You just got a LinkedIn message from a talent scout at a top crypto fund. They want to fast-track you through a new AI-powered interview tool called 'Relay'. You click the link, download the app, and within minutes your browser is swept, your Telegram sessions cloned, and your hardware wallet’s companion app spits out your seed phrase. This isn’t a horror story — it’s the real-time threat SlowMist uncovered on July 29, 2025. The chart whispers, but the volume screams: this is the most targeted credential theft campaign I’ve seen since the ICO era.
Context: Why the AI Interview Narrative Is the Perfect Lure
We’re in a sideways market — chop is for positioning. But while traders stare at resistance levels, attackers are exploiting the hottest trend in hiring: AI-powered recruitment tools. Web3 companies have been racing to adopt automated interview platforms to screen the flood of applicants. The attackers know this. They’ve weaponized the very tool candidates expect to see. Instead of a fake whitepaper or a phishing link, they offer a legitimate-looking desktop app that does exactly what a recruiter would ask — record a video, analyze responses, share screen. Except it also scrapes every credential it can find.
Based on my audit experience during the 2020 DeFi Summer, I saw how quickly social engineering evolves. Back then, it was Telegram DMs promising airdrop allocations. Now it’s a polished recruitment process that mirrors real hiring flows. Speed is the only hedge in a real-time world, and these attackers are moving faster than most security teams can respond.
Core: The Technical Anatomy of the ‘Relay’ Malware
Let’s cut to the data. SlowMist’s sample analysis reveals a custom information stealer built for both macOS and Windows. The binary is signed with a stolen or self-issued certificate — it passes Gatekeeper on Mac. Once installed, it executes a multi-stage payload that targets:
- Browser credential stores (Chrome, Brave, Firefox) — extracting saved passwords and cookies.
- Crypto wallet extensions — specifically looking for MetaMask, Phantom, and Keplr’s localStorage files, where plaintext seed phrases are sometimes cached.
- macOS Keychain — dumping all stored passwords, including those for Exchange APIs and SSH keys.
- Telegram session files — copying the tdata folder to hijack active sessions without 2FA.
This is not a script kiddie operation. The malware uses process injection to evade EDR and maintains persistence via launch agents (mac) or scheduled tasks (Windows). During the Terra crash distraction, I learned that panic makes people click first and think later. That’s exactly what’s happening now. The attackers timed this campaign during a period of relative market calm, when professionals are more likely to entertain unsolicited interview requests.
Liquidity flows where fear turns into opportunity — but here, the fear is manufactured. The malware’s C2 infrastructure is hosted on a mix of bulletproof hosting providers, with exfiltrated data compressed and encrypted before transmission. SlowMist has published the file hashes and domain IOC, but the damage is already done for a window of victims.
Contrarian: This Attack Exposes Crypto’s Biggest Lie — ‘Trustless’ Doesn’t Include the User
Here’s the angle most coverage will miss: this attack isn’t a bug in a smart contract or a flaw in a consensus mechanism. It’s a direct exploitation of the human layer that blockchain was supposed to eliminate. For years, the narrative has been "not your keys, not your coins." But that responsibility is meaningless if users can be socially engineered into giving up those keys willingly.
Ironically, this will drive more liquidity into regulated custody solutions — exactly the opposite of the "self-custody" ethos. When professionals lose their personal wallets, they start trusting institutions again. We didn’t build Bitcoin to be Wall Street’s toy, but that’s exactly what happens when security fears mount. The ETF arbitrage edge I analyzed in 2024 showed that institutional players are already exploiting retail fear to accumulate. Now they’ll add custody services to the list.
Another blind spot: the attack proves that even "secure" operating systems like macOS are vulnerable when users voluntarily install a malicious app. The Web3 community has been slow to adopt sandboxed execution environments for sensitive activities. This event should trigger a shift toward mandatory hardware wallet isolation for any interaction with new software.
Takeaway: Forward-Looking Signal for the Next 90 Days
Expect a spike in demand for hardware cold wallets and dedicated offline signing devices. Watch for announcements from Ledger and Trezor about integration with isolated interview environments. The next evolution will be decentralized identity (DID) protocols that verify recruiter credentials on-chain before any download. Speed kills hesitation, but hesitation can save your wallet. If a recruiter asks you to install an app, pause. Verify via a separate channel. The liquidity of your portfolio depends on it.