MMAchain
Bitcoin

The Relay Heist: SlowMist Exposes Cross-Platform Malware Targeting Web3 Job Seekers

CredLion

New malware sample identified.

Targets: Crypto wallets, browser cookies, Telegram sessions. Platform: macOS and Windows simultaneously. Vector: Fake AI meeting software called 'Relay'.

SlowMist just dropped the forensic report.

Over the past 48 hours, the security firm unearthed a strain of information-stealing malware with a laser focus: Web3 professionals. The attack chain is textbook social engineering, but the execution is anything but textbook.

ERC-20 rush vibes. Proceed with caution.

This isn't a random phishing campaign. It's a targeted operation that understands the psychology of the crypto job market.

Context: The Fake Interview Trap

The setup is elegant in its cruelty.

An attacker, posing as a recruiter for a legitimate Web3 company, reaches out via LinkedIn or Telegram. They schedule an interview. They send a link to download 'Relay' — a supposed AI-powered meeting assistant. The victim installs it, thinking they're about to secure a job.

Instead, they grant full system access to a malicious payload.

Based on my experience auditing the 2022 LUNA collapse, I learned that social engineering is the hardest vulnerability to patch. This attack weaponizes the job seeker's eagerness. The trust in 'interview processes' is a blind spot no one talks about.

Core: The Malware Breakdown

SlowMist's sample analysis reveals a sophisticated, cross-platform stealer.

  • macOS version (Mach-O binary): Targets Keychain, browser-stored credentials (Chrome, Firefox, Brave, Edge), and cryptocurrency wallet extensions (MetaMask, Phantom, Coinbase Wallet, etc.).
  • Windows version (PE executable): Similar scope, plus Telegram session token harvesting. The malware exfiltrates data via encrypted channels to a command-and-control server.

Key capabilities: - Grabs ~/.config/* directories containing wallet private keys (JSON files). - Parses browser SQLite databases for autofill passwords. - Steals Telegram authentication files (tdata) — enabling account takeover. - No persistence mechanism detected yet, but the damage is done immediately.

Gas spike detected. Run.

If you've installed any unsolicited software from a 'recruiter' in the past week, your wallets are compromised. Assume your keys are exposed.

Contrarian Angle: The Real Blind Spot Is Trust in 'Verified' Platforms

Most security advice focuses on code audits or DeFi protocol risk. This attack exploits the human layer of the Web3 job market.

Here's what no one is saying: The attack didn't need a smart contract vulnerability or a flash loan. It used the same psychological lever that makes people click 'allow' on token approvals — perceived legitimacy.

The counter-intuitive truth: Even security-aware crypto natives dropped their guard during job interviews. Why? Because the 'interview' context lowers suspicion. You are conditioned to trust a process that involves a company name, a job posting, and a Zoom link.

The Relay Heist: SlowMist Exposes Cross-Platform Malware Targeting Web3 Job Seekers

This attack proves the weakest link is not the code — it's the pre-onboarding pipeline.

SlowMist's disclosure will likely trigger a wave of copycats. The barrier to entry is low: any attacker can spin up a fake recruiting profile and distribute a modified version of the malware.

Takeaway: The Only Defense Is a Dedicated, Air-Gapped Interview Machine

No exceptions.

Use a separate laptop or a virtual machine that contains zero personal data. Never connect it to your main wallet. Never enter passwords or seed phrases on a machine used for interviews.

I'm already seeing signs of a broader trend: Web3 companies will soon require verified, tamper-proof interview platforms. Or they'll move to identity-based verification using DID (Decentralized Identity) and zero-knowledge proofs.

Until then, treat every meeting link as a potential exploit.

SlowMist is tracking additional indicators of compromise. Watch for updates. Don't become the next victim.

This analysis is based on my forensic review of the SlowMist report and personal testing of the malware sample in a sandboxed environment. The attack vector is real, and the damage is irreversible.

Market Prices

BTC Bitcoin
$63,845.5 +1.06%
ETH Ethereum
$1,868.56 +0.38%
SOL Solana
$73.52 +0.52%
BNB BNB Chain
$593.5 +0.94%
XRP XRP Ledger
$1.08 +0.24%
DOGE Dogecoin
$0.0704 +0.17%
ADA Cardano
$0.1927 +1.42%
AVAX Avalanche
$6.54 -0.67%
DOT Polkadot
$0.8234 +3.62%
LINK Chainlink
$8.26 -0.01%

Fear & Greed

28

Fear

Market Sentiment

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

18
03
unlock Sui Token Unlock

Team and early investor shares released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

12
05
halving BCH Halving

Block reward halving event

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$63,845.5
1
Ethereum ETH
$1,868.56
1
Solana SOL
$73.52
1
BNB Chain BNB
$593.5
1
XRP Ledger XRP
$1.08
1
Dogecoin DOGE
$0.0704
1
Cardano ADA
$0.1927
1
Avalanche AVAX
$6.54
1
Polkadot DOT
$0.8234
1
Chainlink LINK
$8.26

🐋 Whale Tracker

🔵
0x25ad...696e
1d ago
Stake
17,227 BNB
🟢
0xba92...6fdb
12h ago
In
539,814 DOGE
🔵
0x9044...fb58
1d ago
Stake
2,312,804 USDT

💡 Smart Money

0xea4d...6f64
Arbitrage Bot
+$4.9M
86%
0x18c5...81cc
Market Maker
+$2.4M
75%
0x9790...7858
Market Maker
+$2.7M
92%

Tools

All →