The 'Relay' Trap: How Fake AI Recruiters Are Stealing Web3 Wallets in Plain Sight

CryptoLark
Reviews

Decoding the signal from the narrative noise. A new phishing campaign has been unearthed by SlowMist, and it's not the typical spam email or fake airdrop link. This one targets the very foundation of the bull market: talent acquisition. Attackers are posing as recruiters for top Web3 firms, inviting candidates to install an AI-powered meeting tool called 'Relay'—which is actually a custom information stealer designed to drain crypto wallets.

Let me be clear: this is not a theoretical vulnerability. SlowMist has already completed sample analysis and published the attack chain. As someone who spent 2017 auditing ICO whitepapers and later mapping DeFi incentive structures, I can tell you that the evolution from protocol-level hacks to human-level social engineering marks a dangerous new genre. The pivot point where genre defines value is now shifting from code to trust.

Hook: A Job Offer That Costs You Everything

On July 29, 2025, SlowMist released a threat advisory detailing a novel attack vector. The campaign masquerades as a legitimate hiring process: victims receive a LinkedIn message or email from someone claiming to be a recruiter for a prominent blockchain company. They are asked to download and run an installer for 'Relay,' an AI conference tool that supposedly tests their communication skills. The installer contains a trojan that targets both macOS and Windows. Once executed, it exfiltrates browser credentials, crypto wallet data, keychain entries, and Telegram session tokens—all the keys to a Web3 professional's financial kingdom.

During my due diligence sprint in the 2017 ICO frenzy, I saw teams with billion-dollar valuations that didn't even have a working product. Today, I see scammers who have perfected the art of pretending to be a team you'd want to join. The sophistication is staggering: the malware is cross-platform, the social engineering uses AI buzzwords, and the target selection is surgical. This is not a scatter-shot attack; it's a precision strike on the most vulnerable asset in crypto—the human operator.

Context: The Bull Market’s Hiring Fever

We are in a bull market. The narrative around AI and blockchain convergence is at a fever pitch. Every week, a new project raises tens of millions to build 'decentralized AI agents' or 'zero-knowledge machine learning'. Consequently, the demand for Web3 talent has exploded. Recruitment sites, Telegram groups, and LinkedIn are flooded with job postings. Attackers are simply following the liquidity of trust.

Based on my audit experience, I can confirm that the typical Web3 professional’s security hygiene is poor. Many use hot wallets for daily transactions, store private keys in plain text on their machines, and rarely verify the identity of remote recruiters. The 'Relay' malware exploits this exact gap. It does not break the blockchain; it breaks the human process that precedes the blockchain interaction.

Unearthing the logic within the speculative fog, I see a clear pattern: every bull market introduces a new class of social engineering attacks. In 2017, it was ICO whitepapers with fake team photos. In 2020, it was fake yield farming websites. In 2025, it's fake AI recruiters. The narrative evolves, but the underlying incentive remains: extract value from the person who holds the keys.

Core: Technical Anatomy of the 'Relay' Malware

SlowMist’s report indicates that the malware is not a repurposed commodity trojan but a custom piece of code. It uses obfuscation to evade signature-based AV detection. For macOS users, it likely requests accessibility permissions to read keychain data. For Windows users, it hooks browser processes to steal stored credentials and wallet extension files. The most concerning feature is its ability to capture Telegram session tokens—if a victim is a developer or influencer with access to multiple group chats, the attacker can pivot to target other individuals in the same community.

Let me break down the attack flow:

  1. Reconnaissance: The attacker builds a credible fake profile on LinkedIn or similar platforms. They study the target’s work history and align the job description with their skills.
  2. Initial Contact: A personalized message arrives, often referencing the target’s GitHub contributions or past projects.
  3. Payload Delivery: The target is directed to a polished website that mimics a legitimate AI startup. The 'Relay' installer is signed with a newly created developer certificate (likely stolen or forged).
  4. Execution & Exfiltration: The malware runs silently, scanning for filepaths of popular wallets (MetaMask, Phantom, Ledger Live, etc.), browser databases, and Telegram’s tdata folder. It then encrypts and uploads the data to a command-and-control server.
  5. Asset Drain: The attacker now has everything needed to transfer funds without triggering 2FA—session tokens bypass many security layers.

In my role as a narrative strategy consultant, I have seen this script before. During DeFi Summer, I analyzed how incentive structures artificially inflated user growth. Here, the incentive is the victim’s own greed for a high-paying crypto job. The attacker is simply trading on the narrative of career advancement.

Key technical signals for defenders: - The installer file names often contain keywords like "Relay_v1.2.dmg" or "Relay_Setup.exe". - The malware communicates with domains registered within the last 30 days. - It checks for the presence of VPN or sandbox environments to delay execution.

Contrarian: The Real Weakness Isn’t the Code—It’s the Culture

The mainstream crypto security discourse focuses on smart contract vulnerabilities, MEV bots, and cross-chain bridges. But the 'Relay' attack reveals an uncomfortable truth: the human layer has no audit. We celebrate permissionless innovation, but we also have permissionless deception. The same bull market ethos that encourages rapid hiring and blind trust in 'crypto native' professionals is the very fuel for this attack vector.

Most security research teams will tell you to use a hardware wallet and never share your seed phrase. That advice is necessary but insufficient. The 'Relay' malware does not ask for your seed phrase; it takes it. It does not care if you have a Ledger because the attacker can impersonate you in a Telegram group and convince a colleague to sign a malicious transaction.

The contrarian angle: We don't need better antivirus; we need better identity verification for remote interactions. Projects spend millions on smart contract audits but zero dollars on verifying the identity of the people they hire. The next generation of Web3 security will not be about protecting code, but about protecting context. Decentralized identity (DID) solutions and zero-knowledge proof-based credential verification could become the new standard for job applications. Yet, very few projects are building for this use case because it lacks the immediate liquidity exit of a DeFi protocol.

Based on my experience mapping liquidity in DeFi Summer, I can project that the market for 'secure interview platforms' will emerge within the next six months. The damage from this campaign will accelerate that trend. The pivot point is not technical; it's cultural. Once the community loses trust in LinkedIn-style recruitment, the narrative will shift to 'trustless hiring'—similar to how trustless trading gave us DEXs.

Takeaway: The Next Act of the Narrative Cycle

SlowMist’s disclosure is a warning shot. The 'Relay' malware is likely just the first wave. I anticipate copycat campaigns using deepfake audio or even real-time video spoofing within the next twelve months. The bull market will continue to attract talent, but also predators.

Building frameworks for the next narrative cycle requires us to treat every job offer as a potential attack vector until proven otherwise. The question every Web3 professional should ask themselves: Is the opportunity real, or is my wallet the real product?

As I wrote in my 2022 essay 'The Post-Hype Vacuum', bear markets kill weak projects; bull markets kill weak security habits. The 'Relay' attack is the latest symptom of a market that values speed over verification. The signal in the noise is clear: your next career move could be your last financial move. Decode accordingly.

Market Prices

BTC Bitcoin
$63,114.3 -1.03%
ETH Ethereum
$1,868.16 -0.58%
SOL Solana
$72.94 -0.95%
BNB BNB Chain
$579.5 -1.96%
XRP XRP Ledger
$1.06 -0.75%
DOGE Dogecoin
$0.0699 +0.40%
ADA Cardano
$0.1731 +2.37%
AVAX Avalanche
$6.36 -1.17%
DOT Polkadot
$0.7685 +1.16%
LINK Chainlink
$8.11 -1.84%

Fear & Greed

27

Fear

Market Sentiment

7x24h Flash News

More >
{{快讯列表(10)}} {{loop}}
{{快讯时间}}

{{快讯内容}}

{{快讯标签}}
{{/loop}} {{/快讯列表}}

Event Calendar

{{年份}}
28
03
unlock Arbitrum Token Unlock

92 million ARB released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

18
03
unlock Sui Token Unlock

Team and early investor shares released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

Tools

All →

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$63,114.3
1
Ethereum
ETH
$1,868.16
1
Solana
SOL
$72.94
1
BNB Chain
BNB
$579.5
1
XRP Ledger
XRP
$1.06
1
Dogecoin
DOGE
$0.0699
1
Cardano
ADA
$0.1731
1
Avalanche
AVAX
$6.36
1
Polkadot
DOT
$0.7685
1
Chainlink
LINK
$8.11

🐋 Whale Tracker

🔵
0x2718...e4cb
6h ago
Stake
5,660,375 DOGE
🔴
0x84ac...c3d9
1h ago
Out
935 ETH
🔵
0x77d5...dcad
1d ago
Stake
4,680 ETH

💡 Smart Money

0xcd45...c280
Experienced On-chain Trader
-$4.0M
60%
0xab3e...0fd4
Arbitrage Bot
+$1.5M
74%
0xd5b5...7e8d
Top DeFi Miner
+$3.9M
65%