Gelalens

Market Prices

Coin Price 24h
BTC Bitcoin
$62,594.1 -0.60%
ETH Ethereum
$1,836.25 -1.58%
SOL Solana
$71.45 -2.12%
BNB BNB Chain
$575.4 -2.16%
XRP XRP Ledger
$1.05 -0.76%
DOGE Dogecoin
$0.0685 -1.66%
ADA Cardano
$0.1730 +2.00%
AVAX Avalanche
$6.13 -4.64%
DOT Polkadot
$0.7707 +0.92%
LINK Chainlink
$8.01 -1.87%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{ๅนดไปฝ}}
18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

28
03
unlock Arbitrum Token Unlock

92 million ARB released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All โ†’
1
Bitcoin
BTC
$62,594.1
1
Ethereum
ETH
$1,836.25
1
Solana
SOL
$71.45
1
BNB Chain
BNB
$575.4
1
XRP Ledger
XRP
$1.05
1
Dogecoin
DOGE
$0.0685
1
Cardano
ADA
$0.1730
1
Avalanche
AVAX
$6.13
1
Polkadot
DOT
$0.7707
1
Chainlink
LINK
$8.01

๐Ÿ‹ Whale Tracker

๐Ÿ”ด
0xc9ce...7848
12m ago
Out
2,080,886 USDC
๐ŸŸข
0x2b7e...801b
1d ago
In
1,300,360 USDT
๐ŸŸข
0x7486...d575
3h ago
In
770.19 BTC

๐Ÿ’ก Smart Money

0x5d9b...0a9b
Market Maker
+$3.7M
80%
0x8e86...e465
Early Investor
+$4.8M
77%
0xa9a0...7694
Arbitrage Bot
+$0.4M
70%

๐Ÿงฎ Tools

All โ†’
Cryptopedia

Your Next Interview Is Malware: Inside 'Relay,' the Fake AI Hiring Tool Draining Web3 Wallets

CryptoNode

On July 29, 2025, SlowMist's threat intelligence team published a sample analysis that deserves more attention than a chain of retweets. A live information-stealing campaign is running against the Web3 industry, and the delivery mechanism is one ritual every professional in this sector takes for granted: a job interview.

The lure is called 'Relay.' It presents itself as an AI-powered meeting and interview application. It is actually a custom-built stealer with native builds for macOS and Windows. Its harvest target reads like the asset list of a high-value endpoint: browser credentials, crypto wallet extension data, OS keychain secrets, and Telegram Desktop session files. The attack chain is classic social engineering wrapped in a crypto-native narrative. A recruiter makes contact on LinkedIn or Telegram, builds enough rapport to sound legitimate, then asks you to install 'Relay' so the interview can proceed. You install. You run it. The next time you check your wallet, the balance is already gone.

The race wasn't to build the most efficient AI recruiting agent. It was to build the most convincing one โ€” and to point it at the most credential-rich workforce on the planet.

As of this writing, the campaign is still being monitored as active, with lures observed across multiple jurisdictions and infrastructure still responding. The cross-platform engineering alone tells me this is a team operation with a testing pipeline, not a solitary script-kiddie sneeze. And the timing โ€” squarely inside a bull-market hiring boom, when AI meeting tools are normalized and every inbox is flooded with recruiter cold-outs โ€” is deliberate. Chaos is just data waiting for a pattern. I have spent more than a decade reading these patterns in real time, and I am going to break this one down the way it deserves: not as a panic alert, but as an operational brief.

Context: Why the bull market made this inevitable

Let me set the stage, because the 'why now' matters as much as the 'what.'

The 2025 bull market has changed the velocity of hiring inside crypto. Token prices inflate; then headcount inflates. Projects that spent the bear market in survival mode have re-opened requisitions for engineers, protocol researchers, BD leads, and yes, trading strategists like me. Remote-first hiring is no longer a convenience; it is the default. Founders recruit across time zones, candidates interview from home offices, and every step is mediated by software: scheduling bots, AI note-takers, video platforms, coding assessment suites, and now 'AI interview agents' that promise to streamline the entire funnel.

Attackers do not operate outside narratives. They operate inside them. The narrative that created 'Relay' is the sector's uncritical adoption of AI tooling as a trust signal. Here is the psychological logic: when a recruiter says 'our team uses this AI interview platform,' the candidate's threat model does not just relax โ€” it dissolves. The mention of an AI tool has become an institutional marker. It suggests a company that is modern, well-funded, organized. It also hands the attacker the perfect cover for a request that would otherwise be a red flag: install this software on the same machine where you keep your signing keys.

That is the trust assumption the malware exploits. Not a zero-day. Not a vulnerable smart contract. A social expectation.

The threat-intel community has been waiting for this mutation. The most instructive predecessor was 'Contagious Interview,' a campaign documented earlier that weaponized malicious coding-exercise dependencies to breach Web3 developers. 'Relay' follows the same intelligence logic โ€” target a professional's career ambition to reach their private keys โ€” but upgrades the delivery mechanism from a compromised npm package to a standalone, cross-platform executable with its own installer. This is not a new concept. It is a maturation.

That is exactly why SlowMist's report matters. It collapses the gap between 'theorized attack' and 'demonstrated attack.' A sample has been obtained, dissected, and disclosed. Indicators of compromise have been published. The defense window is open right now. The question is how many people will read the report and act before the next variant is packed and shipped.

Core: Anatomy of the operation

What follows is a technical walkthrough of the attack as documented โ€” plus the inferences I am confident drawing from years of auditing credential-theft infrastructure and monitoring wallet drainers.

The contact phase. The attacker builds a recruiter identity. Given the sophistication of this campaign โ€” the polished dual-platform build, the careful selection of 'Relay' as a name generic enough to be plausible but specific enough to be memorable โ€” I assess with high confidence that the operation maintains a portfolio of fake recruiter profiles. These profiles are likely seeded with realistic employment history, mutual connections, and pre-existing conversation logs. The attack surface begins on LinkedIn and Telegram, the two channels where crypto professionals are most exposed to unsolicited outreach.

The trust-building phase. The recruiter engages the target with a role that mirrors their actual experience. They discuss compensation, team structure, roadmaps, maybe tokenomics. Somewhere in the conversation, they introduce 'Relay' as the interview tool, probably with a pitch about asynchronous AI-assisted interviews or 'secure remote collaboration.' The target is never asked to do something impossible. They are asked to do exactly what they would do in any normal hiring flow: download software and run it.

The delivery phase. The target installs. On macOS, the payload is a signed-appearing binary or installer package; on Windows, a standard executable or MSI chain. This is where the operators show their rigor. Shipping a working macOS build means they tested against Gatekeeper behavior, quarantine flags, and possibly notarization. That level of quality assurance costs money. The presence of both builds indicates a deliberate allocation of resources rather than an opportunistic attack. SlowMist's team has already extracted the sample and mapped its credential-access routines.

The runtime behavior. Once executed, the stealer performs a structured sweep. It enumerates Chromium-based browser profiles and reads the local credential databases. It locates browser extension directories for wallet providers and attempts to extract keystore or mnemonic material. It invokes keychain or credential-manager APIs on both platforms to harvest stored secrets. It copies Telegram Desktop's local session data โ€” the 'tdata' directory โ€” the lifecycle key to your account. Then it packages the exfiltrated data and ships it over an encrypted channel to a command-and-control endpoint.

For anyone with a technical bent, the technique set maps cleanly onto MITRE ATT&CK phases: credential access, collection, and exfiltration. Nothing about this code needs to be exotic to be devastating.

The exfiltration economics. Because the malware is data-complete โ€” credentials, accounts, sessions, keys โ€” the operators can execute a tiered monetization strategy. Browser credentials produce immediate account access: exchange sessions, email recovery, password-manager vaults. Wallet extension data, when combined with keychain access, can be decrypted offline. Telegram sessions produce the most damaging asset of all: a live identity that can issue messages to everyone the victim has ever worked with.

Core: The credential pyramid

Let me be blunt about the escalation path, because most threat reporting focuses on 'asset theft' and misses the compounding effect.

The single most dangerous item in the harvest list is the Telegram Desktop session.

Why? Because crypto communities โ€” and especially project teams โ€” run on Telegram the way traditional companies run on Slack and Outlook. Your Telegram session contains active chats with colleagues, investors, infrastructure developers, listing contacts, market makers, and founders. When an attacker copies that session, they are not merely impersonating you; they are inheriting your position inside the web of trust. Messages from your account appear with your name, your history, your access โ€” and your credibility. One copied session turns you into a distribution node for the next wave of attacks.

Close behind is the browser credential store. It unlocks email, cloud dashboards, exchange accounts, and every web tool you have ever logged into. In modern account-recovery workflows, possession of email is commonly enough to reset passwords. An attacker who controls your email can often take over every account you own that is not protected by a hardware key or genuine out-of-band verification.

The wallet extension data ranks third, and this is where retail media will focus, so allow me to set expectations. Depending on the wallet provider's storage architecture, extension data includes either encrypted mnemonic material or keystore files. Client-side encryption is only as strong as its key-management chain. When the same malware already has keychain or credential-manager access, that protection collapses. The wallet may as well have sent its seed phrase in plaintext.

And then there is the operating system's keychain or credential manager โ€” the substrate that unlocks everything else. macOS keychains store application passwords, VPN credentials, and Wi-Fi secrets; Windows Credential Manager holds similar material. The attacker is stealing the hierarchical key ring of your digital life.

I have audited security postures for trading operations, wallet products, and institutional custody workflows. I will tell you the only correct conclusion: a machine infected with this stealer must be treated as zero-trust-broken forever. Not partially compromised. Not maybe-compromised. Every secret that machine ever touched is assumed burned. The passwords, the sessions, the keys, the cached file histories. The operators hold the data package; remediation means rotating everything and rebuilding the environment from scratch.

Core: Why Web3 professionals are the optimal prey

Every threat actor performs a cost-benefit calculation, and this campaign's calculus is worth spelling out.

The optimal prey profile has four properties: access to valuable keys, habits that involve installing unfamiliar software, a low likelihood of coordinated incident response, and assets that settle fast. Web3 professionals score high on all four.

Key custody concentration comes first. A single trader, engineer, or protocol contributor commonly holds multiple hot wallets, personal account keys, wallet browser extensions, hardware wallets, and possibly access to project multi-sigs. The value of one compromised endpoint can exceed the take from a successful exploit of a mid-size DeFi protocol โ€” without the engineering complexity.

Software-installation habits follow close behind. The modern hiring environment has conditioned professionals to install interview video tools, assessment platforms, coding sandboxes, and now AI-agent meeting apps at a rapid clip. Each install is a potential backdoor. The attacker merely accelerates the cadence.

Then there is reporting asymmetry. A meaningful percentage of individual victims will never report the theft. They are either embarrassed, wary of exposing their self-custody arrangement to law enforcement, or simply unsure where to file a complaint. The lack of reporting keeps the campaign profitable and the code unpatched.

Finally, settlement speed. Crypto assets move 24/7. There is no bank-fraud hold, no withdrawal delay at most exchanges, no overnight check-clearing. Stolen keys convert to liquidity within minutes.

In expected-value terms, a single 'Relay' install is potentially worth hundreds of thousands of dollars in keys, sessions, and reputation capital. The attacker's production cost is a few fake profiles and one polished binary. That is a better return on investment than almost any legitimate security product. And until the industry updates the protocol of hiring, the economics will keep improving for the attacker.

Core: Lineage and mutation

Let me zoom out to the campaign lineage so you can see the trajectory.

The crypto workforce has been targeted through job lures since the early 2020s. Earlier reports documented waves of fake blockchain job offers used to lure developers into downloading malicious coding exercises. Separately, state-linked actors were observed conducting fake-interview operations to breach software supply chains. The pattern was always the same: human ambition as the entry vector, developer tooling as the payload.

What changed in 2025 is the sophistication of the packaging. 'Relay' is not a syntax-soup script left in a zip file. It is a polished, dual-platform, information-stealing application with a plausible consumer-facing identity. It rides the AI narrative at a moment when AI meeting tools are simultaneously new and normalized. It targets a specific professional class rather than a mass audience. This is targeted money, not spray-and-pray.

The next step is already implied. If the first generation used a compromised dependency, and the second generation is a standalone binary, the third generation will be an interactive hybrid: a deepfake interviewer in a video call, a compromised npm package that ships inside a take-home assessment, or a clipboard-hijacking module embedded in a contract-signing dApp. Each mutation costs the attacker a little more. Each mutation also raises the stakes for the industry's collective security posture.

This is why time is the scarcest resource. Every day the security community spends writing technical write-ups of the latest variant is a day the malware can evolve. First in, first served, or first to flee. The industry's choice was made before this article was written.

Core: Defense asymmetry

So what does the defense actually look like?

Endpoint detection has a role. SlowMist has published indicators of compromise, and signature-based detection products will catch this specific sample. That is necessary but not sufficient. The executable can be repacked, re-signed, or re-obfuscated, and the detection window closes quickly. EDR that matches known hashes is playing an endless game of chase.

Hardware wallets reduce the risk of signing-key extraction, but they are not a complete defense. If the attacker controls your browser session, they can intercept a transaction in progress or inject a hostile message in a dApp that requests an approval signature. The operator can display a fake transaction that looks legitimate and have the victim physically approve the drain. Hardware is a circumvention of the architecture, not the end of the threat.

Identity isolation is the only robust defense in an interview scenario. Conduct every interview from a device that has zero wallet stores, no Telegram Desktop session, no saved browser credentials, and no keychain material. That means a separate machine used for exactly this purpose โ€” or, if that is infeasible, a virtual machine with networking disabled before installing any tool that is not independently verified.

Every founder and security lead I have worked with knows this intuitively, but the hiring process tends to be overlooked because it is a people function, not an engineering function. The attack disproves that division. The interview session is now part of the attack surface. It should be treated like a smart-contract external call: untrusted until proven otherwise.

Contrarian: The strategic misread

Now the part most coverage will miss: the strategic misread.

Expect the market reaction to this disclosure to be a scramble for new security products. Expect 'Web3 endpoint security,' 'decentralized recruiter identity,' and 'AI meeting verification' startups to emerge with well-funded decks, each promising to close the gap 'Relay' exposed. Some will be genuinely useful. Many will be solution-shaped vacuums that monetize fear without addressing the underlying protocol flaw.

I am going to borrow a framework from my engineering bias: the flaw is not in the endpoint. It is in the protocol design of the recruitment workflow. In smart-contract terms, the hiring process permits an unverified external caller to invoke a state-changing function on a high-value account, with no reentrancy guard and no post-condition check. You do not fix a design flaw by adding better logs. You fix it by rewriting the transaction.

For hiring, that rewrite means enforced context isolation. It means mandatory out-of-band verification of every recruiter identity โ€” not through the same Telegram channel where the initial contact happened, but through a second, independent channel. It means a standard: you may review my public work, you may speak to my references, but you may never install software on any machine that holds signing authority. It means a hiring protocol where the interview environment is ephemeral, burned after each session, and entirely disconnected from the candidate's credential baseline.

That is the contrarian read: more security tools will not fix the trust collapse. The real lesson is that Web3 companies should treat candidate security as seriously as they treat protocol security. Because a fake 'Relay' install on a future protocol contributor's machine is a backdoor into the project's long-term infrastructure, timed to the most optimistic phase of the market cycle.

Let me also underscore the dimension the headlines will miss: the secondary graph attack. The narrative will be 'malware steals your crypto.' The actual intelligence value is in the session data. An attacker with your Telegram session inherits your entire network context. They know, from your chat history, which of your contacts are also high-value targets. They know the language you use with each person, the tone, the shorthand. For a moderately sophisticated operator, this is not a wallet theft. It is a mining operation: one infected professional becomes a trusted gateway into other professionals.

Trust is a variable, not a constant. 'Relay' just redefined its default value.

The collapse wasn't the wallet drain. The collapse is the trust collision โ€” and it compounds with interest.

Takeaway: What to do before the next variant

The next variant is already being written. It will arrive wrapped in a deepfake interviewer, a compromised assessment dependency, or a malicious 'secure signing' dApp. The names will change; the economics will not. Attackers will keep targeting the gap between institutional trust and personal verification, because crypto's hiring pipeline remains one of the most valuable, least guarded surfaces in the industry.

Do not wait for the detection tool. Build the isolation layer. Every candidate, every hired contributor, every founder with a hot wallet on their main laptop should treat an interview as a zero-trust boundary. Use a separate interview machine. Verify identities through an independent channel. Adopt one hard rule: nobody installs anything on a computer that holds signing power.

Watch the signals, too. Monitor SlowMist, Unit 42, and the broader threat-intel circuit for new samples โ€” a fresh build reported in the coming weeks means the operation is iterating. Watch whether LinkedIn and Telegram crack down on fake recruiter identities; their response speed will determine how wide the next wave spreads. And trace the stolen funds: if the campaign's crypto addresses start moving to major exchanges, expect a coordinated freeze-and-forensic cycle that reveals more about the operators.

The pattern in this chaos is clear. The industry can either treat hiring as a verifiable protocol โ€” one where 'let's talk' never implies 'hand over your session keys' โ€” or it can keep paying the interest on the trust loan it took out years ago. Sustainability is just a loan from the future. The question is whether the future will still trust the borrower.