Market Prices

BTC Bitcoin
$62,985.2 +0.07%
ETH Ethereum
$1,854.8 -0.60%
SOL Solana
$72.53 -0.73%
BNB BNB Chain
$576.2 -2.11%
XRP XRP Ledger
$1.07 +0.25%
DOGE Dogecoin
$0.0696 -0.63%
ADA Cardano
$0.1754 +3.79%
AVAX Avalanche
$6.22 -2.77%
DOT Polkadot
$0.7918 +3.97%
LINK Chainlink
$8.15 -0.51%

Event Calendar

{{年份}}
28
03
unlock Arbitrum Token Unlock

92 million ARB released

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

18
03
unlock Sui Token Unlock

Team and early investor shares released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

💡 Smart Money

0x2591...5f01
Institutional Custody
-$2.8M
90%
0x6dfb...a18e
Early Investor
+$2.8M
65%
0x8621...6ead
Top DeFi Miner
+$2.1M
92%

🧮 Tools

All →
Events

The Fake AI Interview That Drains Your Wallet: SlowMist Exposes New Web3 Job Scam

CryptoStack

We didn’t see this one coming. Not like this.

You’re a Web3 professional. You get a LinkedIn message from a recruiter at a legit-sounding crypto firm. They want to interview you. They mention an AI-powered meeting tool called “Relay” — sounds cutting-edge, right? You download it. You run it. And just like that, your entire digital life is handed over to a stranger.

SlowMist just dropped the bomb: a precision-targeted social engineering campaign that exploits the very trust we’ve built in remote hiring. This isn’t a phishing link. This is a full-blown cross-platform information stealer disguised as an interview tool. And it’s already live.


Context: Why Now?

The bull market is euphoric. Hiring is hot. Every Web3 project is scrambling for talent. Attackers know this. They’ve watched the narrative shift toward AI-powered tools in recruitment. They’ve seen how desperate teams are to onboard fast. So they built a trap that plays on our hunger for opportunity.

This isn’t a random scatter-shot attack. It’s a surgical strike against the most valuable targets — developers, analysts, community managers who hold private keys, have access to Telegram groups, and manage treasury wallets. The victim profile: anyone who has ever said “I’m open to work” in crypto.


Core: The Anatomy of the Heist

Let’s get technical. The malware, detected by SlowMist’s security team, is custom-built for both macOS and Windows. That alone shows sophistication — most phishers don’t bother with cross-platform compatibility. But these attackers did their homework.

What does it steal?

Everything. Browser credentials — yes, that includes your password manager. Crypto wallet extensions — think MetaMask, Phantom, Keplr. Keychain/iCloud Keychain data. And, most devastatingly, Telegram session files. Why Telegram? Because that’s where Web3 deals get made. That’s where your private group conversations live. One compromised session lets the attacker impersonate you to your network, launching a secondary wave of attacks.

The delivery mechanism?

The “Relay” AI conference software. The recruiter sends a link. You download a DMG or EXE. The installer looks legitimate — even has a slick UI mimicking a real meeting scheduler. But underneath, it drops a payload that hooks into system processes. No antivirus flags it because it’s not a known strain. This is a zero-day in the social engineering playbook.

SlowMist’s sample analysis reveals the malware uses obfuscation to evade detection and likely employs persistence mechanisms — so even if you think you’ve deleted it, traces remain. The attacker can access your machine remotely, silently, for weeks.

— Root: The weaponized trust in “innovation”.

The AI interview narrative is the perfect Trojan horse. We’ve been conditioned to accept new tools as progress. When a recruiter says “we’re using a new AI meeting platform to streamline interviews,” our guard drops. We want to appear tech-savvy. We don’t question the download.

— s Demo: The fake “Relay” demo interface

The attackers even built a demo video showing how “Relay” works. It’s convincing. It’s polished. It’s a lie.


Contrarian: The Blind Spot Nobody Talks About

Everyone obsesses over DeFi hacks and smart contract vulnerabilities. But the real threat isn’t code — it’s the human behind the screen. This attack exposes a massive blind spot in Web3 security culture: we protect our on-chain assets but ignore our off-chain attack surface.

You use a hardware wallet? Great. But if your laptop is compromised, the moment you connect that Ledger and sign a transaction, your entire portfolio is at risk. The attacker doesn’t need your seed phrase if they can keylog your password or intercept the signed transaction.

The Fake AI Interview That Drains Your Wallet: SlowMist Exposes New Web3 Job Scam

The contrarian take: This attack isn’t about stealing coins. It’s about stealing identity.

By grabbing Telegram sessions and browser cookies, the attacker can become you. They can join your team’s private channels, read insider discussions, and then manipulate market-moving information. They can social-engineer your colleagues into sending funds to “your” address. The damage isn’t just financial — it’s reputational and operational.

We didn’t think about this. The industry has spent billions on securing protocols, but almost nothing on securing the job application process. The party doesn’t stop for security — it keeps dancing until someone gets robbed.


Takeaway: What You Need to Do Now

This isn’t a drill. If you’re job hunting in Web3 right now, your next move could be your last mistake.

The Fake AI Interview That Drains Your Wallet: SlowMist Exposes New Web3 Job Scam

  1. Isolate your interview machine. Use a dedicated laptop or a virtual machine for any unsolicited software installs. Never run new tools on your main workstation.
  1. Verify the recruiter. The attacker likely created fake LinkedIn profiles that mimic real employees. Cross-check via multiple channels — Twitter, Discord, email. If they insist on a specific software, search for its reputation. SlowMist just flagged “Relay” — if you see that name, run.
  1. Assume your Telegram is compromised. Change your session keys immediately. Enable two-factor authentication everywhere. And for the love of crypto, don’t store your private keys in any cloud-connected device.
  1. Watch for the afterwave. The attackers now have victim data. Expect follow-up spear-phishing targeting your network. SlowMist will likely release more IOCs (Indicators of Compromise) — update your threat feeds.

The next big question: Will this attack force Web3 companies to adopt secure interview protocols? Or will we keep hiring based on trust until the next disaster?

I’ve been in this space since the ICO boom. I’ve seen hacks, rugs, and exploits. But this one feels different because it targets the very human desire to belong and build. The bull market euphoria is masking a growing threat landscape. Don’t let a job offer become your exit scam.

Fear & Greed

27

Fear

Market Sentiment

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$62,985.2
1
Ethereum ETH
$1,854.8
1
Solana SOL
$72.53
1
BNB Chain BNB
$576.2
1
XRP Ledger XRP
$1.07
1
Dogecoin DOGE
$0.0696
1
Cardano ADA
$0.1754
1
Avalanche AVAX
$6.22
1
Polkadot DOT
$0.7918
1
Chainlink LINK
$8.15

🐋 Whale Tracker

🔴
0x150c...7359
6h ago
Out
3,455.16 BTC
🟢
0xe4c5...6934
1h ago
In
3,562,295 USDC
🔴
0xc9b1...2e0a
6h ago
Out
4,101 SOL