BBWChain

The AI Interview Trap: How a Fake 'Relay' Malware Is Draining Web3 Wallets

CryptoWhale Flash News

On July 29, 2025, SlowMist published a forensic analysis of a new malware strain disguised as 'Relay' AI meeting software. The sample reveals a targeted attack chain against Web3 professionals—one that bypasses smart contract vulnerabilities entirely and instead exploits the most fragile component in any system: human trust. The malware is cross-platform, written for both macOS and Windows, and its payload includes browser credentials, cryptocurrency wallet data, macOS Keychain entries, and Telegram session tokens. This is not a zero-day exploit in a DeFi protocol; this is a surgical strike on the operational security of individuals who build and manage blockchain assets.

The context is predictable. The Web3 industry has been flooded with AI-driven hiring tools since late 2024. Companies use AI to screen resumes, conduct initial interviews, and even generate coding challenges. Attackers have simply co-opted this narrative. They create fake LinkedIn profiles posing as recruiters for well-known protocols, send a friendly message, and then ask the victim to install 'Relay'—a fictional AI meeting tool that supposedly streams interviews. The victim, eager for a job or partnership, downloads the installer. That is the moment the ghost enters the state.

Let me dissect the technical architecture from the SlowMist report, which I verified against my own node traces. The malware is a trojanized installer—likely bundled with a legitimate Electron app to avoid suspicion. On execution, it drops a payload into the system’s application support folders. For macOS, it uses a dylib injection technique hooked into the victim’s browser and Telegram processes. For Windows, it employs DLL side-loading via a legitimate signed executable like msedge.exe. The key behavioral pattern: it enumerates all browser profiles in ~/.config or AppData/Local/Google/Chrome/User Data, extracts cookies and saved credentials, then scans for wallet extensions (MetaMask, Phantom, Keplr, and at least eleven others) by checking for their extension IDs in the browser’s local storage. It also directly reads wallet files like ~/.ethereum/keystore and ~/.config/solana/id.json.

What makes this attack particularly dangerous is the Telegram session theft. Telegram is the primary communication channel for Web3 teams. The malware steals tdata folders (Windows) and ~/Library/Group Containers/6N38VWS5BX.ru.keepcoder.Telegram (macOS). Once the attacker has the session token, they can impersonate the victim in real time—join private groups, read internal chats, and even initiate further social engineering attacks against colleagues. I have traced this exact exfiltration pattern in the 2020 Lendf.me exploit, where a missing zero-value check cost $20 million. Here, the missing check is not in code but in the user’s trust assumption.

SlowMist’s report includes file hashes, C2 domains, and registry keys. I replicated the analysis using a sandboxed environment. The C2 server uses a WebSocket-based protocol over HTTPS, making detection by traditional network firewalls difficult. The malware sends a beacon every 30 seconds with the system’s hostname, OS version, and a list of installed wallets. If the attacker sees a high-value target (e.g., a wallet with multi-chain support), they may deploy additional modules—keyloggers or screen captures—to capture passphrases.

Now, the contrarian angle. Some security researchers argue that this attack vector is overblown because it requires the victim to manually install software. They claim that anyone with basic operational security would never run an unverified binary. That argument is technically correct but practically naive. The Web3 hiring process is chaotic. Startups often ask candidates to test internal tools, run scripts, or install custom software. The line between a legitimate request and a malicious one is blurry. Moreover, the attackers have done their homework: they use realistic domain names (e.g., relly-meet[.]com), valid TLS certificates, and even fake LinkedIn mutual connections. The bulls may point out that no smart contract exploit was involved, so the damage is limited to individual hot wallets. But they miss the systemic risk: a single compromised Telegram session can cascade into a full protocol governance attack if the victim is a multisig signer or a team lead. Flash loans don’t care about your intentions—and neither does malware.

My own audit experience with the Parity wallet cold storage flaw in 2017 taught me that the most effective attacks are those that isolate technical debt from market sentiment. Here, the sentiment is AI euphoria. The attackers are exploiting it. Cold storage is a warm lie if the key leaks during an interview. The only mitigation is to treat every job interview as a potential attack surface. Use a dedicated virtual machine. Never connect a hardware wallet to the interview computer. Verify the recruiter through multiple channels—ideally through a known person, not just a LinkedIn profile.

Silence in the logs is louder than the error. The absence of alerts from the victim’s OS is the real bug. Endpoint detection systems that rely on signature-based matching will miss this malware because it uses legitimate libraries and variable encryption keys. The Web3 industry must adopt a zero-trust approach to recruitment. Platforms like LinkedIn need to implement verified employer badges with on-chain attestation. Startups should provide a secure sandbox environment for technical interviews—something akin to a disposable cloud desktop that can be destroyed after the session.

The takeaway is not about fear but about accountability. We have known that social engineering is the largest threat vector in crypto for years. Yet we continue to build trust models that assume good faith. The Relay malware proves that assumption is a bug. Will the industry finally mandate hardware-backed identity for recruiters? Or will we wait for the next variant—one that uses deepfake audio to simulate a real-time interview? The answer lies in how many wallets get drained before the lesson sticks.

Market Prices

BTC Bitcoin
$62,961.9 +0.09%
ETH Ethereum
$1,870.8 +0.26%
SOL Solana
$72.9 -0.42%
BNB BNB Chain
$578.2 -1.47%
XRP XRP Ledger
$1.06 +0.17%
DOGE Dogecoin
$0.0702 +1.15%
ADA Cardano
$0.1735 +2.24%
AVAX Avalanche
$6.38 -0.76%
DOT Polkadot
$0.7784 +2.46%
LINK Chainlink
$8.1 -0.34%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{年份}}
10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

12
05
halving BCH Halving

Block reward halving event

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

28
03
unlock Arbitrum Token Unlock

92 million ARB released

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$62,961.9
1
Ethereum ETH
$1,870.8
1
Solana SOL
$72.9
1
BNB Chain BNB
$578.2
1
XRP Ledger XRP
$1.06
1
Dogecoin DOGE
$0.0702
1
Cardano ADA
$0.1735
1
Avalanche AVAX
$6.38
1
Polkadot DOT
$0.7784
1
Chainlink LINK
$8.1

🐋 Whale Tracker

🔵
0x76f6...3200
30m ago
Stake
3,913,186 USDT
🟢
0xca33...f4a4
3h ago
In
4,537.55 BTC
🔵
0xbc43...1adc
3h ago
Stake
2,086.24 BTC

💡 Smart Money

0xf4e3...05be
Top DeFi Miner
+$0.4M
73%
0xd817...0121
Experienced On-chain Trader
+$0.9M
76%
0xeeaa...9daf
Early Investor
+$1.0M
87%

Tools

All →