KawaChain
BTC $78,204.5 +0.66%
ETH $2,461.21 +0.97%
SOL $105.18 +1.57%
BNB $693.8 +0.68%
XRP $1.39 +0.48%
DOGE $0.0850 +0.57%
ADA $0.2017 +0.80%
AVAX $7.38 +1.67%
DOT $0.8521 +1.28%
LINK $11.4 +0.60%
⛽ ETH Gas 28 Gwei
Fear&Greed
69

The Interview That Drains You: SlowMist Uncovers a Cross-Platform Malware Targeting Web3 Professionals

SatoshiShark
Culture

Trust is the most fragile asset in crypto, and it is being mined by attackers who understand narrative better than code. On July 29, 2025, SlowMist published an analysis of a new information-stealing malware disguised as an AI-driven interview tool called “Relay.” The attackers pose as recruiters on platforms like LinkedIn, target Web3 professionals, and install a cross-platform trojan that harvests browser credentials, crypto wallet data, macOS Keychain secrets, and Telegram session tokens. Code is law, but narrative is truth — and here, the narrative of opportunity becomes the vector of compromise.

I recall the early days of 2021, when I audited a similar social engineering campaign aimed at DeFi developers. Back then, the lure was a fake GitHub contribution opportunity. Today, the attackers have evolved, weaponizing the very tools that promised to democratize hiring. This is not a random exploit; it is a surgical strike on the trust fabric of our industry.

Context: The Fragile Web3 Hiring Ecosystem

The Web3 job market has always operated on a blend of pseudonymity and reputation. Discord DMs, LinkedIn InMails, and Telegram groups serve as the primary channels for connecting talent with projects. The assumption has been that genuine recruiters are identifiable through their network and public history. But as the space matures, so do the adversaries. In 2023, we saw phishing kits targeting job applicants on freelance platforms. In 2024, fake project teams used deepfake audio to impersonate founders. Now, in 2025, the attackers have built a custom malware that runs on both macOS and Windows, specifically designed to extract the digital keys to a professional’s entire crypto life.

SlowMist’s report details how the malicious “Relay” application claims to be an AI meeting scheduler. The victim is told to download and run the installer before an interview. Once executed, the malware silently exfiltrates credentials from browsers (Chrome, Brave, Firefox), extracts private keys from wallet extensions (MetaMask, Phantom, Rabby), reads the macOS Keychain for tokens and passwords, and steals Telegram session data — allowing the attacker to hijack ongoing conversations. Based on my audit experience, this level of integration suggests the malware was not coded overnight. It likely underwent several iterations, tested against common endpoint detection systems.

Core: The Narrative Trap and the Technical Mechanics

Let me break down the attack chain from a technical lens, because understanding the mechanism is the first step to surviving it.

The attack begins with social engineering — the weakest link in any security model. The recruiter account often has a legitimate-looking history: profile picture, connections, even past postings. The narrative used is “AI-enhanced interview experience,” which resonates deeply in a culture obsessed with automation and efficiency. The victim, eager for a role, clicks a link that leads to a download page. Here, the code-first skepticism I have developed over years of auditing smart contracts kicks in: never run signed code from an untrusted source.

The malware sample examined by SlowMith is a signed .dmg on macOS and a .exe on Windows, but the signature is self-signed or spoofed. It uses standard techniques to evade detection: obfuscation of strings, dynamic API resolution, and a delay before executing payload to bypass sandbox analysis. The core payload is a multi-threaded stealer that enumerates file systems for wallet directories, reads browser SQLite databases for saved passwords and cookies, and dumps Telegram tdata folders. The macOS variant uses a launch agent for persistence; the Windows variant uses registry run keys. Liquidity flows, but trust evaporates — and here, the liquidity is your private keys flowing out to a remote server.

What makes this attack particularly insidious is the dual-platform coverage. Many Web3 professionals use macOS for its Unix heritage and perceived security. The assumption is that Macs are less targeted. This exploit disproves that. The malware is compiled natively for Apple Silicon and Intel, indicating the attackers had access to both architectures during testing. The theft of Telegram sessions is especially dangerous: once an attacker controls your Telegram, they can impersonate you in group chats, send phishing messages to your contacts, and even reset two-factor authentication if tied to the phone number.

Sentiment analysis of the current market shows a spike in fear, uncertainty, and doubt (FUD) around job-related communications. Twitter threads are circulating warnings, and security-focused accounts are seeing engagement rates 300% above average. This is a narrative accelerator: the story of “AI interview tool = malware” will stick in the collective consciousness for at least the next quarter. For the security ecosystem, this is a demand catalyst. For the average job seeker, it is a call to fundamentally change behavior.

Don’t trade the chart; trade the story. The story here is that trust in remote hiring is being weaponized. Until now, the market narrative around Web3 jobs was bullish — talent inflow, new projects, geographical freedom. This attack introduces a risk premium on that narrative. The cost of a single stolen wallet can exceed a year’s salary. The expected value of applying for a job must now account for potential loss. This could subtly reduce the willingness of top talent to engage in cold applications, favoring those with established networks.

Contrarian Angle: The Real Blind Spot Is Not the Malware

Here is the counter-intuitive insight that most analysts miss: the malware is a symptom, not the root cause. The true structural moral hazard in this attack lies in the web3 industry’s reliance on unverifiable identity systems. We talk about decentralized identity (DID) and verifiable credentials, but in practice, hiring still relies on the same Web2 authentication — LinkedIn profiles, email addresses, and Telegram handles. These are trivially spoofed. The contrarian angle is that the most effective defense is not a better antivirus, but a radical redesign of how we verify professional identity.

Imagine a world where instead of sending a .dmg file, a recruiter issues a one-time use, time-bound credential verified by a smart contract that attests to their affiliation with a project’s multisig. The interview itself runs inside a sandboxed browser instance that has no write access to the host file system. This is not science fiction; it is a logical extension of the zero-trust principle. However, the industry is slow to adopt because convenience currently outweighs security. The contrarian bet is that this attack will accelerate the adoption of such systems, creating a new niche for security-focused identity solutions.

Another blind spot is the assumption that individuals are the only targets. Enterprises that have Web3 divisions are equally vulnerable. A compromised employee’s Telegram session could lead to the leakage of internal governance proposals, private GitHub repositories, or even multisig signing procedures. The ripple effect is far larger than a single wallet drain. Liquity flows, but trust evaporates — and when trust evaporates across an organization, the cost is measured in reputational damage and lost partnership opportunities.

Takeaway: Survival Matters More Than Gains

In a bear market — and we are technically in a prolonged correction despite the occasional relief rallies — survival matters more than gains. The primary concern for every Web3 professional should be the safety of their assets and identities. My advice is to use hardware wallets even for small balances, treat every unsolicited interview request with suspicion, and run all job-related downloads inside a virtual machine or separate device. Verify the recruiter through at least two out-of-band channels — a phone call or a video meeting with established team members.

SlowMist’s disclosure is a gift. The technical indicators of compromise (IOCs) — hashes, domains, URLs — have been published. Check your system logs, reinstall your wallet extensions, and rotate your Telegram tokens. The next mutation of this attack will likely include deepfake video interviews where the recruiter’s face and voice are synthesized. The narrative of “AI interview tool” will become even harder to resist. Code is law, but narrative is truth. The narrative now is that trust is the most expensive thing we trade. Protect it like you protect your seed phrase.

Market Prices

BTC Bitcoin
$78,204.5 +0.66%
ETH Ethereum
$2,461.21 +0.97%
SOL Solana
$105.18 +1.57%
BNB BNB Chain
$693.8 +0.68%
XRP XRP Ledger
$1.39 +0.48%
DOGE Dogecoin
$0.0850 +0.57%
ADA Cardano
$0.2017 +0.80%
AVAX Avalanche
$7.38 +1.67%
DOT Polkadot
$0.8521 +1.28%
LINK Chainlink
$11.4 +0.60%

Fear & Greed

69

Greed

Market Sentiment

Event Calendar

{{年份}}
30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

18
03
unlock Sui Token Unlock

Team and early investor shares released

7x24h Flash News

More >
{{快讯列表(10)}} {{loop}}
{{快讯时间}}

{{快讯内容}}

{{快讯标签}}
{{/loop}} {{/快讯列表}}

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$78,204.5
1
Ethereum
ETH
$2,461.21
1
Solana
SOL
$105.18
1
BNB Chain
BNB
$693.8
1
XRP Ledger
XRP
$1.39
1
Dogecoin
DOGE
$0.0850
1
Cardano
ADA
$0.2017
1
Avalanche
AVAX
$7.38
1
Polkadot
DOT
$0.8521
1
Chainlink
LINK
$11.4

🐋 Whale Tracker

🔵
0x918e...75d7
30m ago
Stake
3,214 ETH
🔴
0x7e88...ce57
12m ago
Out
3,411.70 BTC
🟢
0x3bb2...4f27
1h ago
In
8,308,074 DOGE

💡 Smart Money

0xd405...0a55
Early Investor
+$5.0M
80%
0xf979...92a1
Early Investor
+$4.7M
93%
0xadd1...8aa1
Early Investor
+$1.7M
83%