Fake AI Interview Tool Targets Web3 Professionals: New Social Engineering Threat Uncovered by SlowMist

Ivytoshi NFT
A sophisticated social engineering campaign is targeting Web3 professionals under the guise of a legitimate AI-powered interview tool. SlowMist, a leading blockchain security firm, has identified a custom information-stealing malware disguised as 'Relay' meeting software, distributed through fake recruiter profiles. The attack exploits the growing trend of remote hiring in the crypto industry, aiming directly at the sensitive credentials that control digital assets. The discovery emerged from an ongoing threat intelligence operation. SlowMist’s analysts first noticed suspicious activity linked to job offers on platforms like LinkedIn. Attackers impersonated recruiters from well-known blockchain companies, engaging targets with convincing interview invitations. Once a candidate agreed to an online meeting, they were instructed to download 'Relay,' a seemingly functional AI-powered meeting application. In reality, the software contained a sophisticated trojan designed to harvest credentials, wallet files, and session tokens. Technical analysis reveals a well-planned cross-platform attack. The malware exists in both macOS and Windows versions, a sign of significant development effort. Upon installation, the trojan targets browser credentials, cryptocurrency wallet data, operating system keychains, and even Telegram session tokens. For macOS users, the malware exploits permissions granted during installation to access the keychain, where many users store private keys and passwords. On Windows, it scrapes browser databases and wallet file directories. The breadth of data collection indicates a clear objective: complete control over a victim’s digital identity and crypto assets. SlowMist has completed a full sample analysis and shared indicators of compromise with the wider security community. Their report details the malware’s persistence mechanisms, including attempts to disable security software and maintain access even after a reboot. The firm emphasizes that this is not a generic phishing kit; it is a custom-built tool tailored for the Web3 ecosystem. The attackers demonstrate deep knowledge of the crypto workflow — from wallet setups to Telegram-based project communication. The implications for the Web3 workforce are severe. Anyone who has applied for remote crypto positions or maintains active profiles on hiring platforms is a potential target. The stolen Telegram sessions are particularly dangerous, as they allow attackers to impersonate the victim within project groups, potentially launching secondary attacks on colleagues. If a victim’s wallet private key is compromised, funds can be drained within minutes, with little possibility of recovery. The attack leverages trust — the trust that a legitimate recruiter is real, and the trust that a meeting app is safe. From a market perspective, this event adds to the growing narrative of security risks in the crypto industry, especially as it intersects with artificial intelligence. The use of an 'AI meeting tool' as a lure exploits current hype around AI. This makes the scam more convincing, but it also paints a target on Web3 companies that rely on remote interviews. While there is no direct token price impact, the attack may influence sentiment, pushing users toward hardware wallets and more cautious online behavior. Security audit firms and hardware wallet manufacturers could see increased demand as awareness spreads. The broader ecosystem impact extends beyond individual victims. Hiring platforms like LinkedIn face reputational damage if they fail to curb fake recruiter accounts. Web3 projects may need to implement stricter identity verification for remote hiring, possibly using on-chain attestations or dedicated secure environments. Some might adopt ‘zero-trust’ interview protocols, where candidates are required to use isolated virtual machines. This could spark a new sub-industry of security-focused hiring tools — an opportunity for startups that bridge recruitment and cybersecurity. Regulatory attention is another potential outcome. While the attack itself is criminal, it highlights the vulnerability of the crypto workforce to identity-based fraud. Regulators in Hong Kong, Singapore, and the EU may view this as further evidence that the industry needs better protection for professionals. Mandatory two-factor authentication for wallet access on work devices, or even insurance policies covering social engineering losses, could emerge. The attack underscores the fragile link between digital identity and asset ownership in an industry that prides itself on decentralization. Looking ahead, threat actors are likely to refine this technique. The same social engineering blueprint could be adapted for conferences, airdrop events, or even regulatory compliance calls. Deepfake audio or video may soon replace simple text-based recruiter impersonation. The SlowMist report serves as a critical warning for both individuals and organizations. They urge all Web3 professionals to remain skeptical of unsolicited job offers, to verify recruiter identities through independent channels, and never to run unverified software on primary machines. Using a dedicated machine or virtual environment for interviews is a cheap but effective defense. This attack also reveals a structural weakness in how the crypto industry onboards talent. The reliance on mainstream platforms like LinkedIn, where account verification is minimal, creates an easy entry point for adversaries. While decentralized identity solutions exist, they remain niche. The gap between security best practices and daily operations is exactly what attackers exploit. The beauty of Web3’s permissionless nature becomes a liability when trust is manipulated. In conclusion, the threat is real, active, and likely to evolve. SlowMist’s disclosure gives the community a narrow window to strengthen defenses. The immediate takeaway is practical: harden your own setup, question every download, and assume that any unsolicited interview request could be a trap. For the industry, the longer-term challenge is to build hiring workflows that do not require blind trust. Until then, the echoes of this attack will linger in the quiet hesitation before clicking 'download.'

Market Prices

BTC Bitcoin
$64,713.7 +0.71%
ETH Ethereum
$1,912.24 +1.92%
SOL Solana
$74.05 -0.16%
BNB BNB Chain
$594.3 +0.00%
XRP XRP Ledger
$1.06 -1.13%
DOGE Dogecoin
$0.0701 -0.40%
ADA Cardano
$0.1915 -0.98%
AVAX Avalanche
$6.66 -0.61%
DOT Polkadot
$0.8406 -2.71%
LINK Chainlink
$8.15 -0.35%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{年份}}
30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

Market Cap

All →
1
Bitcoin
BTC
$64,713.7
1
Ethereum
ETH
$1,912.24
1
Solana
SOL
$74.05
1
BNB Chain
BNB
$594.3
1
XRP Ledger
XRP
$1.06
1
Dogecoin
DOGE
$0.0701
1
Cardano
ADA
$0.1915
1
Avalanche
AVAX
$6.66
1
Polkadot
DOT
$0.8406
1
Chainlink
LINK
$8.15

Tools

All →

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

🐋 Whale Tracker

🟢
0xf65e...76df
30m ago
In
1,343.71 BTC
🔵
0x5661...b96b
1d ago
Stake
4,648,631 DOGE
🟢
0xbc76...a943
6h ago
In
22,299 BNB

💡 Smart Money

0x7e8e...7975
Top DeFi Miner
-$0.1M
93%
0xb2df...ce13
Institutional Custody
+$4.5M
63%
0x6e0c...03de
Arbitrage Bot
-$1.6M
84%