SwiflTrail

The New Web3 Parasite: How a Fake AI Interview Tool Is Draining Wallets—And Why Your Hiring Process Is the Next Attack Vector

BitBoy Events

A new malicious software campaign is silently draining the wallets of Web3 professionals who thought they were just attending a job interview.

I didn't need to wait for the mempool to flash red. The signal came from a different source: an internal threat intelligence feed flagged a spike in wallet-draining events tied to a single, recently installed binary. SlowMist’s public disclosure confirms what my own monitoring detected—an organized effort to weaponize the recruitment pipeline against the very people who build this industry.

Context: The “Relay” Trap

The attack vector is simple, almost elegant in its brutality. An actor impersonating a recruiter contacts a target on LinkedIn, Telegram, or email. Conversation is professional. The bait is a meeting invitation for a job interview, required to use a tool called “Relay” — presented as an AI-powered interview assistant. The target downloads and installs it. Within seconds, the system is compromised.

SlowMist's analysis reveals that “Relay” is not a video conferencing tool but a custom information-stealing malware. It targets both macOS and Windows, a deliberate cross-platform design that indicates a seasoned operator. Once installed, it exfiltrates: - Browser credentials (cookies, saved logins) - Cryptocurrency wallet data (keystore files, private keys, browser extension storage) - macOS keychain or Windows credential manager - Telegram session files - Any additional sensitive documents the attacker chooses to target

The payload is not novel in its technical sophistication—it’s the social engineering wrapper that makes it dangerous. The attacker exploited the current AI boom narrative: “We use AI for interviews, please install this software.” A story so plausible it bypasses the skepticism of many seasoned developers.

Core: Code as a Weapon, Trust as a Liability

Let’s cut through the noise. This isn’t a bug in a DeFi contract or a vulnerability in a L2 bridge. It’s a direct assault on the trust layer that underpins the entire Web3 hiring ecosystem. We treat credentials as assets, and this attacker understands that better than most auditors.

Based on my own audit experience during the 2017 ICO storm, I learned that the most dangerous threats rarely come from a smart contract’s logic flaw. They come from the humans operating the keys. When I leveraged 10x on EOS and nearly blew up, it wasn’t a code exploit that hurt me—it was my own failure to isolate risk. That lesson drove me to build my copy trading platform around a simple principle: compartmentalize exposure.

The Relay malware does the opposite of compartmentalization. It centralizes all access into a single installation event. The attacker doesn’t need to exploit a 0-day; they need to convince one developer to click “Install.” And the current market environment—with thousands of remote-first Web3 companies desperate for talent—provides an ideal hunting ground.

SlowMist’s technical report notes that the malware uses obfuscation and anti-debugging techniques. But the real innovation is the infection chain: the attacker preps the victim with a plausible narrative, then delivers a binary that is effectively a full-system credential dump. The cross-platform support (both .dmg for macOS and .exe for Windows) suggests the developers have experience building on both operating systems. Trust the code, verify the chain, own the outcome. In this case, the chain is the social engineering link, not the blockchain.

Contrarian: The Real Vulnerability Is Not User Education—It’s Process Design

Most security advice will tell you to “be careful” and “verify the recruiter’s identity.” That’s like telling a trader to avoid bad trades. It’s empty. The real issue is structural: the entire Web3 recruitment pipeline relies on unverified trust. LinkedIn profiles can be faked. Email addresses are easy to spoof. And the use of third-party software for interviews is standard practice.

Here’s the contrarian angle: The attack reveals that remote hiring in Web3 is a systemic risk, not just a user deficit. We demand trustless systems for DeFi, yet we still onboard talent through centralized, identity-blind channels. The attacker didn’t exploit a bug; they exploited a process that has no built-in verification for the software being installed.

Hype is a liability; liquidity is the only truth. The liquidity of talent into the space is being poisoned. Every incident like this raises the cost of hiring, reduces trust, and gives regulators another reason to impose mandatory security standards on remote work. The attackers aren’t just stealing coins—they are damaging the reputation of Web3 as a safe place to build a career.

Takeaway: Build the Ship Before the Storm

We do not predict the storm; we build the ship. If you are a Web3 professional, change your behavior immediately. Do not install software from an email or direct link. Always run untrusted applications in a virtual machine or a dedicated device separate from your hot wallet environment. Use hardware wallets to store keys, never on a machine that also runs communication apps.

If you are a hiring manager, consider implementing verified identity protocols using DID or on-chain attestations for recruiters. Invest in isolated interview environments—remote desktops or browser sandboxes—where no malicious binary can touch your data.

This attack is not an isolated event. It is the first of a new generation of sophisticated, targeted campaigns aimed at the people who control the keys to the ecosystem. The attackers are watching the market. They are reading the job boards. They are learning from the social engineering playbooks of traditional finance and applying them to Web3 with precision.

What will you do when the next version of “Relay” arrives? Because it will.

The only question is whether you will have built your ship before the storm.

Market Prices

Coin Price 24h
BTC Bitcoin
$65,017.2 +1.26%
ETH Ethereum
$1,917.72 +1.11%
SOL Solana
$74.74 +2.92%
BNB BNB Chain
$593.8 +1.16%
XRP XRP Ledger
$1.03 +1.66%
DOGE Dogecoin
$0.0702 +1.75%
ADA Cardano
$0.2012 +0.55%
AVAX Avalanche
$6.54 +2.51%
DOT Polkadot
$0.8231 +1.45%
LINK Chainlink
$8.3 +2.02%

Fear & Greed

30

Fear

Market Sentiment

Event Calendar

{{年份}}
30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

18
03
unlock Sui Token Unlock

Team and early investor shares released

12
05
halving BCH Halving

Block reward halving event

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

28
03
unlock Arbitrum Token Unlock

92 million ARB released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

Tools

All →

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$65,017.2
1
Ethereum ETH
$1,917.72
1
Solana SOL
$74.74
1
BNB Chain BNB
$593.8
1
XRP Ledger XRP
$1.03
1
Dogecoin DOGE
$0.0702
1
Cardano ADA
$0.2012
1
Avalanche AVAX
$6.54
1
Polkadot DOT
$0.8231
1
Chainlink LINK
$8.3

🐋 Whale Tracker

🔵
0xc849...1d83
2m ago
Stake
4,406,111 USDT
🔴
0xa841...357b
12m ago
Out
40,192 BNB
🟢
0x140a...ff94
6h ago
In
50,860 SOL

💡 Smart Money

0x7850...73e2
Arbitrage Bot
+$1.7M
91%
0xf6db...dd81
Market Maker
+$4.9M
95%
0xb255...73c8
Top DeFi Miner
+$1.1M
70%