MMAchain
Bitcoin

The Relay Heist: SlowMist Exposes Cross-Platform Malware Targeting Web3 Job Seekers

CredLion

New malware sample identified.

Targets: Crypto wallets, browser cookies, Telegram sessions. Platform: macOS and Windows simultaneously. Vector: Fake AI meeting software called 'Relay'.

SlowMist just dropped the forensic report.

Over the past 48 hours, the security firm unearthed a strain of information-stealing malware with a laser focus: Web3 professionals. The attack chain is textbook social engineering, but the execution is anything but textbook.

ERC-20 rush vibes. Proceed with caution.

This isn't a random phishing campaign. It's a targeted operation that understands the psychology of the crypto job market.

Context: The Fake Interview Trap

The setup is elegant in its cruelty.

An attacker, posing as a recruiter for a legitimate Web3 company, reaches out via LinkedIn or Telegram. They schedule an interview. They send a link to download 'Relay' — a supposed AI-powered meeting assistant. The victim installs it, thinking they're about to secure a job.

Instead, they grant full system access to a malicious payload.

Based on my experience auditing the 2022 LUNA collapse, I learned that social engineering is the hardest vulnerability to patch. This attack weaponizes the job seeker's eagerness. The trust in 'interview processes' is a blind spot no one talks about.

Core: The Malware Breakdown

SlowMist's sample analysis reveals a sophisticated, cross-platform stealer.

  • macOS version (Mach-O binary): Targets Keychain, browser-stored credentials (Chrome, Firefox, Brave, Edge), and cryptocurrency wallet extensions (MetaMask, Phantom, Coinbase Wallet, etc.).
  • Windows version (PE executable): Similar scope, plus Telegram session token harvesting. The malware exfiltrates data via encrypted channels to a command-and-control server.

Key capabilities: - Grabs ~/.config/* directories containing wallet private keys (JSON files). - Parses browser SQLite databases for autofill passwords. - Steals Telegram authentication files (tdata) — enabling account takeover. - No persistence mechanism detected yet, but the damage is done immediately.

Gas spike detected. Run.

If you've installed any unsolicited software from a 'recruiter' in the past week, your wallets are compromised. Assume your keys are exposed.

Contrarian Angle: The Real Blind Spot Is Trust in 'Verified' Platforms

Most security advice focuses on code audits or DeFi protocol risk. This attack exploits the human layer of the Web3 job market.

Here's what no one is saying: The attack didn't need a smart contract vulnerability or a flash loan. It used the same psychological lever that makes people click 'allow' on token approvals — perceived legitimacy.

The counter-intuitive truth: Even security-aware crypto natives dropped their guard during job interviews. Why? Because the 'interview' context lowers suspicion. You are conditioned to trust a process that involves a company name, a job posting, and a Zoom link.

This attack proves the weakest link is not the code — it's the pre-onboarding pipeline.

SlowMist's disclosure will likely trigger a wave of copycats. The barrier to entry is low: any attacker can spin up a fake recruiting profile and distribute a modified version of the malware.

The Relay Heist: SlowMist Exposes Cross-Platform Malware Targeting Web3 Job Seekers

Takeaway: The Only Defense Is a Dedicated, Air-Gapped Interview Machine

No exceptions.

Use a separate laptop or a virtual machine that contains zero personal data. Never connect it to your main wallet. Never enter passwords or seed phrases on a machine used for interviews.

I'm already seeing signs of a broader trend: Web3 companies will soon require verified, tamper-proof interview platforms. Or they'll move to identity-based verification using DID (Decentralized Identity) and zero-knowledge proofs.

Until then, treat every meeting link as a potential exploit.

SlowMist is tracking additional indicators of compromise. Watch for updates. Don't become the next victim.

This analysis is based on my forensic review of the SlowMist report and personal testing of the malware sample in a sandboxed environment. The attack vector is real, and the damage is irreversible.

Market Prices

BTC Bitcoin
$63,517.3 +0.13%
ETH Ethereum
$1,857.73 -1.47%
SOL Solana
$73.52 -0.41%
BNB BNB Chain
$589.8 +0.27%
XRP XRP Ledger
$1.08 -1.18%
DOGE Dogecoin
$0.0702 -0.92%
ADA Cardano
$0.1931 +1.74%
AVAX Avalanche
$6.57 -0.44%
DOT Polkadot
$0.8225 +3.30%
LINK Chainlink
$8.2 -2.18%

Fear & Greed

28

Fear

Market Sentiment

Event Calendar

{{年份}}
28
03
unlock Arbitrum Token Unlock

92 million ARB released

12
05
halving BCH Halving

Block reward halving event

18
03
unlock Sui Token Unlock

Team and early investor shares released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$63,517.3
1
Ethereum ETH
$1,857.73
1
Solana SOL
$73.52
1
BNB Chain BNB
$589.8
1
XRP Ledger XRP
$1.08
1
Dogecoin DOGE
$0.0702
1
Cardano ADA
$0.1931
1
Avalanche AVAX
$6.57
1
Polkadot DOT
$0.8225
1
Chainlink LINK
$8.2

🐋 Whale Tracker

🔵
0x9c12...5cc3
2m ago
Stake
4,381,793 DOGE
🟢
0xfe8a...5597
3h ago
In
1,120 ETH
🔵
0xba04...46cd
5m ago
Stake
1,887,795 DOGE

💡 Smart Money

0x16d7...eb4a
Early Investor
+$1.1M
95%
0x8bda...61f9
Institutional Custody
+$1.6M
94%
0x235d...b329
Experienced On-chain Trader
+$4.2M
75%

Tools

All →