Hook
Speed kills, but slow kills too in this game. SlowMist just dropped a bomb. A new breed of info-stealer, wrapped in the shiny promise of an “AI meeting tool,” is picking off Web3 professionals by the dozen. 2025, July 29 – the security firm published its sample analysis. The target? Your private keys, your browser credentials, your Telegram sessions. The infection vector? A fake job interview.
I’ve been in this industry since the ICO frenzy of 2017. I’ve seen spear-phishing evolve from Nigerian prince emails to pixel-perfect replicas of exchange dashboards. But this one feels different. It’s surgical. It’s exploiting the one thing crypto natives trust without hesitation: the promise of a better opportunity.
Context
The attack chain is deceptively simple. Threat actors impersonate real recruiters – likely from established Web3 companies – on platforms like LinkedIn. They initiate conversations, build rapport, then send a link to download “Relay,” an AI-powered meeting scheduler. The victim installs the application, thinking they’re one step closer to a dream job. Instead, they’ve just handed over the keys to the castle.
This isn’t a generic phishing campaign. The malware is custom-built, with separate binaries for macOS and Windows. It harvests browser-stored passwords, crypto wallet extensions, keychain data, and even Telegram session tokens. The attackers know exactly who they’re after: developers, traders, and DeFi power users who live in their browsers and hot wallets.
We bought the dip, but the floor kept dropping – and this time the floor is personal. The crypto community has long operated on a culture of openness and rapid hiring. “Get in fast, verify later” is a mantra that worked during the 2021 bull run. Now it’s a liability.
Core
Let’s break down the technicals. SlowMist’s analysis reveals that “Relay” is a signed application that, once launched, executes a multi-stage payload. On macOS, it abuses the accessibility permissions to read system-level keychains. On Windows, it hooks into browser processes to exfiltrate cookies and saved passwords for exchanges, wallet dashboards, and even corporate VPNs.
Based on my experience leading rapid-response threat intelligence at a major exchange during the 2022 crash, I can tell you that this level of cross-platform sophistication is rare. Most malware targets one OS. Building and maintaining two distinct codebases requires dedicated resources – likely a funded group, not a lone actor.
The stolen data includes: - Browser credential stores (Chrome, Brave, Firefox) - Wallet extension data (MetaMask, Phantom, etc.) – not just seed phrases but also encrypted vaults that are decrypted on the fly - macOS Keychain items - Telegram desktop session files (allowing attackers to bypass 2FA on Telegram)
Once the payload executes, it phones home to a command-and-control server. The attackers can then pull fresh data, inject new wallet addresses into clipboard monitors, and even push fake transaction approval popups.
Hype is the fuel, but fundamentals are the engine. And the fundamental here is simple: social engineering bypasses all technical security. You can have the most hardened hardware wallet, but if you install a malware app that reads your screen, your seed phrase is gone.
Where the yield is sweet, the risk is steep. The sweet yield here is the promise of a high-paying Web3 job. The steep risk is your entire portfolio.
Contrarian
Everyone is focused on the malware itself. But the unreported angle is the erosion of trust in the entire remote hiring pipeline for crypto. This attack isn’t just about stealing funds; it’s about poisoning the well of talent acquisition.
Think about it. Web3 companies already struggle to attract top engineers because of volatility and regulatory uncertainty. Now every candidate who receives a recruiter’s LinkedIn message will have to assume it could be a trap. The cost of this attack isn’t the few thousand dollars stolen from victims – it’s the millions in lost hiring efficiency and the chilling effect on legitimate recruiting.
Moreover, the timing is brutal. The bull market is humming, projects are scaling, and demand for talent is at a peak. Attackers know this. They’re exploiting the FOMO that drives both investment and job hunting.
I’ve seen the moon, now I’m looking for the exit – and this attack is a flashing red sign that the ecosystem’s security culture hasn’t matured fast enough. The contrarian take? The real killer isn’t the malware – it’s the broken verification layer. No one is verifying that the recruiter is who they say they are. KYC for job boards? Decentralized identity for hiring? Those conversations are starting now, but they’re years late.
Takeaway
What does this mean for your portfolio? Immediate action: freeze all hot wallet activity in your browser. Offload funds to a hardware wallet. Change your Telegram 2FA and rotate session keys. For the next 30 days, treat any unsolicited job interview request as hostile until you’ve verified the person through a video call using only known software (Zoom, Google Meet).
Longer term, the industry needs a standard for verified employment identity – something akin to ENS for hiring. Until then, the risk of a single malicious download wiping out years of gains is too high.
I’ll be watching for the next variation: deepfake video interviews. The attackers will evolve. Will your security habits?