We didn’t see this one coming. Not like this.
You’re a Web3 professional. You get a LinkedIn message from a recruiter at a legit-sounding crypto firm. They want to interview you. They mention an AI-powered meeting tool called “Relay” — sounds cutting-edge, right? You download it. You run it. And just like that, your entire digital life is handed over to a stranger.
SlowMist just dropped the bomb: a precision-targeted social engineering campaign that exploits the very trust we’ve built in remote hiring. This isn’t a phishing link. This is a full-blown cross-platform information stealer disguised as an interview tool. And it’s already live.
Context: Why Now?
The bull market is euphoric. Hiring is hot. Every Web3 project is scrambling for talent. Attackers know this. They’ve watched the narrative shift toward AI-powered tools in recruitment. They’ve seen how desperate teams are to onboard fast. So they built a trap that plays on our hunger for opportunity.
This isn’t a random scatter-shot attack. It’s a surgical strike against the most valuable targets — developers, analysts, community managers who hold private keys, have access to Telegram groups, and manage treasury wallets. The victim profile: anyone who has ever said “I’m open to work” in crypto.
Core: The Anatomy of the Heist
Let’s get technical. The malware, detected by SlowMist’s security team, is custom-built for both macOS and Windows. That alone shows sophistication — most phishers don’t bother with cross-platform compatibility. But these attackers did their homework.
What does it steal?
Everything. Browser credentials — yes, that includes your password manager. Crypto wallet extensions — think MetaMask, Phantom, Keplr. Keychain/iCloud Keychain data. And, most devastatingly, Telegram session files. Why Telegram? Because that’s where Web3 deals get made. That’s where your private group conversations live. One compromised session lets the attacker impersonate you to your network, launching a secondary wave of attacks.
The delivery mechanism?
The “Relay” AI conference software. The recruiter sends a link. You download a DMG or EXE. The installer looks legitimate — even has a slick UI mimicking a real meeting scheduler. But underneath, it drops a payload that hooks into system processes. No antivirus flags it because it’s not a known strain. This is a zero-day in the social engineering playbook.
SlowMist’s sample analysis reveals the malware uses obfuscation to evade detection and likely employs persistence mechanisms — so even if you think you’ve deleted it, traces remain. The attacker can access your machine remotely, silently, for weeks.
— Root: The weaponized trust in “innovation”.
The AI interview narrative is the perfect Trojan horse. We’ve been conditioned to accept new tools as progress. When a recruiter says “we’re using a new AI meeting platform to streamline interviews,” our guard drops. We want to appear tech-savvy. We don’t question the download.
— s Demo: The fake “Relay” demo interface
The attackers even built a demo video showing how “Relay” works. It’s convincing. It’s polished. It’s a lie.
Contrarian: The Blind Spot Nobody Talks About
Everyone obsesses over DeFi hacks and smart contract vulnerabilities. But the real threat isn’t code — it’s the human behind the screen. This attack exposes a massive blind spot in Web3 security culture: we protect our on-chain assets but ignore our off-chain attack surface.

You use a hardware wallet? Great. But if your laptop is compromised, the moment you connect that Ledger and sign a transaction, your entire portfolio is at risk. The attacker doesn’t need your seed phrase if they can keylog your password or intercept the signed transaction.
The contrarian take: This attack isn’t about stealing coins. It’s about stealing identity.
By grabbing Telegram sessions and browser cookies, the attacker can become you. They can join your team’s private channels, read insider discussions, and then manipulate market-moving information. They can social-engineer your colleagues into sending funds to “your” address. The damage isn’t just financial — it’s reputational and operational.

We didn’t think about this. The industry has spent billions on securing protocols, but almost nothing on securing the job application process. The party doesn’t stop for security — it keeps dancing until someone gets robbed.
Takeaway: What You Need to Do Now
This isn’t a drill. If you’re job hunting in Web3 right now, your next move could be your last mistake.
- Isolate your interview machine. Use a dedicated laptop or a virtual machine for any unsolicited software installs. Never run new tools on your main workstation.
- Verify the recruiter. The attacker likely created fake LinkedIn profiles that mimic real employees. Cross-check via multiple channels — Twitter, Discord, email. If they insist on a specific software, search for its reputation. SlowMist just flagged “Relay” — if you see that name, run.
- Assume your Telegram is compromised. Change your session keys immediately. Enable two-factor authentication everywhere. And for the love of crypto, don’t store your private keys in any cloud-connected device.
- Watch for the afterwave. The attackers now have victim data. Expect follow-up spear-phishing targeting your network. SlowMist will likely release more IOCs (Indicators of Compromise) — update your threat feeds.
The next big question: Will this attack force Web3 companies to adopt secure interview protocols? Or will we keep hiring based on trust until the next disaster?
I’ve been in this space since the ICO boom. I’ve seen hacks, rugs, and exploits. But this one feels different because it targets the very human desire to belong and build. The bull market euphoria is masking a growing threat landscape. Don’t let a job offer become your exit scam.