On July 29, 2025, SlowMist published a chilling disclosure. A new malware campaign, disguised as an AI-powered meeting tool called "Relay," has been systematically draining the wallets and credentials of Web3 professionals across both macOS and Windows. The attackers posed as recruiters, weaving a narrative of opportunity—only to harvest private keys, browser data, and Telegram sessions. This isn't just another phishing scheme. It is a calculated assault on the trust architecture that underpins decentralized work.
Context
Social engineering has always been crypto's blind spot. From the 2020 Twitter hack to the recent wave of Discord wallet drainers, human psychology remains the weakest link. But this new attack vector signals an escalation. The attackers didn't target random users; they aimed specifically at individuals actively seeking employment in blockchain—developers, community managers, and analysts. By exploiting the growing buzz around "AI interview tools," they tapped into a narrative of convenience and innovation. The malware itself was no amateur job: it featured cross-platform compatibility, stealthy persistence mechanisms, and a broad theft scope covering keychains, browser credentials, and even Telegram session cookies. Code is law, but narrative is truth—and here, the attackers weaponized both.

Core
The technical anatomy reveals a sophisticated threat. According to SlowMist's sample analysis, the "Relay" installer contains obfuscated scripts that reach out to a command-and-control server post-execution. Once live, it begins exfiltrating: - Browser-stored passwords and cookies (Chrome, Brave, Firefox) - Encrypted wallet data from desktop clients (MetaMask, Phantom, etc.) - Apple Keychain entries on macOS - Telegram desktop session files (allowing attackers to impersonate victims in ongoing chats)
The attack chain leverages the victim's own authorization: by convincing them to click "Install" on a legitimate-seeming DMG or EXE, it bypasses traditional perimeter defenses. No zero-day exploit needed—just a well-crafted story. SlowMist's team highlighted that the malware uses domain fronting to evade network detection, a technique more common in nation-state operations. This shows that the line between advanced persistent threats and crypto-specific crime is blurring.
I have seen this pattern before. During the 2020 DeFi Summer, I audited liquidity pools that collapsed purely because the human—not the code—was the weakest link. The same principle applies here. Liquidity flows, but trust evaporates. The wallets being emptied are not just hot wallets; they're repositories of years of earned credibility. The real loss is not the money but the trust in remote work itself.
Contrarian
The prevailing narrative frames this as a security failure: "install suspicious software, lose everything." But that's too simple. The contrarian truth is that these attacks reveal a structural moral hazard in the industry's reliance on chain-of-identity. We trusted email verification, LinkedIn profiles, and Zoom calls. The pandemic normalized remote hiring, and Web3 doubled down on pseudonymous meritocracy. But pseudonymity is a double-edged sword: it protects privacy while enabling impersonation.
What if the solution isn't more antivirus software but a fundamental rethinking of credentialing? Decentralized identity (DID) and verifiable credentials (VCs) have been theoretical for years. This attack could be the catalyst that pushes companies to demand zero-knowledge proof of employment history, or even isolated virtual machines for interview sessions. The contrarian angle: the attack will ironically accelerate adoption of trust-minimized hiring protocols, turning a threat into an opportunity for the fledgling DID ecosystem.
Takeaway
Don't trade the chart; trade the story. The narrative here is evolving from "malware warning" to a broader reckoning with how we validate human relationships in a digital world. If you are a Web3 professional, take this as a call to action: never run an unverified executable, even if it comes from a recruiter with a polished LinkedIn. Use a hardware wallet for any funds you cannot afford to lose. And while you're at it, demand that your next employer proves their identity on-chain.
The ghost in the blockchain is not a bug in the code—it is our willingness to trust a story without verifying the teller.