The most dangerous code in Web3 right now isn't on-chain. It’s wrapped in a recruiting pitch.
On July 29, 2025, SlowMist’s threat intelligence team dropped a chilling report: a new piece of malware, disguised as an AI-powered meeting tool called "Relay," is systematically targeting Web3 professionals. The attack vector is deceptively simple—an unsolicited LinkedIn message from a fake recruiter, an invitation to install an "AI interview assistant," and within minutes, your browser credentials, crypto wallet data, macOS Keychain, and Telegram sessions are exfiltrated to a command server. Both macOS and Windows versions exist. The code is clean, the targeting is surgical, and the narrative is terrifyingly credible.
This isn't just another phishing campaign. It’s a semantic attack on the very trust fabric that makes Web3 recruitment work.
Context: The Narrative of Efficiency
Over the past twelve months, the crypto job market has undergone a quiet revolution. Remote-first hiring became the norm, and AI-powered tools—from resume parsers to virtual interview assistants—became the backbone of screening processes. Companies like Relay (the legitimate platform, not the malware clone) gained traction by promising to streamline technical interviews with real-time coding analysis and behavioral assessments. The narrative was simple: AI makes hiring faster, fairer, and more global.
Attackers are now exploiting that narrative. They clone the look and feel of legitimate tools, use stolen recruiter identities from real Web3 firms, and leverage the industry’s hunger for talent to lower defenses. The victim isn't a naive retail investor—it’s a senior Solidity developer, a DeFi researcher, a security engineer. People who know better. People who, ironically, are trained to question on-chain transactions but not off-chain trust.
I’ve seen this pattern before. In 2021, during the NFT boom, I tracked a series of "executive assistant" phishing scams that targeted high-value collectors. The technique was identical: leverage a trusted role, automate the social engineering, and focus on the gap between technical sophistication and human psychology. The difference now is the scale and the weaponization of AI as a narrative shield.
Core: The Mechanics of Narrative Arbitrage
Let’s dissect the attack chain. The attacker first profiles their target—likely from GitHub commits, conference speaker lists, or Telegram groups. They clone a real recruiter’s LinkedIn profile, often from a well-known Web3 company, and initiate a conversation. The pitch is standard: "We’re impressed by your work on X protocol; we’d love to have a quick chat to discuss a role." Then comes the hook: "To streamline the process, please install our interview tool, Relay AI. It's used by almost all Web3 firms now."
Once the victim downloads and runs the installer—.dmg for macOS, .exe for Windows—the malware deploys a series of data stealers. Based on SlowMist's sample analysis, the code harvests:
- Browser passwords and cookies (Chrome, Firefox, Brave, etc.)
- Crypto wallet extensions (MetaMask, Phantom, etc.)
- macOS Keychain entries (includes exchange API keys, VPN credentials)
- Telegram session files (enables account hijacking)
- Local text files and notes (likely for seed phrases)
This is not a generic info-stealer. It’s a custom tool built for one purpose: to drain the digital identity of a Web3 professional. The attacker doesn’t care about your Netflix password. They want your private keys, your Telegram access (to message your network), and your enterprise VPN credentials.
The narrative exploitation here is profound. The attacker sells a story—"AI makes hiring easier"—that aligns perfectly with the industry’s self-image. Web3 loves new technology, efficiency, and meritocracy. A tool that accelerates hiring is not suspect; it’s progress. The malware’s success directly correlates with how well it mimics this narrative. Decoding the narrative before the price reacts—in this case, the “price” is the user’s entire security posture.
Just as liquidity can be a mirror reflecting false confidence, this attack shows that trust, when leveraged as a narrative, becomes a vulnerability. The arbitrage lies in understanding human fear—the fear of missing a career opportunity outweighs the caution of running an unsigned binary.
From my own forensic analysis of similar attacks in 2022, I can confirm that the most effective social engineering always targets a genuine pain point. In FTX’s collapse, the narrative of “regulatory arbitrage” blinded investors to liquidity risks. Here, the narrative of “AI efficiency” blinds professionals to code integrity.
Contrarian: This Attack Actually Strengthens the Case for Decentralization
Counter-intuitively, this malware reveals why centralized trust models are failing. The attack relies on the fact that a recruiter’s identity on LinkedIn is fundamentally centralized—one hack of a profile and the entire trust chain breaks. The solution isn’t better antivirus software or corporate NDAs. It’s decentralized identity (DID) and zero-knowledge proof-based verification.
Imagine a future where every recruiter has a verifiable credential on-chain, signed by their employer’s DAO. The interview tool is a zero-trust application that runs in a sandboxed environment, authenticated by a hardware key. Your seed phrase never touches the operating system. The attack we’re seeing today is simply the growing pain of a transition from Web2 trust models to Web3-native security.
In that sense, the real story isn’t the malware—it’s the industry’s slow realization that the old tools (LinkedIn, Google Meet, Slack) are liabilities. The attacks will only get more sophisticated: expect deepfake video interviews within six months. The logic remains: break the centralized trust bottleneck, and you break the attack chain.
Takeaway: The Next Narrative Will Be About Defensive Identity
The attackers are already ahead. They will evolve. They will use stolen Telegram sessions to message the victim’s colleagues, impersonating them. They will use generative AI to mimic voices. The only sustainable defense is to build identity verification into the recruitment process at the protocol level.

So ask yourself: when a recruiter sends you a link to “install a quick tool,” is your trust in their profile or in the protocol? Illusions break; logic remains. The next wave of security innovation will not be about detecting malware—it will be about making trust programmable.

Who owns the attention? Follow the capital. Right now, the capital is flowing to security teams that understand narrative hacking. This article is a call to action for every Web3 professional: audit your interview process like you audit a smart contract. Because the next attack won’t just steal your keys—it will steal your reputation.