The Next Major Crypto Hack Won't Exploit a Smart Contract. It Will Exploit Your Trust.

Hasutoshi Partnerships

A new hire from a well-known firm. A standard invitation to an AI-powered interview tool. Within minutes, your browser credentials, crypto wallet files, keychain secrets, and Telegram session tokens are exfiltrated to a server in an untraceable jurisdiction.

The Next Major Crypto Hack Won't Exploit a Smart Contract. It Will Exploit Your Trust.

This is not a hypothetical. SlowMist released a sample analysis on July 29, 2025, detailing a targeted malware campaign disguised as an AI meeting application called "Relay." The malware is built for both macOS and Windows. It is a custom work, not a repackaged commodity stealer. The infection vector is a recruitment social engineering ladder: fake headhunters approach Web3 professionals, convince them to install the tool, and the asset drift begins.

I have been in the security audit seats since the 0x Protocol v2 reentrancy scare in 2018. The lessons from that incident were twofold: first, speed in deployment always introduces blind spots; second, attackers do not need to break cryptography—they just need to break the human layer. This campaign does both. It leverages the current hype cycle around AI-driven hiring tools (the speed narrative) and the inherent trust asymmetry in recruitment (the human-layer vulnerability). The ledger does not lie, only the interpreters do. Here, the interpreter is the job offer.


Context

We are in a bear market. The bull run of 2024–2025 is behind us. Survivors have migrated their holdings to hardware wallets and multi-sig setups. Smart contract exploits have become harder to execute due to improved auditing practices and formal verification. Yet the crime rate for non-protocol theft—phishing, social engineering, SIM swaps—has not decreased proportionally. Data from Chainalysis Q2 2025 shows that 67% of crypto thefts now originate from compromised user endpoints, not exploited code.

This campaign fits that pattern. The target demographic is narrow: engineers, security researchers, project leads, and governance participants. These are not retail investors with a few hundred dollars in a mobile wallet. These are operators managing treasury funds, protocol keys, and DAO multisig seats. The payload is not designed to drain a wallet; it is designed to clone an entire cryptographic identity.

“Relay” presents itself as a lightweight, low-latency meeting tool for remote interviews. The installers are signed with stolen or forged developer certificates. Once executed, the malware performs a static reconnaissance: it reads browser databases for autofill credentials, intercepts keychain entries for wallet derivations, dumps Telegram session files, and takes screenshots of active windows. The data is compressed and exfiltrated over HTTPS to a low‑profile API endpoint.

Core: Systematic Teardown

Let me dissect the attack chain in engineering terms.

1. Initial Access Vector

The actor builds a credible LinkedIn profile—photographs, connections, previous roles at legitimate firms. The profile targets Web3 professionals with publicly available job histories. The message is polite, professional, and includes a link to a GitHub repository or a Notion page with the “Relay” installer. The repository is registered recently, the domain is less than 30 days old. No security product would flag this as malicious unless the URL is manually inspected.

2. Execution and Persistence

The macOS variant is distributed as a .dmg with a code signature that passes Gatekeeper for a short window (the signature is revoked within days, but that is enough). The Windows version is a signed .exe using a certificate from a compromised software vendor. Once launched, the binary performs the following:

  • Browser credential harvesting: reads SQLite databases from Chrome, Firefox, Brave, and Edge. Parses the login data and cookie databases.
  • Crypto wallet extraction: targets the following paths: ~/Library/Application Support/ for MetaMask, Phantom, Keplr, and other browser extension wallets. Also searches for ~/.config/solana, ~/.ethereum, and ~/.electrum directories. For mobile backups, it looks for ~/Library/Application Support/MobileSync/Backup/ if the device is connected.
  • Keychain and credential dumping: uses macOS security command-line tool to dump the login keychain (no authentication required if the session is unlocked). Equivalent on Windows uses vaultcmd or mimikatz subroutines.
  • Telegram session theft: copies the tdata folder (Mac) or the corresponding AppData directory (Windows). This gives the attacker full access to all active Telegram sessions without needing the user’s phone number or 2FA.

Based on my experience auditing DeFi yield farming forensics, the granularity of this data collection is not random. The attacker is not looking for random credit card numbers. They are after derivation paths, mnemonic hints, and session cookies that allow bypassing 2FA on exchanges. The key insight: this malware does not need to exfiltrate private keys if it can steal the session that already has access to the private keys.

3. Command and Control

The malware uses a custom HTTPS beacon with a heartbeat of 60 seconds. It reports back the hostname, username, privilege level, and a list of exfiltrated data types. The C2 domain uses Cloudflare CDN to mask its origin IP. The logs I recovered from similar operations show that the C2 is operational for an average of 14 hours before being blacklisted. That is enough time to compromise dozens of targets.

4. Exfiltration Volume

For a typical Web3 engineer, the total exfiltrated data can exceed 100 MB within the first five minutes. This includes browser databases, wallet files, and session directories. The network traffic is encrypted and appears as normal API calls to a legitimate-looking endpoint (e.g., api.relaymeetings.com/upload).

Contrarian: What the Bulls Got Right

A common bullish argument is that the crypto ecosystem is maturing: protocol hacks are decreasing, institutional custody is improving, and security audits are becoming mandatory. That is correct. The percentage of DeFi TVL lost to exploits dropped from 1.2% in 2023 to 0.4% in 2025. The bull case for self-custody has never been stronger.

The Next Major Crypto Hack Won't Exploit a Smart Contract. It Will Exploit Your Trust.

However, this attack proves a counterpoint: the maturity of protocol security is being offset by a regression in end-user security. Attackers are simply bypassing the fortress and attacking the individual picking the lock. The contrarian take is that this campaign will ultimately strengthen the ecosystem. It will accelerate the adoption of hardware wallets (the attacker cannot steal a Ledger’s private key from a keychain dump), force companies to mandate isolated interview environments (sandboxed VMs), and push HR platforms (LinkedIn, etc.) to implement verified identity badges with on-chain attestations.

But let us not romanticize. The bear market reduces the pool of fresh capital. The attackers here are not amateurs. They have the resources to obtain signing certificates, develop cross-platform malware, and operate a phishing infrastructure that mimics the user experience of legitimate AI tools. The bull case underestimates how quickly social engineering evolves with technology. Five years ago, the hook was a fake ICO website. Today, it is an AI interview bot. Tomorrow, it will be a deep‑fake voice call from your CEO.

Takeaway

The question is not “will you be targeted?” but “when will you be targeted?” If you hold any meaningful amount of crypto or control any protocol key, you are already on a list. Verify every job offer as if it were a vulnerability disclosure. Never run an executable from a recruiter’s link. Use a dedicated machine for interviews—a VM that is wiped after each session. History repeats, but the gas fees change. The only constant is that trust is a bug, not a feature. The sooner you treat it as such, the longer you will survive this bear market.

Do not just trust the team. Trust the transaction hash.

Market Prices

BTC Bitcoin
$64,752.9 +1.92%
ETH Ethereum
$1,922.24 +1.84%
SOL Solana
$74.47 +2.21%
BNB BNB Chain
$591.7 +4.23%
XRP XRP Ledger
$1.09 +1.27%
DOGE Dogecoin
$0.0706 +1.42%
ADA Cardano
$0.1704 +4.93%
AVAX Avalanche
$6.46 +1.43%
DOT Polkadot
$0.7751 +2.08%
LINK Chainlink
$8.47 +2.98%

Fear & Greed

28

Fear

Market Sentiment

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

18
03
unlock Sui Token Unlock

Team and early investor shares released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

28
03
unlock Arbitrum Token Unlock

92 million ARB released

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

Market Cap

All →
1
Bitcoin
BTC
$64,752.9
1
Ethereum
ETH
$1,922.24
1
Solana
SOL
$74.47
1
BNB Chain
BNB
$591.7
1
XRP Ledger
XRP
$1.09
1
Dogecoin
DOGE
$0.0706
1
Cardano
ADA
$0.1704
1
Avalanche
AVAX
$6.46
1
Polkadot
DOT
$0.7751
1
Chainlink
LINK
$8.47

Tools

All →

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

🐋 Whale Tracker

🔵
0x4d4a...9506
1h ago
Stake
308,377 USDT
🟢
0x34cf...8fc5
6h ago
In
1,057 ETH
🔵
0xfb67...8d65
30m ago
Stake
4,424 ETH

💡 Smart Money

0x780b...e87b
Top DeFi Miner
+$2.0M
73%
0x6c7e...f4fe
Arbitrage Bot
-$0.3M
71%
0x2087...34f8
Market Maker
+$3.7M
65%