DiviCube

The AI Interview Trap: How a Fake Zoom Clone Is Draining Web3 Wallets

Guide | CryptoLion |

The recruiter's voice was warm, professional. He asked about my Solidity experience, my thoughts on zk-rollups. The job was at a top-tier DeFi protocol — or so the LinkedIn message claimed. He sent a link: 'Relay', an AI-powered interview tool. Said it was the new standard for remote hiring. I downloaded it. The app icon flickered, then vanished. Thirty minutes later, my MetaMask balance was zero. That's not my story. But it was someone's. And it could be yours.

This isn't a protocol exploit. No flash loan attack, no oracle manipulation. This is a slow, silent kill — a social engineering spear aimed directly at the heart of Web3 talent. SlowMist dropped the analysis yesterday. The malware is cross-platform, targeting macOS and Windows. It steals browser credentials, crypto wallet keys, Apple Keychain data, Telegram sessions. Everything. And it's using the hottest narrative in crypto right now: AI.

Hype, heartbeats, and hard data — the trifecta of my reporting. But this time the data points to a bleeding wound. Over the past 7 days, a silent evacuation has been happening. Not of funds from a bridge, but of trust from the hiring pipeline. And the market? It's too busy watching charts to see the real threat: the people building the future are being harvested.

The Context: A Perfect Storm of Bad Timing

We're in a sideways market. July 2025. Bitcoin hovering around $75k, Ethereum gas low, everyone waiting for the next catalyst. The narrative cycle has shifted from memecoins to AI-driven infrastructure. Projects are racing to hire the best engineers, researchers, and operations folks. LinkedIn is flooded with job postings from new L2s, modular blockchains, and AI-agent protocols.

Attackers know this. They've studied the job market. They know that every Web3 professional is desperate to stay ahead of the curve, to grab a role that offers tokens, remote flexibility, and a front-row seat to the modular future. So they weaponize the very tools we trust: recruitment.

The 'Relay' app is a custom-built info-stealer. Not a repurposed malware kit — a bespoke, polished application designed to look legitimate. It mimics the UI of popular AI meeting tools like Otter.ai or Fireflies.ai. It even has a landing page with fake testimonials. The attacker plays the long game: they engage in multiple rounds of conversation, ask technical questions, build rapport. Then they send the 'tool' link.

Based on my audit experience, I've seen social engineering evolve from simple 'you won a Bitcoin' to sophisticated spear-phishing using compromised email threads. But this is different. This is a marriage of deep-tech narrative and old-school digital theft. The attacker doesn't need to break the blockchain. They just need to break the person.

The Core: How the Malware Works — A Technical Autopsy

SlowMist's analysis reveals a multi-stage attack chain. Let me break it down step by step, because if you're reading this, you need to know exactly what you're up against.

Stage 1: The Lure

The attacker identifies a target — usually a Web3 developer, smart contract auditor, or DevOps engineer with public-facing GitHub or LinkedIn profiles. They fake a recruiter persona: a company name that sounds real, a profile with a few connections, maybe a Veriswap handle. They message the target directly, offering a role with a competitive token package and fast-track interviews.

Stage 2: The Activation

After initial chat, the 'recruiter' proposes a technical interview using 'Relay'. The target downloads a DMG (macOS) or EXE (Windows) installer. The app requests permissions: accessibility API, keychain access, disk access — typical for a legitimate meeting tool. But behind the scenes, it executes a payload that installs a persistent backdoor.

What does it steal? Everything. - Browser credentials: stored passwords, cookies, autofill data from Chrome, Firefox, Brave, Edge. - Crypto wallet extensions: private keys, seed phrases from MetaMask, Phantom, Rabby, Backpack — any wallet that stores data in browser local storage or keychain. - Apple Keychain (macOS): This is critical. Many crypto users store SSH keys, Wi-Fi passwords, even hardware wallet PINs in Keychain. The malware uses the accessibility API to dump Keychain contents without user interaction. - Telegram sessions: The app scrapes Tdata folders, allowing attackers to log into the victim's Telegram account from their own machine. This enables social engineering on the victim's contacts, asking them to 'verify a new job offer' — and the cycle continues. - Other sensitive files: The malware searches for files with names like 'private key', 'seed', 'backup', 'wallet', and exfiltrates them via HTTPS to a C2 server.

Stage 3: The Extraction

The malware compresses all stolen data into a zip file and uploads it to a command-and-control server hosted on a decentralized storage network (IPFS or similar) to avoid takedown. The attacker then sifts through the data, prioritizing wallet keys and Telegram sessions. Within hours, the victim's hot wallet is drained — often before they even realize the interview was a scam.

Risk marker: High. This isn't a theoretical attack. SlowMist has confirmed multiple incidents with real victims. The attack surface is deliberately narrow: Web3 professionals. The precision is chilling.

The Contrarian Angle: This Isn't About You — It's About the Industry's Soft Underbelly

Most security warnings focus on the individual: don't click suspicious links, use hardware wallets, verify recruiters. All valid. But the contrarian view is that this attack reveals a structural vulnerability that the market is mispricing.

First, the attack is a diagnostic of the industry's trust deficit. Web3 is built on permissionless systems, but human interaction still relies on centralized platforms — LinkedIn, Telegram, Zoom. Attackers are exploiting the gap between decentralized ideals and centralized communication. The solution isn't just better antivirus; it's a rethink of how we verify identity in hiring.

Second, this attack will accelerate the adoption of decentralized identity (DID) and zero-knowledge credentials. If you're a job seeker, wouldn't you prefer a system where you can prove your skills without revealing your private key? I've been saying this since the 2021 NFT peak — tracing the trail from NFT peaks to DeFi valleys — identity is the next frontier. This attack is the catalyst.

Third, the contrarian trade is on security infrastructure. While the market lumps all 'crypto' into one asset class, the real winners will be infrastructure plays: hardware wallet makers (Ledger, Trezor), security audit firms (SlowMist, Trail of Bits), and decentralized identity protocols (like Polygon ID, Ceramic). The 'Relay' scam is a $0 market cap event for most tokens, but it's a billion-dollar catalyst for security.

The Takeaway: What to Watch Next

This isn't the last attack. It's the first of a new wave. The same AI tools that make our lives easier are being weaponized. Expect deepfake recruiters — AI-generated video calls where the attacker looks and sounds exactly like a real hiring manager. Expect fake coding challenges that deploy malware when you run npm install from a poisoned repository.

From the peak to the pit: a survivor — I've lived through LUNA, through FTX, through a dozen rug pulls. Each time, the market forgets until the next shock. But this time it's different. The attack targets the people building the future. If we don't fix the human layer, the technology layer will collapse under its own weight.

So here's what I'm watching: - Decentralized verification markets: Projects that allow users to attest to their identity without revealing private data. If a hiring platform integrates zk-proofs, it wins. - Browser isolation technology: Startups building sandboxed environments for untrusted apps. If 'Relay' ran in a container, it couldn't steal keys from the host. - Regulatory ripple: This attack may push governments to mandate security standards for remote hiring in crypto. Another layer of compliance, but also another moat for established players.

The sprint to the ETF finish line was about capital. The sprint to the security finish line is about survival. And the clock is ticking.

Stay safe. Use a hardware wallet. Never install an interview app from an unsolicited message. And if a recruiter asks you to 'just trust the process' — run.

Market Prices

Coin Price 24h
BTC Bitcoin
$77,452.6 -3.01%
ETH Ethereum
$2,433.25 -2.75%
SOL Solana
$103.57 -3.57%
BNB BNB Chain
$687.8 -3.59%
XRP XRP Ledger
$1.38 -3.18%
DOGE Dogecoin
$0.0844 -4.34%
ADA Cardano
$0.2002 -4.98%
AVAX Avalanche
$7.28 -2.77%
DOT Polkadot
$0.8384 -4.03%
LINK Chainlink
$11.32 -4.14%

Fear & Greed

68

Greed

Market Sentiment

Event Calendar

{{年份}}
28
03
unlock Arbitrum Token Unlock

92 million ARB released

12
05
halving BCH Halving

Block reward halving event

18
03
unlock Sui Token Unlock

Team and early investor shares released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$77,452.6
1
Ethereum ETH
$2,433.25
1
Solana SOL
$103.57
1
BNB Chain BNB
$687.8
1
XRP Ledger XRP
$1.38
1
Dogecoin DOGE
$0.0844
1
Cardano ADA
$0.2002
1
Avalanche AVAX
$7.28
1
Polkadot DOT
$0.8384
1
Chainlink LINK
$11.32

🐋 Whale Tracker

🟢
0x72ac...f1a1
6h ago
In
3,308,613 USDC
🟢
0x433c...bce5
1h ago
In
3,039 ETH
🔴
0x6db8...700a
1d ago
Out
32,942 BNB

💡 Smart Money

0x8c4e...c1be
Arbitrage Bot
+$4.3M
74%
0xaaac...fb69
Experienced On-chain Trader
+$2.6M
77%
0x45dd...58f0
Institutional Custody
+$0.6M
78%