The Fake AI Interview Trap: How a Custom Malware Is Draining Web3 Wallets
Over the past 72 hours, SlowMist’s threat intelligence team published a forensic breakdown of a new information-stealing campaign that targets Web3 professionals with surgical precision. The attack vector is disarmingly simple: a fake AI-powered meeting tool called "Relay" is being pushed via LinkedIn-style recruitment messages. Once installed, it exfiltrates browser credentials, crypto wallet keys, macOS keychain data, and Telegram session tokens. This is not a spray-and-pray phishing operation — it is a custom-crafted cross-platform malware designed to harvest the private keys of the highest-value targets in the industry. And based on my experience reverse-engineering similar campaigns during the 2021 NFT metadata break, the attack chain is already being weaponised against developers, founders, and traders who are currently interviewing for remote roles.
The context matters. Since early 2025, the crypto hiring market has been flooded with legitimate AI-assisted interview tools. Startups like "Relay" sound plausible — and that plausibility is exactly what the attackers are exploiting. We are in a period of consolidation markets, where capital is tight and talent is still scarce. The psychological pressure on job seekers to respond quickly, install a meeting tool, and prove their technical competence is being used as a Trojan horse. This is not a new technique; social engineering has been around since the dawn of phishing. But what makes this attack unique is the level of customisation. The malware is compiled for both macOS and Windows, uses obfuscation to evade endpoint detection (EDR), and specifically targets the data that Web3 professionals care about most: seed phrases, private keys, and Telegram sessions that hold access to project groups and OTC channels.
Let me walk through the core technical details. SlowMist’s analysis confirms that "Relay" is a multistage payload. The first stage is a legitimate-looking installer that mimics the UI of a professional meeting app. After the user grants permissions — including screen recording on macOS — the second stage drops a Python-based backdoor that scans for browser extensions associated with MetaMask, Phantom, and other hot wallets. It also dumps the contents of the macOS keychain, where many users store API keys and SSH tokens. On Windows, the malware targets the encrypted vaults of Telegram Desktop. The sophistication here is that the attackers are not just targeting wallet files; they are stealing the entire identity layer of a Web3 professional. Once they have a Telegram session, they can impersonate the victim in private group chats, extract further intel, and launch lateral attacks. From editorial desk to the bleeding edge of crypto, I have watched threat actors evolve from simple clipboard hijackers to this level of operational security. The 2026 AI-agent fraud exposé I published earlier this year showed a similar pattern: attackers test the market with a low-cost campaign, then pivot to higher-fidelity tools once they confirm the ROI.
But here is the contrarian angle that most analysts are missing. The danger is not the malware itself — it is the infrastructure of trust that the industry has built around remote hiring. Every Web3 company today posts job descriptions on X and LinkedIn, expects candidates to install third-party software, and rarely verifies the authenticity of the recruiter. The real vulnerability is the absence of standardised identity verification in the hiring pipeline. Unlike traditional finance, where background checks and corporate VPNs are mandatory, crypto startups are still operating with a permissionless mindset. This attack will not be stopped by better antivirus software. It will only be stopped when the industry adopts zero-trust job application workflows: requiring recruiters to prove their domain ownership via ENS, using ephemeral virtual machines for every interview, and mandating hardware wallet-only interactions. The same heuristic break that created the NFT metadata crisis — centralised gateways as a point of failure — is now repeating itself in hiring. The attack is not a flaw in the tool; it is a flaw in the economic model of trust in a pseudonymous industry.
The takeaway is stark. If you are a Web3 professional actively looking for a new role, assume that every unsolicited interview invitation is a potential infostealer campaign. Do not install any meeting software that is not from a verified domain with a public audit trail. Use a dedicated laptop or a sandboxed environment for all job-related communications. The blockchain industry prides itself on being permissionless, but permissionless does not mean trustless. The next time you click "Install" on a recruiter’s link, ask yourself: do you really know who is on the other side of the camera? Or are you about to hand them the keys to your entire digital empire?