Gelalens

Market Prices

Coin Price 24h
BTC Bitcoin
$62,768.9 -0.49%
ETH Ethereum
$1,860.47 -0.78%
SOL Solana
$71.76 -2.26%
BNB BNB Chain
$576.9 -2.10%
XRP XRP Ledger
$1.06 -1.20%
DOGE Dogecoin
$0.0696 -0.44%
ADA Cardano
$0.1733 +1.70%
AVAX Avalanche
$6.31 -2.14%
DOT Polkadot
$0.7745 +0.98%
LINK Chainlink
$8.05 -1.70%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{年份}}
28
03
unlock Arbitrum Token Unlock

92 million ARB released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

18
03
unlock Sui Token Unlock

Team and early investor shares released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$62,768.9
1
Ethereum
ETH
$1,860.47
1
Solana
SOL
$71.76
1
BNB Chain
BNB
$576.9
1
XRP Ledger
XRP
$1.06
1
Dogecoin
DOGE
$0.0696
1
Cardano
ADA
$0.1733
1
Avalanche
AVAX
$6.31
1
Polkadot
DOT
$0.7745
1
Chainlink
LINK
$8.05

🐋 Whale Tracker

🔵
0x8a00...5c87
3h ago
Stake
17,194 BNB
🔴
0x0d1e...bcdb
12m ago
Out
5,687 BNB
🔵
0x30e9...15ee
1d ago
Stake
13,951 SOL

💡 Smart Money

0x2dfb...fadf
Experienced On-chain Trader
+$0.6M
85%
0x0306...0e7b
Market Maker
+$1.0M
89%
0xac3d...467a
Experienced On-chain Trader
+$0.1M
79%

🧮 Tools

All →
Exchanges

The Recruiter’s Trap: How a Fake AI Meeting Tool Is Draining Web3 Wallets

LarkPanda
On July 29, 2025, SlowMist published a forensic analysis that sent a chill through the Web3 hiring circuit. A new infostealer, packaged as an AI meeting software named ‘Relay,’ had been silently draining wallets of senior developers and traders. The delivery method? A fake job interview. This isn’t a phishing link in a Discord DM. It’s a fully compiled cross-platform Trojan—targeting both macOS and Windows—that siphons browser credentials, crypto wallet extensions, keychain secrets, and Telegram session files. The attackers didn’t need to break a hash; they broke the victim’s trust by wearing the mask of opportunity. Context: The crypto industry runs on trust—trust in code, in smart contracts, in the promise of decentralized work. But the human layer remains the weakest link. Recruitment scams are not new. In 2017, I audited 45 ERC-20 whitepapers and identified three with fraudulent proof-of-concept claims; back then, the scam was promising a token that never materialized. Today, the scam is promising a job that steals your keys. The attackers studied their marks: they knew Web3 professionals live on Telegram, keep hot wallets for rapid trading, and are constantly scanning LinkedIn for the next role. By weaponizing the ‘AI interview’ narrative—a currently hyped tech trend—they turned a signal of legitimacy into a vector of compromise. SlowMist’s report confirms that the malware has already claimed multiple victims across Ethereum and Solana ecosystems. Tracing the code back to its genesis block: the ‘Relay’ binary is delivered as a fake Electron app, signed with an ad-hoc certificate to bypass basic Gatekeeper checks on macOS. On execution, it harvests browser-stored passwords, wallet extension seeds (MetaMask, Phantom, Coinbase Wallet), macOS keychain items, and Telegram session data files (tdata). The exfiltration is over HTTPS to a VPS host. The social engineering layer is the true masterpiece: attackers crafted realistic LinkedIn profiles with credible work histories, engaged in technical pre-interview chit-chat, and sent calendar invites with a link to download ‘Relay’ for a live coding interview. Once installed, the app requests screen-recording and microphone permissions—ostensibly for the interview—but also silently copies the entire wallet directory. Follow the smart contract, ignore the whitepaper: the real vulnerability is not the code but the human narrative it hijacks. SlowMist’s analysis revealed that the malware uses static string encryption and no packer, making it detectable if you look—but who runs a virus scan before a promising job interview? Here is the contrarian angle: the solution is not better antivirus. It’s systemic cynicism. The industry romanticizes ‘trustless systems,’ yet we still trust a LinkedIn connection. The blind spot is that we’ve outsourced identity verification to platforms that profit from fake profiles. Composability is a double-edged sword: the same efficiency that powers remote hiring also powers remote robbery. This attack reveals a deeper truth—the threat model is not just technical but behavioral. The average Web3 native has 3-4 hot wallets, each with hundreds or thousands of dollars in liquid assets. One malicious npm package or one fake job offer can wipe them out. The mitigation is not a tool; it’s a process. Every unsolicited recruitment outreach should be treated as a zero-trust handshake. Use a dedicated virtual machine for any interview-related app. Only transact from hardware wallets. And if the role seems too perfect, it’s probably a trap. The attackers are betting that ambition overrides caution. Where liquidity flows, truth eventually pools. Expect this vector to spawn imitators, using deepfake audio and video to mimic real recruiters. The next phase will involve on-chain proof of HR identity—verifiable credentials signed by a project’s multisig. Until then, assume every job offer contains a backdoor. The market will price this risk into the cost of hiring and the premium on security tools. The question is not if you’ll be targeted, but when. And that window is closing.