New malware sample identified.
Targets: Crypto wallets, browser cookies, Telegram sessions. Platform: macOS and Windows simultaneously. Vector: Fake AI meeting software called 'Relay'.
SlowMist just dropped the forensic report.
Over the past 48 hours, the security firm unearthed a strain of information-stealing malware with a laser focus: Web3 professionals. The attack chain is textbook social engineering, but the execution is anything but textbook.
ERC-20 rush vibes. Proceed with caution.
This isn't a random phishing campaign. It's a targeted operation that understands the psychology of the crypto job market.
Context: The Fake Interview Trap
The setup is elegant in its cruelty.
An attacker, posing as a recruiter for a legitimate Web3 company, reaches out via LinkedIn or Telegram. They schedule an interview. They send a link to download 'Relay' — a supposed AI-powered meeting assistant. The victim installs it, thinking they're about to secure a job.
Instead, they grant full system access to a malicious payload.
Based on my experience auditing the 2022 LUNA collapse, I learned that social engineering is the hardest vulnerability to patch. This attack weaponizes the job seeker's eagerness. The trust in 'interview processes' is a blind spot no one talks about.
Core: The Malware Breakdown
SlowMist's sample analysis reveals a sophisticated, cross-platform stealer.
- macOS version (Mach-O binary): Targets Keychain, browser-stored credentials (Chrome, Firefox, Brave, Edge), and cryptocurrency wallet extensions (MetaMask, Phantom, Coinbase Wallet, etc.).
- Windows version (PE executable): Similar scope, plus Telegram session token harvesting. The malware exfiltrates data via encrypted channels to a command-and-control server.
Key capabilities: - Grabs ~/.config/* directories containing wallet private keys (JSON files). - Parses browser SQLite databases for autofill passwords. - Steals Telegram authentication files (tdata) — enabling account takeover. - No persistence mechanism detected yet, but the damage is done immediately.
Gas spike detected. Run.
If you've installed any unsolicited software from a 'recruiter' in the past week, your wallets are compromised. Assume your keys are exposed.
Contrarian Angle: The Real Blind Spot Is Trust in 'Verified' Platforms
Most security advice focuses on code audits or DeFi protocol risk. This attack exploits the human layer of the Web3 job market.
Here's what no one is saying: The attack didn't need a smart contract vulnerability or a flash loan. It used the same psychological lever that makes people click 'allow' on token approvals — perceived legitimacy.
The counter-intuitive truth: Even security-aware crypto natives dropped their guard during job interviews. Why? Because the 'interview' context lowers suspicion. You are conditioned to trust a process that involves a company name, a job posting, and a Zoom link.
This attack proves the weakest link is not the code — it's the pre-onboarding pipeline.
SlowMist's disclosure will likely trigger a wave of copycats. The barrier to entry is low: any attacker can spin up a fake recruiting profile and distribute a modified version of the malware.

Takeaway: The Only Defense Is a Dedicated, Air-Gapped Interview Machine
No exceptions.
Use a separate laptop or a virtual machine that contains zero personal data. Never connect it to your main wallet. Never enter passwords or seed phrases on a machine used for interviews.
I'm already seeing signs of a broader trend: Web3 companies will soon require verified, tamper-proof interview platforms. Or they'll move to identity-based verification using DID (Decentralized Identity) and zero-knowledge proofs.
Until then, treat every meeting link as a potential exploit.
SlowMist is tracking additional indicators of compromise. Watch for updates. Don't become the next victim.