DiviCube

The Relay Trap: Why Your Next Job Interview Could Drain Your Wallet

Guide | Zoetoshi |

A freshly crafted malware sample hit the wires July 29, 2025. Two binaries. One for macOS, one for Windows. Both designed to do one thing: siphon every credential from a Web3 professional’s machine. The lure? An AI meeting tool called "Relay." The delivery? A fake recruiter on LinkedIn. The result? Total asset compromise. I didn't touch the sample myself—SlowMist beat me to it—but their report reads like a blueprint for a new wave of targeted attacks. The spread wasn't wide yet. It will be. You don't walk into a bear trap. You walk into a job interview.

Context: The Web3 Hiring Gold Rush The crypto market is in mid-bull cycle euphoria. Everyone’s hiring. Projects raise $100M and need engineers, marketers, community managers. The remote-first nature of Web3 means LinkedIn messages are constant. AI-powered interview tools are normal—companies use them to screen candidates faster. The trust is built on familiarity: a recruiter’s profile, a calendar invite, a link to download a tool. The same trust that drives adoption drives vulnerability. When I ran my 2017 ICO arbitrage script, I didn’t trust the platforms. I trusted my Python. But I also understood that the market moves on speed, not due diligence. The same speed that made me $150k in six weeks is now weaponized against job seekers.

SlowMist’s analysis reveals a carefully orchestrated social engineering chain. The attacker creates a fake recruiter persona, scrapes real Web3 job postings, and reaches out to targets. The “Relay” application is a custom-built stealer, packed with obfuscation to bypass endpoint detection. It targets browser credentials—Chrome, Brave, Firefox. It targets keychain and macOS Keychain. It targets Telegram session files. And it targets cryptocurrency wallet extensions—MetaMask, Phantom, Rabby. One install, and your private keys, your seed phrases, your 2FA backup codes are gone. The structural integrity of your security posture collapses instantly.

Core: The On-Chain Forensics of Trust Exploitation Let’s break the attack chain down like I would a DeFi exploit. The vulnerability isn't in a smart contract. It’s in the human operating system.

Phase 1: Reconnaissance The attacker monitors LinkedIn, X, and Telegram groups for active job seekers. They target individuals with public wallets—ENS names, NFT PFP, dex trading history. A quick blockchain scan confirms the target has assets worth stealing. The attacker creates a believable LinkedIn profile: real company name, fake employee, professional photo (often stolen from a real person or AI-generated). I’ve seen these profiles before. The difference now is the sophistication of the follow-up.

Phase 2: The Hook The message is personalized: "Hi [Name], I’m a recruiter for [Project]. We loved your work on [Project/Thread]. Are you open to a quick chat? We use a new AI scheduling tool called Relay. Could you install it and pick a time?" The tool is packaged as a .dmg or .exe, hosted on a custom domain that mimics a real meeting platform. The domain is registered with privacy services, the SSL certificate is valid. From a UX perspective, the moon is the limit—attackers now copy the entire front end of Calendly or Zoom.

Phase 3: The Install The user downloads and runs the file. On macOS, the app passes Gatekeeper because it’s signed with an Apple Developer ID (stolen or bought). On Windows, Windows Defender flags nothing—the binary is freshly compiled and hashes are unknown. The malware immediately spawns child processes: - A credential stealer that scrapes browser databases. - A keychain dumper that decrypts stored passwords. - A Telegram session hijacker that reads tdata files. - A wallet extension data miner that targets local storage files.

I’ve audited wallet code. The lack of encryption on local storage for most hot wallets is insane. Structural integrity? Zero. The malware doesn’t need to break encryption; it just copies the files. The data is then exfiltrated via HTTPS to a command-and-control server, often disguised as a legitimate analytics API.

Phase 4: The Aftermath Within minutes, the attacker has the user’s private keys, Telegram sessions, and email access. They log into the victim’s exchange accounts, drain funds, and mint malicious NFTs. The Telegram session allows them to impersonate the victim in group chats—sending messages to friends asking for “a small loan” or sharing malicious links. This is a systemic collapse, not just a single wallet loss.

Contrarian: The Real Blind Spot Is Not AI—It’s Trust Everyone is panicking about AI deepfakes and AI-generated code. Meanwhile, the simplest attack vector—a fake recruiter with a customized stealer—is winning. The contrarian truth: the crypto community’s obsession with “trustlessness” has made us lazy in the physical world. We trust hardware wallets, but we install random software to get a job. We trust multisig, but we click on links from unknown people.

Let’s talk about the narrative. The market is in a bull run. Prices are up. FOMO is high. The last thing anyone wants to hear is “don’t install that meeting tool.” But that’s exactly when the best trades are front-run—by being contrarian to euphoria. I shorted LUNA in 2022 when everyone was buying the dip. The systemic failure was obvious if you looked at the on-chain transaction logs. The same principle applies here: the systemic failure is the lack of security hygiene in hiring processes.

The attack doesn’t break any blockchain protocol. It breaks the trust fabric of the Web3 workforce. And the market isn’t pricing that risk yet. The contrarian play? Don’t be the victim. But also watch for the second-order effects: hardware wallet sales will spike, security audit firms like SlowMist will see increased demand, and new identity verification protocols (DID, ZK-based interview tools) will get funded. The narrative shift is real.

Takeaway: Actionable Price Levels for Your Security Budget You don’t need to buy a new token. You need to buy a second laptop. Or at least a dedicated VM. Here’s my battle-tested checklist: 1. Hardware wallet only for signing—never enter your seed phrase into anything that runs on your main OS. 2. Dedicated interview machine—a cheap laptop or a virtual machine that you nuke after each session. No saved credentials, no browser extensions. 3. Verify identities through secondary channels—if a recruiter contacts you on LinkedIn, DM their official X account or send a message to the company’s verified team. If they can’t confirm, don’t install. 4. Use a burner Telegram account—never log into your primary Telegram on a machine that also holds your crypto. 5. Monitor SlowMist’s IOC list—the hashes and domains for “Relay” are published. Block them on your home router.

The market is pricing in a 0% chance of you getting hacked. The real probability is higher. I didn’t write this to scare you. I wrote it because I’ve seen the logs. The structural integrity of your digital life depends on a single click. The spread between safe and compromised isn’t a hack—it’s a job offer.

Trust the code. Not the sender.

Market Prices

Coin Price 24h
BTC Bitcoin
$77,452.6 -3.01%
ETH Ethereum
$2,433.25 -2.75%
SOL Solana
$103.57 -3.57%
BNB BNB Chain
$687.8 -3.59%
XRP XRP Ledger
$1.38 -3.18%
DOGE Dogecoin
$0.0844 -4.34%
ADA Cardano
$0.2002 -4.98%
AVAX Avalanche
$7.28 -2.77%
DOT Polkadot
$0.8384 -4.03%
LINK Chainlink
$11.32 -4.14%

Fear & Greed

68

Greed

Market Sentiment

Event Calendar

{{年份}}
10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

12
05
halving BCH Halving

Block reward halving event

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$77,452.6
1
Ethereum ETH
$2,433.25
1
Solana SOL
$103.57
1
BNB Chain BNB
$687.8
1
XRP Ledger XRP
$1.38
1
Dogecoin DOGE
$0.0844
1
Cardano ADA
$0.2002
1
Avalanche AVAX
$7.28
1
Polkadot DOT
$0.8384
1
Chainlink LINK
$11.32

🐋 Whale Tracker

🟢
0xaf1a...9d11
12h ago
In
225 ETH
🔴
0xba77...7f77
6h ago
Out
44,989 SOL
🟢
0xba89...fa4b
2m ago
In
45,509 BNB

💡 Smart Money

0xb364...a323
Early Investor
+$0.1M
69%
0x552a...985a
Market Maker
+$1.9M
90%
0x19a3...b656
Market Maker
+$4.5M
95%