Gelalens

Market Prices

Coin Price 24h
BTC Bitcoin
$62,768.9 -0.49%
ETH Ethereum
$1,860.47 -0.78%
SOL Solana
$71.76 -2.26%
BNB BNB Chain
$576.9 -2.10%
XRP XRP Ledger
$1.06 -1.20%
DOGE Dogecoin
$0.0696 -0.44%
ADA Cardano
$0.1733 +1.70%
AVAX Avalanche
$6.31 -2.14%
DOT Polkadot
$0.7745 +0.98%
LINK Chainlink
$8.05 -1.70%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{年份}}
10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

18
03
unlock Sui Token Unlock

Team and early investor shares released

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$62,768.9
1
Ethereum
ETH
$1,860.47
1
Solana
SOL
$71.76
1
BNB Chain
BNB
$576.9
1
XRP Ledger
XRP
$1.06
1
Dogecoin
DOGE
$0.0696
1
Cardano
ADA
$0.1733
1
Avalanche
AVAX
$6.31
1
Polkadot
DOT
$0.7745
1
Chainlink
LINK
$8.05

🐋 Whale Tracker

🟢
0x982b...28de
2m ago
In
3,413 ETH
🔵
0x9855...759e
1d ago
Stake
32,454 BNB
🔵
0x25d6...ab42
3h ago
Stake
9,895,195 DOGE

💡 Smart Money

0x4db3...9c15
Experienced On-chain Trader
+$4.6M
81%
0x9952...2ddb
Early Investor
+$3.1M
72%
0x3836...2fbc
Experienced On-chain Trader
+$1.9M
63%

🧮 Tools

All →
NFT

The Relay Trap: Fake AI Interview Software Drains Web3 Wallets

CryptoAlpha

New exploit targeting Web3 professionals. Attackers pose as recruiters. Victim installs 'Relay' AI meeting software. Real malware. SlowMist confirms. Wallet data stolen. Browser credentials exfiltrated. Telegram sessions hijacked. Audit passed. Trust failed.

Beacon chain stable. Fragility remains.

The timing isn't random. Bull market 2025. Hiring spree across crypto firms. Scammers know the pattern. LinkedIn flooded with fake profiles. Recruiters offer remote gigs. The bait? An AI-powered interview tool. The hook? Relay. The catch? It's a cross-platform info-stealer.

Context: every hiring manager is desperate for talent. Speed trumps verification. That's the opening. Attackers spent time studying Web3 workflows. They know we run hot wallets, store private keys in keychains, keep Telegram open for deal flow. They built for that.

Core: Technical dissection.

SlowMist's sample analysis reveals a mature payload. Two builds: macOS .dmg, Windows .exe. Both signed with stolen or self-signed certs — the code isn't the vulnerability, the trust is. The installer runs a fake meeting UI. Meanwhile, backdoors execute:

  • Browser credential theft: Chrome, Firefox, Brave. Saved passwords, autofill data, session cookies.
  • Crypto wallet extraction: MetaMask, Phantom, Keplar — any extension or desktop wallet with stored keys.
  • Keychain dump (macOS): iCloud, SSH keys, app-specific passwords.
  • Telegram session cloning: .tdesktop folder, tdata directory. Full access to chats without MFA.

Based on my audit experience during the Ethereum 2.0 Beacon Chain slashing conditions, I recognize this pattern. Attackers don't break cryptography. They break human behavior. The Relay malware is no exception. It doesn't exploit a zero-day. It exploits the one thing we rush: speed into a recruiter's link.

Data flow:

Victim downloads → installs → fake UI runs → malware persists → data exfiltration to C2 (SlowMist mapped IPs) → attackers sell credentials or drain wallets.

Cross-platform capability means no safe OS. Windows users lose hot wallets. macOS users lose keychain and Telegram sessions. The attack surface is complete.

Contrarian angle: The irony of AI trust.

We're in a bull market. Everyone is building AI agents for trading, analysis, hiring. The narrative: AI will make crypto faster, smarter, safer. This attack turns that narrative on its head. The promise of AI-streamlined hiring is the vector. The attacker didn't need to hack a smart contract. They didn't need to exploit a bridge. They used the industry's own hype against it.

SlowMist's disclosure is critical. But here's the unreported angle: the real damage isn't the stolen wallets. It's the stolen Telegram sessions. With Telegram access, attackers can impersonate the victim within their company, project groups, deal channels. They can send malicious links to other team members — a second-order attack that spreads faster than the first. The initial victim might never know until coworkers report suspicious messages.

During DeFi Summer, I created a yield optimization model to calculate true APY after gas. I saw how incentives mask reality. This attack does the same: the incentive of a remote job masks the cost of trust. No one checks the hash of the installer before clicking. No one scans the code. They just want the interview.

Takeaway: The next wave of defense.

Expect more of these. The playbook is written. Copycats will modify the payload, rebrand the tool, target different roles (community managers, developers, researchers). What's the fix?

  • Hardware wallets only for signing. Never store private keys on devices used for communication.
  • Dedicated machines for interviews. Use VMs or sandboxes. Treat every recruiter as hostile until proven otherwise.
  • SlowMist's IOC list should be deployed by every crypto company's security team.

But the deeper problem remains. Web3 hiring lacks a trust framework. We have exchange reserve proofs, on-chain audits, but no standard for verifying a recruiter's identity. Until we build that, every remote job offer is a potential exploit.

Question for founders: how much talent will you lose because your hiring process is indistinguishable from a scam?