You open your inbox. A LinkedIn message from a recruiter at a top-tier DeFi protocol. The company is real, the job listing matches your skills, and the urgency is palpable — they need you to interview tomorrow using their new AI-powered meeting tool, ‘Relay.’ You download the installer. You double-click. And in that instant, your entire crypto portfolio becomes someone else’s property. This is not a hack. This is a harvest.
Welcome to the new front line of Web3 security: a social engineering campaign so precisely targeted that it makes phishing emails look like spam. On July 29, 2025, SlowMist Security published a detailed analysis of a malware strain disguised as an AI interview platform, designed specifically to steal the private keys, browser credentials, and Telegram sessions of Web3 professionals. This isn’t a vulnerability in a smart contract — it’s a vulnerability in human trust. And in a bull market where speed is the only alpha left, that trust is the most expensive asset you have.

Context: The Bull Market Hiring Frenzy
The current bull cycle has triggered a massive hiring spree across Web3. Protocols are desperate for developers, strategists, and community managers. LinkedIn feeds are flooded with remote job postings offering six-figure salaries in stablecoins. Attackers have noticed the pattern — and they’ve built a trap that exploits the exact moment when suspicion is lowest.
SlowMist’s report reveals that the attackers create convincing fake recruiter profiles, often impersonating HR staff from well-known projects like Uniswap, Arbitrum, or Chainlink. They initiate conversations on LinkedIn or Telegram, and after a brief exchange, they send a link to download ‘Relay’ — a malicious application that presents itself as a next-generation AI meeting tool. The malware is cross-platform, with builds for both macOS and Windows, and it doesn’t just steal passwords. It extracts browser-stored private keys, keychain data, cryptocurrency wallet files, and — most critically — active Telegram session tokens. Telegram is the communication backbone of the crypto industry; a stolen session grants the attacker full access to a victim’s private chats, groups, and contacts, enabling follow-on spear-phishing attacks.
Core: Dissecting the Anatomy of a Pump
Let me break down the technical mechanics, because understanding the kill chain is the only defense. I’ve been tracking on-chain security incidents for years — from ICO exit scams to DeFi flash loan attacks — but this one is different. It’s not exploiting a code bug; it’s exploiting the gap between Web3’s decentralized ethos and the centralized platforms we rely on for hiring.
SlowMist’s analysis indicates that the ‘Relay’ malware is a custom information stealer, likely forked from existing open-source variants (like Stealerium or RedLine) but heavily modified. Here’s what it does:
- Browser Credential Theft: It scrapes saved passwords and cookies from Chrome, Firefox, Brave, and Opera. This alone is dangerous — many crypto exchange accounts are protected only by email-based 2FA, which becomes worthless if the cookie is stolen.
- Cryptocurrency Wallet Extraction: The malware specifically targets directories for MetaMask, Ledger Live, Exodus, and Phantom. It copies the entire wallet data folder, including encrypted keystore files. If the user’s wallet is unlocked or the password is saved in the browser, the private keys are instantly exposed.
- Keychain Access (macOS): On Mac systems, it reads the user’s login keychain, extracting passwords for VPNs, SSH keys, and API tokens. This is a goldmine for attackers who want to pivot to other services.
- Telegram Session Hijacking: This is the most insidious feature. The malware reads the Telegram Desktop session file (typically at
%APPDATA%\Telegram Desktop\tdataon Windows or~/Library/Application Support/Telegram Desktop/tdataon macOS) and transmits it to a command-and-control server. Once the attacker has the session, they can impersonate the victim without needing 2FA — Telegram’s verification is bypassed if the session is already authorized. - Persistence Mechanism: The installer adds itself to startup folders (Windows Run key or macOS LaunchAgents) to survive reboots. Even if the user deletes the app, the malware can reinstall itself from a temp file.
IOCs (Indicators of Compromise) published by SlowMist include specific file hashes, domain names used for C2 communication, and unique registry keys. I’ve verified some of these against my own threat intel feeds — the C2 domains are registered on privacy-focused registrars, and the SSL certificates are self-signed, a classic pattern for limited-lifetime campaigns.
The attack is shockingly effective because it leverages the ‘AI tool’ narrative. In 2025, every crypto startup is using AI-powered tools for recruitment, project management, or trading. The market is saturated with new AI apps. The ‘Relay’ name sounds generic enough to be real. Victims are already primed to download unfamiliar software for interviews — they’ve done it before with Zoom, Google Meet, and Discord. The psychological friction is nearly zero.
From a quantitative perspective, the damage potential is enormous. Let me run a quick estimate: if the campaign targets 10,000 Web3 professionals, and only 1% fall for it, that’s 100 wallets drained. Assuming an average wallet value of $50,000 (conservative for industry insiders), the total stolen could exceed $5 million in a single wave. And that’s just the first-order loss — the second-order impact from compromised Telegram accounts could lead to multimillion-dollar social engineering scams against protocols.
Contrarian Angle: The Real Vulnerability Isn’t the Malware — It’s the Hiring Pipeline
Here’s the contrarian take that most security analysts are missing. Everyone is focusing on the malware code, the C2 infrastructure, the IOCs. That’s table stakes. The real story is the structural fragility of Web3’s talent acquisition process.
Web3 companies pride themselves on trustless protocols, immutable code, and decentralized governance. Yet they recruit through LinkedIn — a centralized, identity-verification-light platform — and conduct interviews using unverified applications sent over unencrypted channels. Yields are just lies with better formatting, and so are these job offers. The gap between the industry’s technological ideals and its operational reality is the attack surface.
This attack will not be a one-off. It’s a proof of concept that will spawn copycats. We’re already seeing variants that use deepfake audio to impersonate recruiters during brief ‘intro’ calls. The lifecycle of this narrative is clear: initial shock, followed by a wave of security tips, then a gradual acceptance that remote hiring in crypto is inherently risky. The market will eventually demand standardized verification — maybe a blockchain-based identity system for job offers, or a secure sandbox environment for interviews.

There’s also a hidden opportunity. Security startups that can provide ‘verified interview environments’ — browser-based VMs that restrict file access, or hardware-backed authentication for job applications — will see explosive demand. This is the same pattern we observed after the Axie Infinity hack in 2022, which sparked a wave of cross-chain security audits.
Takeaway: Speed Without Security Is Just Faster Loss
The bull market is not a permission slip to lower your guard. Every signal sent over Telegram, every link clicked from a stranger, every app installed for an interview — each is a potential vector. I’ve seen too many post-mortems where victims say, “I knew better, but the opportunity was too good.”
Here’s my forward-looking judgment: within six months, we will see the emergence of a Web3-specific ‘interview security’ certification. Protocols will start requiring candidates to use verified interview portals, similar to how exchanges require KYC. The alpha today is not in chasing the next hot protocol — it’s in the infrastructure that secures the people building it.
Chasing the ghost in the liquidity pool is one thing. Chasing a ghost job is another. The next time you see a recruiter slide into your DMs with a ‘Relay’ link, ask yourself: is this a career move or a data extraction?
_Patterns hide in the noise floor — this noise is a signal. Listen to it._