We didn’t see it coming. A fake AI interview tool, “Relay,” masquerading as the next big remote-hiring platform, is actually a cross-platform malware designed to drain your crypto. SlowMist just dropped the full analysis, and the attack chain is terrifyingly simple: a LinkedIn message, a “quick voice test,” and then your wallet goes silent.
Context: The Web3 Hiring Gold Rush Turns Toxic
The market is euphoric. AI tools are everywhere. Hiring is hot. Attackers know this. They’ve weaponized the very narrative that lures Web3 professionals: cutting-edge tech, remote flexibility, and exclusive insider opportunities.
Targets are specific: developers, founders, security researchers — anyone holding private keys on a daily driver machine. The social engineering is surgical. A fake recruiter sends a link to “Relay,” a supposed AI meeting tool. You install it. That’s the point of no return.
Core: Inside ‘Relay’ — A Cross-Platform Treasure Hunter
Based on my own forensic experience tracking malware campaigns, the technical sophistication here is eyebrow-raising. ‘Relay’ isn’t a script kiddie’s toy. It’s a custom, multi-stage infostealer built for both macOS and Windows — a rarity in the wild.
What gets stolen, in order of pain:
- Browser credentials: Logins for exchanges, email, and cloud accounts.
- Crypto wallet data: Private keys, seed phrases from hot wallets like MetaMask, Phantom, or browser extensions.
- macOS Keychain: All stored passwords, including SSH keys and API tokens.
- Telegram sessions: Full access to your Telegram — messages, groups, and contacts.
This last one is the silent killer. Once an attacker owns your Telegram session, they can impersonate you to your network. Imagine: a fake message from “you” to your co-founder, asking for the multisig key. That’s the secondary attack vector the market is missing.
The malware uses obfuscation to slip past endpoint detection. It doesn’t trigger alerts because it mimics legitimate video call software. The payload is delivered only after the victim clicks “Install,” bypassing email gateways entirely.
SlowMist’s analysts already reverse-engineered the sample and published indicators of compromise (IOC). But let’s be real — by the time you read this, variants are probably already circulating. You can’t uninstall this. If your machine is infected, assume all credentials are burned.

The speed of this threat demands a velocity-first response. I’m breaking this story because every hour without a public warning means more victims. Your next job interview could be the one that empties your wallet.

Contrarian: The Party Doesn’t Stop — But Your Hot Wallet Might
Here’s the counter-intuitive angle the herd will miss:
This attack doesn’t weaken crypto — it strengthens the case for cold storage. Every time a hot wallet gets drained, hardware wallet sales spike. Ledger, Trezor, GridPlus — they’ll see a rush. Security firms like SlowMist become the heroes of the narrative.
But the real blind spot? Trust in AI tools just took a hit. The very innovation that powers remote hiring is now a loophole. Smart projects will pivot to zero-trust interview environments: dedicated virtual machines, one-time-use browsers, and blockchain-verified recruiter identities.

Ironically, the attack uses the same hype cycle that pumps narratives. “AI-powered recruitment” is now a red flag. The smartest move is to treat every unsolicited job offer as a zero-day exploit.
Takeaway: The Next Wave Is Deepfake Interviews
This is just the first wave. Expect audio deepfake interviewers within six months. Attackers will clone voices, imitate known recruiters, and demand you “test” their platform. Your only defense? A hardware wallet and a paranoid mindset.
— Root: The hardware wallet is your only safe seat.
What to do now:
- Immediately change passwords for any account accessed from a work computer.
- Rotate Telegram encryption keys and log out all active sessions.
- Never install an app sent via a LinkedIn DM — verify the recruiter through a secondary channel.
- Use a dedicated, isolated machine for any interview that requires software installation.
This is the s Demo of how fast the attack surface evolves. The bull market euphoria is blinding us to the simplest threat: a fake job offer.
Stay sharp. The next interview might be a rug pull.