Your next job interview could empty your crypto wallet. No cap.
A new breed of social engineering just hit the Web3 talent pool, and it’s nasty. Attackers are posing as recruiters, pitching a fake AI meeting tool called “Relay” to unsuspecting developers, analysts, and ops folks. One download, and your secrets are gone. SlowMist just published the full breakdown, and I’ve been digging through the sample since it dropped. Speed is the only currency that matters here, and you need this intel before your next Zoom call.
Let’s rewind. The context is ugly but simple: the bull market brought a flood of remote hiring across crypto. Everyone’s hungry for talent, but scammers are hungrier. They’ve weaponized the “AI interview” narrative—a hot trend in 2025—to lower your guard. The lure? A job offer from a “top DeFi protocol” with a custom link to download Relay for video screening. Classic spear-phishing, but with a modern twist.
The malware is cross-platform—macOS and Windows—which tells me the attackers either have a solid dev team or bought a kit off the dark web. Once installed, Relay goes to work: it scrapes browser credentials, crypto wallet data, macOS Keychain, and even Telegram session tokens. That last one is brutal. Telegram is where teams coordinate, share alpha, and store private keys in pinned messages. If they grab your session, they can impersonate you to your colleagues and start a secondary attack chain. SlowMist confirmed the malicious binary contains obfuscation and anti-debugging tricks. Based on my experience tracking similar malware during the DeFi Summer chaos, this is professional-grade stuff.
Here’s the core insight—and I’m bolding this because it’s critical: The attack targets the very tool Web3 professionals trust most: recruitment channels. LinkedIn, Twitter DMs, even Discord. The attackers likely built fake profiles weeks in advance, networking with real people to seem legit. I’ve seen this playbook before—back in 2017, I audited ICOs for a living, and scammers would clone team bios to trick investors. But this time, the payload is a full information-stealer, not just a phishing page. The data exfiltration is real-time, and the loss can be catastrophic.
Now for the contrarian angle—the part most analysts are missing. Everyone’s screaming “panic” and “check your wallet.” But here’s what nobody’s saying: This attack is actually a bullish signal for crypto security infrastructure. Every major hack or scam creates a demand spike for defensive solutions. Cold wallet vendors like Ledger and Trezor will see a bump in sales. Security audit firms like SlowMist, Trail of Bits, and OpenZeppelin will get more corporate contracts. Endpoint detection tools (CrowdStrike, etc.) will be marketed harder to Web3 companies. I’m already hearing whispers of startups building “secure interview environments” – isolated VMs or browser sandboxes for remote hiring. In the jungle of alerts, silence is gold. But right now, the noise is a feature, not a bug. If you’re running a security protocol or a hardware wallet company, this is your moment to capture mindshare.
Let me drop another contrarian take: this scam might actually accelerate the adoption of decentralized identity (DID) and zero-knowledge proof solutions for hiring. Imagine a future where you verify a recruiter’s on-chain reputation before clicking any link. That’s not a fairy tale—it’s a logical next step. We rode the wave of DeFi summer, and now we read the tide. The tide here is pointing toward trust-minimized recruitment.
So what’s the takeaway? Three actions, right now. First, if you’re job hunting or receiving unsolicited invites, treat every link like a potential trap. Verify the recruiter’s identity through multiple channels. Second, use hardware wallets for your main funds and never connect them to a machine that runs unverified software. Third, enable 2FA on everything, especially Telegram, and rotate your session keys if you’ve downloaded anything suspicious recently. SlowMist will update the IOC list—I recommend following their GitHub.
Chasing the green candle that never sleeps means staying sharp when the market lulls. This is the kind of story that doesn’t move prices—until it does. The real impact isn’t in a token chart; it’s in the confidence of the workforce. If Web3 can’t hire without fear, the whole ecosystem slows down.

The sprint ends, but the ledger remains open. What will you do with this alpha?