There is a peculiar silence that accompanies a successful social engineering campaign. It does not announce itself like an on-chain exploit, where block explorers narrate the draining of a treasury in real time and thousands of commentators gather to dissect the mechanics. This silence is different. It begins at the precise moment a Web3 developer clicks “Install” on a meeting application called Relay, recommended by a recruiter they have never met, for an interview that feels entirely plausible. The application’s icon lands in the dock. The setup wizard runs. Permissions are granted — keychain access, accessibility, screen recording — because the app is, ostensibly, an AI-powered meeting assistant. And silence endures until, days later, a wallet is drained, a Telegram account begins sending messages its owner never composed, and a decade of digital credentials evaporates into a stranger’s server.
On July 29, 2025, SlowMist — the blockchain security firm best known for its MistTrack on-chain forensics platform — lifted the curtain on this emerging threat. The disclosure described a targeted recruitment campaign: attackers impersonating talent-acquisition professionals at crypto companies, inviting experienced Web3 practitioners to install Relay, a counterfeit AI meeting-notetaker, only to deliver a custom information-stealing trojan. The malware was compiled for both macOS and Windows. Its payload was surgical: browser credential stores, cryptocurrency wallet data, macOS Keychain contents, and Telegram session files. This is not a broad-net phishing expedition. It is an assassination of digital identity, disguised as an employment opportunity.
To understand why this campaign matters — and why it will not be the last of its kind — we must first map the terrain the attackers selected. The bull market of 2025 has produced a peculiar form of institutional frenzy. Following the 2024 Bitcoin ETF approvals, capital flooded into digital assets with the force of a tide, and with capital came the most predictable of consequences: a war for talent. Projects are raising, teams are expanding, and the demand for engineers, auditors, researchers, and operations staff has outpaced every existing pipeline. Every serious protocol is hiring, and the urgency is legible in job boards, Discord servers, and the phrase “competitive compensation” that now precedes even the mention of a role’s responsibilities.
Hiring, in the remote-native world of Web3, runs on trust artifacts. LinkedIn profiles, X verifications, GitHub activity, Discord histories, conference appearances, and an accumulating portfolio of on-chain credentials — these are the signals that bridge the physical gap between candidate and employer. There is no headquarters to visit, no HR office to verify an interviewer’s badge, no corporate IT department to approve a software installation. The entire employment relationship is negotiated across a digital divide that both sides must cross on faith. This is the context the attackers exploited with chilling patience. They did not target the exchanges, the bridges, or the audited contracts. They targeted the candidate pipeline — the most human, least scrutinized surface in the entire digital asset economy.
Consider the asymmetry of the Web3 professional’s position. A traditional enterprise employee works on a managed device, deploys a vetted software catalog, and enjoys the protection of a dedicated security operations function. Should a suspicious installer appear, the employee can forward it to an IT team that exists precisely for that contingency. The Web3 professional enjoys none of this. They are expected to be their own security operations center, their own procurement department, and their own incident response team. They run their wallets on the same machine they use for interviews. They keep seed phrases in password managers or, alarmingly, in the notes sections of their keychains. They sign smart contract interactions between meetings. Their Telegram accounts are repositories of protocol relationships, DAO memberships, and deal flows. In other words, the Web3 professional is not merely a target; they are a walking, talking hot wallet with a resume attached.
The choice of an AI meeting tool as the lure deserves particular attention. In 2025, AI meeting-notetakers have become as ubiquitous as email. Otter, Fireflies, Fathom, Granola, and a dozen other services promise to transcribe, summarize, and action-item every conversation. The narrative of productivity has normalized the act of granting a third-party application deep system access — microphone, camera, screen recording, calendar, and contacts. The attackers did not invent a new name out of thin air; they invented a plausible variation of an existing category. Relay sounds like a meeting tool. It behaves, in its earliest installation steps, like one. It is only in the exfiltration phase that its true nature is revealed.
There is a geographical and industrial irony worth noting. SlowMist is one of the most credible actors in this ecosystem, having assisted in the investigation of some of the largest exploits in crypto history, including cross-chain bridge thefts and exchange intrusions. That the firm’s threat-intelligence wing now publishes analyses of fake recruiting software says something uncomfortable about the industry’s maturation: the cheapest attack vector in blockchain is no longer a smart contract bug. It is a cleverly phrased invitation.
Let me now walk through the technical anatomy of the campaign, not as a panic-inducing exposé, but as a practitioner’s deconstruction. Because understanding the machinery — the precise points of failure, the decisions that enable the attack, and the economics that motivate it — is the only durable defense.
Step one is reconnaissance, and here the attackers were fastidious. This was not a mass automated campaign. To target Web3 professionals effectively, one must understand the industry’s social graph: who builds at which protocol, which recruiters are actively hiring, what artifacts signal momentum — job postings, GitHub activity, speaking engagements, and recent funding announcements. The attackers created or compromised recruiter personas, likely on LinkedIn, and made them indistinguishable from genuine talent professionals. Given the campaign’s precision, the level of open-source intelligence gathering required is substantial. This is not the work of an opportunistic script kiddie; it is the work of an operator who studied the industry’s hiring rituals with the patience of a predator studying a watering hole.
Step two is the trust transaction itself. The recruiter reaches out with an opportunity that fits the victim’s profile. There is a conversation, a screening call, perhaps even a first technical discussion. Then comes the pivot: “For the next stage, we use Relay for structured interviews — the AI notes really help our hiring committee.” The candidate is sent a link. That link, and here is the detail that should chill every security professional, leads to a privately distributed installer, not an App Store listing, not a verified download page, not a code-signed distribution channel with public reputation. The candidate, who has spent years being trained by the industry to respond to urgency and opportunity, makes a calculation: my career is on the line, the credentials look right, and this is how modern companies hire. The installer runs.
Step three is the payload. SlowMist’s sample analysis indicates a dual-platform trojan, and the dual-platform investment is itself a meaningful signal. Opportunistic phishing groups rarely build for both ecosystems; the maintenance burden is too high, and the return from macOS victims in a typical campaign rarely justifies the engineering cost. Precision groups — whether financially motivated syndicates, espionage-aligned actors, or advanced persistent threat organizations — invest in fragmentation because they intend to run the operation at scale. On Windows, the malware likely deploys the standard arsenal of credential theft: reading Chromium-based browser databases, decrypting saved passwords where possible, extracting autofill data, and hunting for wallet extension vaults. On macOS, the attack is more sophisticated, and more telling. Accessing the Keychain requires either elevated privileges granted through the setup wizard’s permission prompts or a targeted attack against the user’s Keychain password. The authors knew precisely where the valuable data lives and what permissions to request. They also knew that macOS users, conditioned by years of “drag the app to Applications” installations, rarely inspect code signatures or gatekeeper warnings with genuine rigor.
The exfiltration scope reads like an inventory of a modern digital life. Browser credential stores feed the attackers accounts for exchanges, cloud dashboards, email providers, and password managers. Cryptocurrency wallet data — the extension vaults and wallet files that hold the cryptographic material of one’s financial existence — is the obvious prize. macOS Keychain contents extend far beyond passwords: they hold Wi-Fi credentials, application secrets, and, in the dangerous but common user practice of storing seed phrase remnants in the Notes app, the literal keys to the kingdom. And Telegram session files, the crown jewel of the operation, allow account impersonation without triggering the two-factor authentication notifications that ordinarily guard a hijacked login.
The inclusion of Telegram session theft is, in my assessment, the most carefully considered component of the entire operation. Telegram is the nervous system of the crypto industry. DAO coordination, private chats with fellow founders, investor discussions, and recruitment conversations all flow through it. A Telegram session file, once stolen, allows an attacker to wear the victim’s identity without needing the password. They do not need to breach the account; they have the key. And once inside the victim’s Telegram universe, the attacker gains something more valuable than a single wallet: they gain provenance. Messages sent from a trusted account to the victim’s contacts inherit the victim’s reputation. This is how a point-source malware infection becomes a propagating social worm. One compromised developer can, within hours, expose their entire professional network to the same fake recruiter script — only now the fake recruiter message arrives from a colleague’s account, and the link carries a trusted silhouette.
There is a human story buried inside this technical architecture, and it is the story I found myself returning to as I read SlowMist’s disclosure. In my years researching cross-border payments in Latin America, I documented how migrant workers are systematically defrauded by employment agencies that promise legitimacy and deliver exploitation. The pattern is identical: the victim is operating outside the protection of formal institutions, desperate for opportunity, and willing to trust a convincingly professional intermediary who appears to hold the keys to a better life. The agency collects its fee — sometimes a document, sometimes a bank account number, sometimes a photograph of identity papers — and then disappears. The Web3 professional targeted by the Relay campaign is the migrant worker of the digital economy. Both are told that they must assume the risk of the journey themselves. Both are taught that distrust is a disqualifying trait. Both discover, too late, that the intermediary was the hazard all along.
The economics of this attack chain deserve a moment of forensic appreciation. Follow the money, not the noise. The attacker’s upstream costs are significant: cross-platform malware development, social engineering infrastructure, persona maintenance, and command-and-control servers. There is a long game here. The immediate prize — a hot wallet’s contents — is volatile and may be modest. But the durable prize is identity: the Telegram sessions, the browser credentials for exchanges, the cloud dashboards, the email accounts. These grant the attacker the ability to move laterally, to fund further operations, and, in the most chilling scenario, to sell compromised identities to other criminal groups. In the dark-market taxonomy of our industry, credentials are commodities, and a freshly harvested Web3 professional’s identity fetches a premium precisely because it is embedded in a high-trust network. The attack is not a theft; it is an acquisition.
I have been watching this pattern for longer than I care to admit. In 2017, I spent weeks reverse-engineering the smart contracts of seven utility tokens, most of which had raised significant capital. The code was often weak, but the deeper weakness was operational. Teams conducted business through unencrypted communication channels, stored privileged keys on shared laptops, and trusted voice verification without any proof of identity. I wrote about that fragility then, and the industry responded with a decade of investment in code-security tooling — audits, formal verification, bug bounties, and monitoring platforms. We built an impressive fortress around the protocol layer. We left the human layer exposed. The Relay campaign is the inevitable consequence of that asymmetry: the attacker knows the fortress walls are thick, so they walk around them and knock on the front door.
Let me also address the detection gap, because it is the part of this story that security professionals should find most troubling. Endpoint detection and response suites ship with heuristics, but novel unsigned malware — especially custom trojans distributed through private links rather than public repositories — enjoys a window of invisibility. That window is measured in days, sometimes weeks, before a sample is shared, dissected, and published as an indicator of compromise. SlowMist’s disclosure is essential precisely because it compresses that timeline. But the timeline compression only helps the segment of the ecosystem that actively reads threat-intelligence feeds. The majority of job-seeking developers will never see a SlowMist publication. They will see a message in their inbox. The gap between those two realities is where the attack lives.
Now comes the part of this analysis that will make some readers uncomfortable, because it forces us to question a belief the industry holds sacred. We have spent half a decade telling ourselves that the core vulnerability of decentralized finance is code, and that the remedy is better engineering. Formal verification, ZK-rollups, audited multi-sigs, secure enclaves — the entire edifice of modern Web3 security rests on the premise that if we harden the computation, we protect the assets. The Relay campaign contradicts that premise. No smart contract was exploited. No consensus mechanism was attacked. No cryptographic primitive was broken. An attacker sent a LinkedIn message and a meeting-app link. The most sophisticated adversary in this story did not attack the code. They attacked the transaction that precedes the code: the decision to trust.
And this is where the bull market reveals its dark twin. Euphoria is not merely an investment condition; it is a security condition. The frantic pace of hiring, the FOMO of candidates desperate to join the next rocketship, the pressure to appear flexible and cooperative in front of a potential employer — all of these create the ideal psychological substrate for social engineering. The candidate who is anxious about landing a role will not question the recruiter who insists on a specific tool. The candidate who is mentally calculating a token allocation will not examine the code-signing certificate on the installer. The candidate who has convinced themselves that “this is how the industry works now” will grant keychain permissions with the same reflexive compliance they once offered corporate HR portals. Volatility is the tax on impatience — and impatience, it turns out, also brokers access to your wallet.
There is a deeper structural irony here. The crypto industry devoted the last decade to the principle of self-sovereignty: your keys, your responsibility. But the Relay campaign exposes the ethical limit of that slogan. Telling individuals they are solely responsible for their security is an abdication of collective duty when the ecosystem’s own hiring culture normalizes the installation of unverified software as a condition of employment. We cannot simultaneously demand that professionals hold their own keys and then socially compel them, through the pressure of the hiring process, to expose those keys to unsigned binaries. This is the institutional-ethical tension the campaign lays bare: the industry’s ethos of individual responsibility has become a convenient cover for the absence of protective infrastructure. A traditional employer has an IT department, a software procurement policy, and a duty of care. Web3 offers its workforce none of these.
The contrarian conclusion, then, is this: the most important security upgrade in the coming cycle is not a new audit tool or a better hardware wallet. It is the invention of trust infrastructure for the hiring process itself — decentralized identity verification for recruiters, attestation-based proof that a job offer is genuine, and session isolation for candidate software. Until that infrastructure exists, the professional Web3 workforce is being asked to run a gauntlet where the opposition has studied their psychology more carefully than the industry has studied their safety. And that is not a technical problem. It is an ethical one.
The next twelve months will determine whether the industry treats this campaign as an anomaly or a blueprint. If the actors behind the Relay trojan are professionals, as the evidence strongly suggests, then the playbook is already being refined. New names will replace Relay. New personas will populate LinkedIn. The threat will be rebranded faster than the industry can update its warnings. The durable response cannot be a blog post or a hash list; it must be a shift in the default behaviors of both employer and candidate. Serious Web3 companies should begin offering sandboxed interview environments — isolated virtual machines in which candidates can run any requested tool without endangering their primary devices. Recruiters should carry verifiable credentials issued by the hiring protocol, cryptographically binding their identity to the organization they claim to represent. And candidates should adopt a simple rule that would have neutralized this entire campaign: never install unverified software on the machine that holds the keys.
There is, in the end, a quiet continuity between this week’s disclosure and every major security event I have witnessed across twenty-two years of observing this industry. The pattern is always the same: we audit the code, we secure the protocol, we celebrate our growing maturity — and then an attacker walks through the door we were certain no one would notice. The private key was never the frontier. The inbox was. The interview room was. Trust, once weaponized, compounds faster than any token. The market will absorb this story, as it absorbs every security narrative in a bull cycle, with a brief flutter of concern followed by a return to momentum. That is the nature of noise. But the slow, silent work of building trust infrastructure is already underway, and it will not be accelerated by panic. It will be accelerated by the quiet realization, arriving in a recruiter’s message on a Tuesday afternoon, that the most dangerous asset in this industry is not the code we fail to read. It is the identity we fail to verify. Follow the money, not the noise. The money is in the keys. And the keys are one careless install away from a stranger.