation, or liquidity crises. But this attack highlights a more insidious threat: the erosion of trust in the recruitment layer of Web3. If professionals cannot trust a job offer, the entire talent pipeline stalls. Projects will struggle to hire, innovation slows, and the narrative shifts from 'decentralized opportunity' to 'decentralized danger'. Yet, this same fear creates a market opportunity. Security companies like SlowMist, hardware wallet manufacturers (Ledger, Trezor), and endpoint detection vendors will see increased demand. The attack also validates the need for zero-trust interview environments—sandboxed VMs, isolated browsers, or dedicated 'interview laptops' that never touch real wallets. The winners will be those who operationalize security as a service for the hiring process.
Let me offer a concrete, actionable takeaway. First, if you are a Web3 professional currently job hunting, immediately audit your system for any suspicious applications named 'Relay' or similar. Check your browser extensions, your startup items, and your Telegram authorized sessions. Second, for every interview, use a completely separate device or a sandboxed virtual machine. Never run untrusted software on your main machine where your wallet is installed. Third, verify recruiters through multiple channels—cross-reference their LinkedIn profile with the project's official website, call the company's public number, and ask for a video call where you can see their face before downloading anything. Finally, move all significant funds to a hardware wallet and resist the urge to connect it to any software during the hiring process. In the silence of the dip, the weak hands break. Here, the weak hands are those who click without verifying.
This is not a theoretical warning. The code has been analyzed, the sample is in the wild, and the window for protection is closing. Assume that any unsolicited interview invitation with a 'unique AI tool' is hostile until proven otherwise. The market may be sideways, but the attackers are moving sideways too—straight into your wallet.