Servit
Magazine

The Relay Trap: How a Fake AI Interview Tool Is Draining Web3 Wallets

Raytoshi

It started with a LinkedIn message. A recruiter, polished profile, years of crypto experience. They pitched a role at a top DeFi protocol. The interview was via 'Relay'—an AI-powered meeting app that supposedly analyzed communication patterns. Within minutes of installation, the malware had scraped browser credentials, exfiltrated wallet private keys, and cloned Telegram sessions. The code did not lie. The intent did.

SlowMist detected the strain on July 29, 2025. It is not a script kiddie exploit. It is a custom, cross-platform infostealer targeting macOS and Windows simultaneously. The attackers understood Web3 professionals: they knew that trust in recruitment processes is low, but ambition is high. They weaved a narrative around AI tools—the hottest narrative in crypto—to bypass skepticism. Complexity is often a disguise for theft.

Context: The Weaponization of Recruitment

The attack chain is deceptively simple. Threat actors create fake LinkedIn profiles posing as hiring managers from reputable Web3 companies. They send personalized messages with a link to download 'Relay,' a supposed AI tool for remote interviews. The executable is signed with a stolen certificate to bypass macOS Gatekeeper and Windows Defender. Once run, it drops a payload that performs the following: - Extracts passwords from Chrome, Firefox, Brave, and Safari. - Steals private keys from common wallets: MetaMask, Phantom, Ledger Live, and Exodus. - Dumps Telegram desktop session tokens for account takeover. - Harvests macOS Keychain credentials.

Based on my audit experience with 0x Protocol v2, I recognize the pattern: attackers exploit the weakest link in the security chain—human trust. The 0x incident was an integer overflow in code. This is a vulnerability in social engineering, but equally catastrophic. The code does not lie; intent does. The 'Relay' app has no legitimate AI function. Its sole purpose is exfiltration.

Core: Systemic Risk Forensics

Let me dissect the technical anatomy. The malware uses a modular architecture similar to the RedLine stealer but with enhanced persistence. It registers as a launch agent on macOS and a scheduled task on Windows. It communicates with a command-and-control server over HTTPS with encrypted payloads to evade network detection.

What makes this attack dangerous is not the malware itself—it’s the targeting.

The attackers did not blast random emails. They conducted reconnaissance. The fake recruiters had dozens of connections, posted relevant content, and engaged in industry discussions. They understood the hiring cycle: Q3 is when many teams expand. They knew that candidates rarely verify the authenticity of interview software because the recruiter’s profile appears legitimate.

This is a supply chain attack on human capital. By compromising a single professional, the attacker gains access to: - Internal project vaults (via stolen wallet keys). - Private Telegram groups where alpha and trade signals are shared. - Corporate credentials if the target uses the same password for work systems.

Ponzi schemes leave trails in the data. So do infostealers. SlowMist’s analysis identified the wallet addresses where stolen funds were consolidated. The blockchain remembers what humans forget.

Contrarian: What the Bulls Got Right

Some will argue this is simply an advanced phishing campaign—nothing new. They claim that anyone running unverified executables deserves the loss. That is technically correct. But it misses the point.

The bulls would say: 'This proves that the Web3 hiring process is robust if you follow basic opsec.' They emphasize that hardware keyboards and diligent verification can prevent compromise. They are not wrong. However, the attack exposes a structural vulnerability in the ecosystem: the reliance on centralized identity proxies like LinkedIn for trust verification.

Here is the contrarían insight: The attack succeeded because Web3 professionals have been conditioned to expect innovation. The 'AI interview tool' trick works because the industry constantly pushes new tools. The same mindset that embraces DeFi yields also embraces 'efficiency hacks' like AI-driven recruitment. This cognitive bias is a security hole. The more we demand seamless onboarding, the easier it becomes to slip malware into the pipeline.

Moreover, the attackers demonstrated a nuanced understanding of asset recovery impossibility. They did not target exchanges with robust KYC. Instead, they stole directly from hot wallets and Telegram sessions, which are pseudonymous by design. Once the funds move through a mixer, they are effectively gone.

Takeaway: Verify the Hash, Trust No One

The 'Relay' incident is not an isolated event. It is a preview of the next wave of attacks that will weaponize AI narratives for social engineering. The solution is not to abandon recruitment but to institutionalize zero-trust interview processes.

Projects should mandate that all interview software be audited by a third party or run in isolated virtual machines. Individuals must - Never run executables from recruitment links. - Use hardware wallets for on-chain activity. - Enable session-specific Telegram passwords.

Silence is the only honest ledger. The attackers are not silent anymore. They are embedding themselves in the recruiting workflow. Audit the edges, not just the center. The next candidate may not be a candidate at all.

This analysis is based on SlowMist’s public report and my own post-mortem reviews of similar threats. No positions held.

Market Prices

Coin Price 24h
BTC Bitcoin
$62,808.6 -0.26%
ETH Ethereum
$1,862.38 -0.45%
SOL Solana
$72.16 -1.56%
BNB BNB Chain
$577.6 -1.90%
XRP XRP Ledger
$1.06 -0.96%
DOGE Dogecoin
$0.0697 -0.14%
ADA Cardano
$0.1730 +1.70%
AVAX Avalanche
$6.34 -1.60%
DOT Polkadot
$0.7764 +1.56%
LINK Chainlink
$8.07 -1.36%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{年份}}
30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

28
03
unlock Arbitrum Token Unlock

92 million ARB released

🧮 Tools

All →

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$62,808.6
1
Ethereum ETH
$1,862.38
1
Solana SOL
$72.16
1
BNB Chain BNB
$577.6
1
XRP Ledger XRP
$1.06
1
Dogecoin DOGE
$0.0697
1
Cardano ADA
$0.1730
1
Avalanche AVAX
$6.34
1
Polkadot DOT
$0.7764
1
Chainlink LINK
$8.07

🐋 Whale Tracker

🔵
0x7da2...6b16
30m ago
Stake
2,245,724 USDT
🟢
0x8ac3...da39
12h ago
In
910.57 BTC
🔵
0x7863...9099
1h ago
Stake
44,220 BNB

💡 Smart Money

0x95e6...1ea6
Top DeFi Miner
+$0.3M
61%
0xb1bb...c33c
Market Maker
+$5.0M
75%
0xd7c7...c377
Institutional Custody
+$2.2M
62%