Hook
On July 29, 2025, SlowMist dropped a threat intelligence report that should freeze every Web3 professional's mouse mid-click. A new strain of info-stealing malware, disguised as an AI-powered meeting tool called "Relay," has been actively deployed against crypto developers, traders, and founders. The attack chain is terrifyingly elegant: a fake recruiter on LinkedIn sends a link, the victim installs a seemingly legitimate app for an interview, and within seconds, malware exfiltrates browser credentials, cryptocurrency wallet files, macOS Keychain data, and even active Telegram sessions. The pixel that promised a job interview turned into a digital robber’s window. This isn’t another phishing campaign. It’s the first large-scale, cross-platform, socially engineered assault that weaponizes the Web3 hiring boom itself.
Context
Why now? The market has been sideways for months. Bitcoin oscillates between $65,000 and $72,000, altcoins bleed slowly, and the noise around AI+crypto convergence has reached a deafening pitch. In this environment, job seekers are desperate for signals of legitimacy—and scammers know it. Remote hiring has become the backbone of the decentralized workforce. LinkedIn, Telegram, and Discord are the new HR departments. Attackers have studied this ecosystem meticulously. They understand that Web3 professionals trust a custom interview tool over a generic Zoom link because it signals exclusivity and technical savvy. The "Relay" malware exploits that exact psychological shortcut. It’s not a bug in the software; it’s a direct attack on the trust fabric that holds the industry together. SlowMist’s report confirms the malware comes in both macOS and Windows variants, with a comprehensive theft capability that suggests a well-funded, technically adept adversary—likely a group with deep knowledge of crypto workflows.
Core
Let me walk through what the malware actually does, because the technical details reveal the attackers’ priorities. Based on my experience auditing incident response logs, the first thing that stands out is the cross-platform parity. Most crypto-targeting malware is Windows-only, assuming Mac users are either too savvy or too few. This one treats both equally. On macOS, it exploits the standard .dmg installation flow, then drops a binary that requests accessibility permissions—a common, often-approved request for screen recording or meeting apps. Once inside, it targets:
- Browser credential stores: Chrome, Firefox, and Brave. Not just passwords, but session cookies, meaning even users with 2FA are exposed if their session is still valid.
- Crypto wallet extensions: It scrapes local storage for MetaMask, Phantom, Rabby, and others, extracting seed phrases if they’re stored in plaintext or partially obfuscated.
- macOS Keychain: This is the killer. Keychain stores not just app passwords, but also Wi-Fi credentials, VPN settings, and in some cases, private keys from non-browser wallets like Electrum or Atomic Wallet.
- Telegram session files: The attacker harvests
tdatafolders, which allow them to hijack Telegram accounts entirely. Once inside, they can impersonate the victim to run further social engineering on their contacts, including other Web3 professionals.
The immediate impact is catastrophic for anyone who falls for it. But the ripple effect is worse. A single compromised Telegram account belonging to a well-known DeFi developer could lead to a wave of secondary attacks. The attacker can access private group chats, steal unpublished code, or trick team members into signing malicious transactions. The pixel wasn't a broken link; it was a vault key. The community didn't realize how vulnerable their communication channels were until this moment.
But here’s the insight that most coverage will miss: the malware’s theft prioritization tells us exactly what the attackers value most. They didn’t bother with system-level keyloggers or screen captures—too noisy. Instead, they focused on persistent tokens and stored secrets. This suggests the adversary is not interested in live monitoring but in long-term access and offline decryption. They want to drain wallets and sell access, not hold data for ransom. This is a precision strike on the most liquid assets in crypto: private keys and session tokens.
To prevent this, the immediate technical countermeasure is simple but painful: never install custom software for a job interview. Use a clean virtual machine or a dedicated hardware device. But the industry needs a systemic fix. Based on my conversations with security engineers at major exchanges, the attack has already triggered internal alerts. Expect mandatory hardware wallet usage for any professional engaging in remote interviews, and a sudden spike in demand for identity verification solutions like decentralized identifiers (DIDs).
Contrarian
The obvious narrative is "AI tools are dangerous—another reason to fear new tech." That’s lazy. The contrarian angle is that the real vulnerability is not the malware or even the AI narrative—it's the industry's reliance on trust without verification. We’ve built an entire economy on pseudonymous reputations, but when it comes to hiring, we still rely on a LinkedIn profile picture and a Zoom link. The attackers exploited a gap that the Web3 ethos itself created: the belief that transparency and community vetting eliminate the need for centralized identity checks. They don’t.
SlowMist’s report mentions that the fake recruiters had polished LinkedIn profiles with years of history and mutual connections. That’s not a technical hack—that’s a social one. The malware is just the delivery mechanism. The real story is that trust didn't depreciate fast enough. The community didn't spot the pattern until it was too late. We’ve been so focused on smart contract audits and cross-chain bridges that we forgot to audit the human layer. The contrarian take: this attack will accelerate the adoption of on-chain attestations for professional credentials. Platforms like ENS, Polygon ID, and Lit Protocol could see a surge in use as hiring managers demand verifiable claims. The very thing that made Web3 attractive—permissionless interaction—is now a liability. To fix it, we need voluntary reputation systems that are cryptographically secure.
Another blind spot: the attack exploits the AI hype cycle. By branding the tool as "AI-powered meeting software," the scammer leverages a market where thousands of new AI tools launch daily, each promising to revolutionize productivity. The skepticism usually reserved for crypto projects evaporates when the world "AI" is attached. This incident will force a recalibration: AI features must come with auditable transparency, not just marketing buzz. Expect regulators to latch onto this as justification for stricter software vetting requirements in financial hiring.
Takeaway
This is not a one-off exploit. It’s a new playbook. The combination of social engineering, cross-platform malware, and precise targeting will be replicated and refined. Within six months, we will see copycat variants that use deepfake video interviews or real-time voice cloning to bypass even multi-factor authentication. The only defense is to shift the trust layer from platform credentials (LinkedIn, Telegram) to cryptographic proofs (DIDs, signed attestations). The next time you receive a job offer that requires a custom install, ask yourself: would you trust this person with your seed phrase? Because that’s what you’re doing.
The pixel wasn't a bug. It was a feature for thieves. The community didn't see it coming. But trust shouldn't depreciate—it should upgrade. Will your next job interview be verified on-chain?