The most dangerous code in Web3 right now isn’t a smart contract exploit or a flash loan attack. It’s a binary file disguised as an AI meeting tool, waiting to be double-clicked by a developer or a trader desperate for their next role. On July 29, 2025, SlowMist disclosed a new targeted campaign where attackers pose as recruiters and lure victims into installing a fake application called “Relay”—a malicious info-stealer designed to drain wallets, hijack browser sessions, and exfiltrate Telegram credentials.
This isn’t a generic phishing blast. It’s a surgical strike on the narrative of opportunity.
Context: The Recruiting Trap
The attack chain is deceptively simple. An impersonated recruiter reaches out on LinkedIn or Telegram, offering an interview for a coveted Web3 position. The “interview” requires installing “Relay,” described as an AI-powered meeting assistant. Once installed, the malware—built for both macOS and Windows—scans the system for browser cookies, password manager entries, cryptocurrency wallet files, keychain data, and active Telegram sessions. Within minutes, the attacker gains access to trading accounts, hot wallets, and private communication channels.
SlowMist’s analysis reveals the malware is cross-platform, indicating a developer team with serious resources. The payloads are obfuscated and likely use anti-debug techniques to evade endpoint detection. The targets are not random; they are Web3 engineers, analysts, and investors—people whose machines hold high-value keys and negotiation secrets.
Core: When the Code Talks but the Story Sells
This attack is a textbook case of narrative-driven exploitation. The AI recruiting tool story is a perfect hook: it’s trending, it promises efficiency, and it plays on the urgency of securing a job in a competitive market. The victim’s trust is anchored in the recruiter’s credibility—a fabricated LinkedIn profile, a conversational Telegram thread, a sense of insider access. “Narrative is the new liquidity,” and here, the liquidity is the victim’s entire digital asset portfolio.
From a technical standpoint, the malware’s theft surface is comprehensive. It targets: - Browser-stored credentials (cookies, saved passwords) - Crypto wallet extensions (e.g., MetaMask, Phantom, Rabby) - macOS Keychain and Windows Credential Manager - Telegram session files (allowing session hijacking without 2FA)
Why these categories? Because the attacker understands the Web3 workflow. A developer keeps their wallet in the browser, their tokens on a hot wallet, and their deal flow in Telegram. The session tokens alone can be used to impersonate the victim in group chats, launching secondary attacks on colleagues.
Based on my experience auditing social engineering vectors during the Terra post-mortem, I know that the most effective attacks exploit a single moment of misplaced trust. Here, the trust is built on a story: “We’re a cutting-edge Web3 fund using AI to streamline hiring.” The code talks—it executes, steals, and exfiltrates—but the story sells the click.
Sentiment Dynamics
The current bull market (July 2025) amplifies the risk. Professionals are FOMOing into new opportunities; they’re less cautious because the environment feels prosperous. This attack leverages precisely that psychology. The narrative of AI in hiring is hot—everyone wants to be “evaluated by AI.” The malware creator piggybacks on that hype. As I often say, “Hype decays; utility endures.” But in this case, the “utility” is a parasitic one: the malware works, and it will persist until the narrative shifts.
Contrarian: The Real Vulnerability Isn’t Code—It’s Narrative
Most security analysis focuses on protocol bugs or DeFi hacks. But this attack reveals the true blind spot: the trust layer between humans and machines. We’ve been conditioned to trust recruitment processes. LinkedIn feeds, recruiter DMs, interview scheduling—it all feels routine. Yet the attacker exploits exactly that normalization.
The contrarian insight? This attack may actually boost the value proposition of hardware wallets and zero-trust interviewing environments. Cold storage demand will spike in the short term as professionals reconsider hot wallet exposure. Security services like SlowMist gain visibility, and enterprise-grade endpoint detection tools find new Web3 clients. The panic creates a market for defense.
But the deeper irony is that the same narrative dynamics enabling the attack—speed, opportunity, AI enthusiasm—also contain the seeds of defense. The market will reprice security as a job-market necessity. I expect to see dedicated “Web3 interview sandboxes” emerge: isolated VMs or browser containers that allow candidates to participate without exposing their main environment. This attack is a forcing function for a new security stack.
Takeaway: The Next Narrative Shift
What comes after this? The attackers will iterate. Deepfake audio or video of recruiters, real-time manipulation during “interviews,” and even AI-generated code reviews that embed backdoors. The narrative will evolve from “AI helps you get a job” to “AI is the interview itself.” And the defense will need to be just as narrative-aware.
As we move forward, ask yourself: When the code talks and the story sells, who’s actually buying? If you’re a Web3 professional, your next job offer might be a honeypot. Trust the data, not the story.