We didn’t see this coming — until SlowMist peeled back the layers.
A new malware campaign, disguised as a legitimate AI interview tool called "Relive," is targeting Web3 professionals with surgical precision. The attack vector isn’t a smart contract bug or a flash loan exploit. It’s a job offer. And that makes it far more dangerous.
We didn’t build trustless systems so that a recruiter could be the backdoor.
— Root: The assumption that a warm LinkedIn message from a "crypto hiring manager" is safe.
Let’s walk through the kill chain. The attacker impersonates a recruiter from a well-known Web3 company, sends a calendar invite with a link to download "Relive" — a custom-built info-stealer. The software mimics a legitimate AI meeting tool (think Otter.ai or Fireflies.ai), but the binary is nothing more than a polished Trojan. SlowMist’s analysis reveals it’s cross-platform: both macOS and Windows variants exist. Once installed, it exfiltrates browser passwords, crypto wallet extensions’ data, macOS Keychain entries, and Telegram session tokens — all in one silent sweep.
This isn’t a spray-and-pray attack. It’s a spearphishing campaign aimed at people who hold significant crypto assets. The attacker understands the industry: they know that Web3 developers and founders often have tens of thousands of dollars in hot wallets, use browser-based wallets for convenience, and treat Telegram as their primary communication channel. Stealing a Telegram session is the modern equivalent of stealing a corporate badge — it unlocks access to private groups, alpha channels, and future targets.
But here’s where the story gets philosophically interesting.
We’ve been conditioned to believe that the killer app of crypto is "trust minimization." Smart contracts replace escrow. Public keys replace identity. But this attack reveals a glaring blind spot: the human layer. You can audit a Solidity contract line by line, but you cannot audit a recruiter’s intentions. The very trust that Web3 seeks to eliminate from financial transactions has migrated to employment relationships — and it’s being weaponized.
— Root: The trust we place in a job offer that comes with a code snippet.
Based on my own experience running a Web3 community and watching the hiring frenzy in this bull market, I’ve seen countless founders skip background checks on hires. Speed trumps diligence. "We’re a DAO, we move fast" becomes the justification for skipping security basics. Now, the same rush is being exploited from the other side: applicants are so eager to land a role at a hot project that they click "Download" without a second thought.
The contrarian angle here is uncomfortable. The immediate reaction from the security community will be: "Use a hardware wallet. Never store keys on a laptop." That advice is sound — but it misses the point. The real vulnerability isn’t technical; it’s cultural. We have built an entire industry on the myth that code is law, yet we still trust a LinkedIn profile picture and a meeting link. The attack surface isn’t a bug in Ethereum’s state machine — it’s a bug in our collective decision-making under urgency and FOMO.
Let me be provocative: maybe the reason this attack works is because we secretly want to trust. In a market filled with scams, rugs, and exploits, the job interview feels like a safe space — a moment of honest human connection. The attacker exploits this emotional gap. They don’t break encryption; they break the human need for belonging.
SlowMist’s disclosure is a service to the ecosystem, but the pattern is now public. Expect copycat campaigns within weeks. The attack will evolve: deepfake video interviews, fake coding tests that inject backdoors, even fraudulent reference checks that steal your entire network.
So what do we do?
First, immediate tactical advice: Never install software from an unsolicited meeting invite. If a recruiter asks you to download a specific tool — especially one you’ve never heard of — verify their identity through a separate channel (Slack, Discord, or a phone call). Use a dedicated virtual machine or a clean laptop for interviews if you’re actively job hunting. And for the love of Nakamoto, keep your private keys on a hardware device that isn’t connected to your work computer.
But the deeper lesson is about infrastructure. We need to build tooling that makes social engineering harder — not just technically, but socially. Decentralized identity (DID) systems that allow recruiters to prove their affiliation with a project without revealing personal data. Zero-knowledge proof-based verification of employment. Even "safe interview environments" that run code in sandboxed containers. The technology exists; what’s missing is the will to deploy it.
We didn’t anticipate that the Trojan horse would be a job offer.
— Root: The false sense of safety that comes with being part of a trusted community.
The Web3 narrative has always been about empowerment — taking control away from intermediaries and giving it to individuals. But empowerment comes with responsibility. This attack is a wake-up call that the weakest link isn’t your code — it’s your next click. As we ride this bull market, let’s not let euphoria blur our judgment. The most sophisticated smart contract can’t protect you from the person on the other end of a Zoom call.