The Fake AI Interviewer That Steals Your Wallet: A New Social Engineering Playbook
AlexWolf
Over the past 72 hours, a new breed of malware has been circulating under the guise of an AI meeting tool named 'Relay'. This is not another generic phishing campaign. It is a precision strike against the Web3 workforce. SlowMist’s disclosure reveals a fully weaponized social engineering chain: attackers pose as recruiters, send a custom ‘AI interview software’, and on installation, silently exfiltrate browser credentials, crypto wallet data, macOS keychain contents, and Telegram sessions. The target isn’t the protocol—it’s the person behind the private key.
Context matters. We are in a bear market. Survival instincts drive talent to hunt for roles at surviving or emerging projects. That desperation becomes the attack surface. The attackers understand this. They exploit the narrative of ‘AI job tools’—a trusted, even hyped, category in 2025. The ‘Relay’ malware is not a script kiddie effort. It is cross-platform (macOS and Windows), stealthy, and data-hungry. SlowMist’s sample analysis confirms the malicious binary collects enough information to drain a hot wallet, hijack a Telegram account, and pivot into the victim’s professional network. This is an incentive-aligned attack: the effort is high, but the payout—direct access to Web3 professionals’ keys and sessions—justifies the cost.
Core insight: the attack deconstructs the traditional trust model of recruitment. In Web3, identity and reputation are often linked to Discord handles, Telegram IDs, and public wallet addresses. A recruiter’s credibility is rarely verified beyond a LinkedIn profile. The ‘Relay’ malware targets this gap. It doesn’t need to break a blockchain’s cryptography. It bypasses the entire security stack by hijacking the human layer. SlowMist’s forensic breakdown shows the malware captures browser-stored passwords, private keys from wallet extensions like MetaMask and Phantom, and even the local keychain that holds SSH keys and API tokens. The Telegram session theft is particularly insidious—it allows attackers to impersonate the victim in group chats, sending malicious links to colleagues or community members. This is a contagion vector.
Based on my forensic analysis of incentive structures in Web3 hiring, this attack reveals a critical blind spot. Most security discourse focuses on smart contract audits, MEV protection, and rug pulls. But the most vulnerable asset is the developer’s own machine. In a bear market, developers are more likely to accept job interviews from unknown sources. They are also more likely to use hot wallets for gas fees and testnets. The ‘Relay’ attack exploits this precisely. The attackers didn’t need to find a 0-day in Solana or Ethereum. They weaponized a job application.
Contrarian angle: the market will likely treat this as a one-off phishing alert. But that misses the structural shift. This attack represents the institutionalization of targeted social engineering in crypto. We saw similar patterns in 2022 with the fake job offers that led to the Axie Infinity Ronin bridge breach. Now the vector is being democratized. The ‘Relay’ malware is likely a build-tool for repeat use. Expect variants that use deepfake audio to simulate a recruiter’s voice, or fake video calls to capture facial recognition data. The narrative here is not about ‘another hack’—it is about the weaponization of the bear market’s most emotional trigger: the search for income.
The contrarian truth: this attack is actually bullish for the security sub-sector. Hardware wallets, air-gapped signing devices, and endpoint detection tools will see demand spikes. But the more profound implication is for hiring practices. Web3 companies will need to adopt verifiable credentials—perhaps using zero-knowledge proofs to confirm a recruiter’s affiliation without leaking personal data. Or they may require all interview software to run inside sandboxed virtual machines. The cost of not doing so is the next big exploit.
Takeaway: the ‘Relay’ malware is a canary in the coal mine of bear market security. Do not run unverified applications. Verify recruiters through a second channel—check their company email domain, ask for a public tweet from the company account, or use a video call without installing any software. Use a hardware wallet for any significant holdings. Isolate your interview environment: a separate laptop, a fresh VM, or even a bootable Linux USB. The next variant will be better. The narrative of ‘secure recruitment’ is about to become a dedicated vertical in Web3 security.
— James Davis
— Narrative Hunter
— Forensic Incentive Deconstructor