The Relay Trap: Dissecting a Malware Campaign Targeting Web3 Professionals Through Fake Hiring

CryptoLion
Layer2

The data suggests a new attack vector has emerged, one that bypasses traditional smart contract exploits and targets the human layer directly. Over the past week, SlowMist disclosed a phishing campaign where attackers impersonate recruiters from legitimate Web3 projects. They invite targets to install an AI-powered meeting tool called "Relay." The tool is malware. It steals browser credentials, encrypted wallet data, macOS Keychain contents, and Telegram sessions. This is not a theoretical vulnerability. It is a deployed, cross-platform information stealer. I have traced the code logic through the available sample analysis. The attack chain is clean, precise, and deeply cynical. It exploits the one thing most security audits ignore: trust in a job offer.

Context: The Web3 hiring ecosystem has grown rapidly. Projects compete for talent, and remote-first culture means interviews happen over video calls. Attackers weaponize this norm. They create fake LinkedIn profiles, scrape real project information, and approach developers, researchers, and community managers. The bait is an invitation to install "Relay," presented as an AI meeting scheduler or note-taking tool. Once installed, the payload executes silently. It targets both macOS and Windows. The malware hooks into the user's browser to extract saved passwords and cookie databases. It reads the files associated with MetaMask, Phantom, and other browser-based wallets. It dumps the macOS Keychain. It exfiltrates Telegram local session files, granting the attacker persistent access to the victim's Telegram account without needing the phone number or 2FA code.

This is not a zero-day exploit in a cryptographic library. It is a social engineering attack that exploits insecure defaults in how professionals handle job applications.

Core: Let me dissect the technical mechanics based on the indicators shared by SlowMist. The malware is likely packaged as a legitimate Electron application. The "Relay" installer is signed? We don't know yet. But the execution flow is standard for this class of stealer. On launch, it spawns a hidden process that enumerates all running processes. It looks for Chrome, Brave, Firefox, Edge, and browsers based on Chromium. It then reads the SQLite databases that store saved credentials. For each login, it decrypts the password using the browser's local encryption key. On macOS, this key is stored in the Keychain, which the malware also dumps by abusing the security command-line tool. It searches for known wallet extension directories under the user's Application Support folder. For MetaMask, it copies the vault.json file—the encrypted backup of the seed phrase. The decryption key is derived from the user's browser password, which by default is synced across devices if they use password sync. The malware also targets Phantom, Backpack, and other browser-based wallets.

The Telegram attack is particularly insidious. Telegram stores its local session cache in a directory called tdata. The malware copies this entire folder. With the session data, an attacker can log in as the victim on any device, bypassing SMS or 2FA. They can then monitor the victim's chats, impersonate them to contacts, and pivot to further attacks within Telegram groups of Web3 projects. This is a classic supply-chain style attack on trust relationships.

Based on my audit experience with wallet implementations, I see a pattern: the security model of browser-based wallets assumes the host machine is trusted. That assumption is fragile. Here, it is shattered. The attack does not exploit a cryptographic weakness—it exploits the fact that private keys are stored where the user can access them, which is exactly where malware can access them too. This is the same structural vulnerability I traced in 2017 when auditing ERC20 token contracts: the interface is simple, but the failure modes are paved by misuse.

I have also benchmarked similar malware during my MakerDAO stress tests. In 2020, I simulated liquidation cascades where price oracle latency created a gap for arbitrageurs. The gap here is not time, but trust. The user's willingness to run an unsigned binary because it came from a job offer. The code logic is clear: the attacker invested in cross-platform development, evasion techniques, and multi-vector data exfiltration. The return on investment is the ability to drain hot wallets and compromise Telegram accounts.

Tracing the silent logic where value meets code.

Contrarian: The standard defensive advice is "don't click on unknown links" or "verify the recruiter." This advice is insufficient. The attackers here are sophisticated. They use real project names, real employee names, and realistic AI-generated meeting tools. A developer with two years of experience in Solidity, desperate for a job in a bear market, will install the tool. The blind spot is that the Web3 hiring process lacks a verified identity layer. Recruiters on LinkedIn are not authenticated by the blockchain. There is no cryptographic proof that a hiring manager's message is genuine. The ecosystem has built zero-knowledge proofs for scaling, but zero trust for human interaction.

I do not trust the doc; I trust the trace. In this case, the trace shows that the attacker used a common technique: hosting the malware on a domain that mimics a legitimate meeting service. The domain might have been registered only days before the attack. Yet the typical user does not check domain registration date or SSL certificate issuance history. The real surprise is that this attack has not been more common. The reason it happens now is timing: AI hype makes people trust AI tools. The narrative of "AI meeting scheduler" is plausible. The attack is a direct consequence of narrative-driven technology adoption without parallel investment in security training.

The contrarian angle is that the solution is not better antivirus. It is changing how identity is verified in professional interactions. Web3 hiring should adopt a form of decentralized identity (DID) where recruiters sign their invitations with a public key. Candidates can verify the signature on-chain. Until then, the recommendation for any Web3 professional is to use a dedicated, ephemeral virtual machine for every job interview invitation. Treat every recruiter contact as a zero-trust request.

When abstraction fails, the NFTs bleed value. Here, it is not NFTs but trust that bleeds.

Takeaway: This attack vector will not be a one-off. It will evolve. I predict that within six months, we will see variants using deepfake audio or video to simulate the recruiter during a live screen-sharing session. The malware will then ask the victim to type their seed phrase into a fake terminal or connect a hardware wallet under the pretense of verifying identity. The only defense is to decouple your valuable keys from the machine used for communication. Use hardware wallets for all significant funds. Assume any unsolicited job approach is an attack until proven otherwise. If a recruiter asks you to install a proprietary meeting tool, demand a standard Zoom or Google Meet link instead. If they refuse, walk away.

Dissecting the corpse of a failed standard. The standard here is the trust model of online professional networking. It has failed. The code is clear: human trust is the weakest link. Trace it. Patch it. Do not rely on the next audit report to save you. The only security that matters is the one you enforce on your own machine.

ZK proofs are not magic; they are math. But this attack is not about math. It is about psychology. And psychology does not have a cryptographic fix—yet.

Market Prices

BTC Bitcoin
$63,036.6 -1.24%
ETH Ethereum
$1,865.49 -1.15%
SOL Solana
$72.83 -1.07%
BNB BNB Chain
$582.4 -1.34%
XRP XRP Ledger
$1.06 -0.89%
DOGE Dogecoin
$0.0697 +0.30%
ADA Cardano
$0.1722 +1.59%
AVAX Avalanche
$6.33 -1.86%
DOT Polkadot
$0.7622 -0.17%
LINK Chainlink
$8.1 -1.90%

Fear & Greed

27

Fear

Market Sentiment

7x24h Flash News

More >
{{快讯列表(10)}} {{loop}}
{{快讯时间}}

{{快讯内容}}

{{快讯标签}}
{{/loop}} {{/快讯列表}}

Event Calendar

{{年份}}
28
03
unlock Arbitrum Token Unlock

92 million ARB released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

18
03
unlock Sui Token Unlock

Team and early investor shares released

Tools

All →

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$63,036.6
1
Ethereum
ETH
$1,865.49
1
Solana
SOL
$72.83
1
BNB Chain
BNB
$582.4
1
XRP Ledger
XRP
$1.06
1
Dogecoin
DOGE
$0.0697
1
Cardano
ADA
$0.1722
1
Avalanche
AVAX
$6.33
1
Polkadot
DOT
$0.7622
1
Chainlink
LINK
$8.1

🐋 Whale Tracker

🔴
0x96d2...2bc1
1h ago
Out
981 ETH
🔴
0xb75d...4b06
12m ago
Out
25,843 BNB
🟢
0x9646...f568
1d ago
In
3,304.90 BTC

💡 Smart Money

0x8350...62c0
Market Maker
+$3.1M
68%
0x7ae5...2060
Experienced On-chain Trader
+$3.6M
64%
0xf57a...7c0e
Arbitrage Bot
+$4.9M
67%