Another day, another social engineering attack. This time it’s “AI meeting software” targeting Web3 professionals. I’ve reviewed the SlowMist report. The pattern is familiar. Pain is just tuition; I paid in full so you don’t have to.
Context
Let’s strip the fluff. Attackers pose as recruiters from legitimate Web3 firms. They invite you to install “Relay” – a fake AI meeting tool. Once installed, it’s not a tool. It’s a cross‑platform information stealer. macOS. Windows. Both. It grabs browser credentials, crypto wallet data, keychain contents, Telegram sessions. Everything a professional trader or developer uses daily. SlowMist already analyzed the samples and published IoCs. The attack chain is complete.
This isn’t amateur hour. The malware is custom. It avoids common detection. It targets exactly the people who hold large balances and private keys. The social engineering is sophisticated: they use LinkedIn profiles, cloned company emails, urgency. “Please install before the interview.” Classic pressure play.
Core
From my audit experience, this attack signals a shift. Past phishing tried to steal seed phrases via fake websites. This one goes deeper – it owns your machine. The Telegram session theft is the silent killer. Once they have that, they can social‑engineer your entire contact list. Fund managers, project leads, exchange OTC desks. The damage cascades.
I tracked the code logic. The malware checks for common browser extensions: MetaMask, Phantom, Keplr. It dumps their local storage. It also reads macOS Keychain where many users store API keys for trading bots. That’s the real alpha. They’re not after your 0.1 ETH wallet. They want the power user’s infrastructure.
We don’t get paid for being right; we get paid for being profitable. Right now, being profitable means securing your environment. Treat every unsolicited job offer as hostile. Use a dedicated machine for your crypto operations – no email, no social media, no video calls. If you must interview, spin up a live Linux USB. Log out of all sessions first.
Contrarian
The retail narrative says “just be careful.” That’s weak. The real blind spot is trust in digital identity. Attackers now clone entire hiring pipelines. They know the Web3 culture of remote work and open applications. They exploit that openness. The contrarian view: this is not a one‑off incident. It’s a template. Expect copycats within weeks. The smart money is already moving to hardware wallets and isolated environments. The rest will learn the hard way.
I didn’t write this to be popular; I wrote it because it’s true. Most will ignore this until they lose funds. Then they’ll pay the tuition – but the market won’t refund you.
Takeaway
Actionable: treat any job interview requiring software installation as a red flag. Verify the recruiter through a known network. Use a separate machine with zero crypto credentials. Check the SlowMist IoCs. Update your antivirus. Change Telegram session tokens. The next variant might use deepfake video. Stay ahead. Pain is just tuition; I paid in full so you don’t have to.