JackConsensus
BTC $65,065.5 +1.67%
ETH $1,932.98 +1.28%
SOL $74.92 +1.77%
BNB $594.1 +3.92%
XRP $1.09 +1.38%
DOGE $0.0709 +1.07%
ADA $0.1704 +4.93%
AVAX $6.47 +0.81%
DOT $0.7720 +1.26%
LINK $8.52 +2.42%
⛽ ETH Gas 28 Gwei
Fear&Greed
28

Red Flag: The New Web3 Hiring Scam That Steals Your Private Keys

SatoshiStacker Podcast

The Web3 hiring market just got a new threat. And it's not a fake job listing or a phishing email. It's a full-blown info-stealer that targets your wallet, your browser credentials, and your Telegram session in one click. SlowMist flagged a new malicious payload disguised as an AI meeting tool called 'Relay'. Cross-platform. Compiled for both macOS and Windows. The attack chain is complete: a fake recruiter invites you to an interview, sends a link to 'Relay', and the moment you install it, your machine is compromised.

This isn't a theoretical risk. SlowMist has the sample. They've dissected the code. The malware harvests browser-stored passwords, cryptocurrency wallet files, keychain data, and even active Telegram session tokens. A single misclick can drain your entire portfolio. The social engineering is precise: it preys on the hiring rush in crypto, where professionals eagerly accept interview requests from unknown recruiters.

Red Flag: The New Web3 Hiring Scam That Steals Your Private Keys

Context: why this matters now.

The attack surface is the human trust layer. Web3 has spent years auditing smart contracts, securing bridges, and hardening DeFi protocols. But the attacker just jumped over the wall. They're not attacking the chain. They're attacking the person behind the keyboard. The 'Relay' malware is a custom build, not a repurposed generic trojan. It specifically targets data that Web3 professionals treasure: wallet seeds, exchange API keys stored in browsers, and Telegram sessions that grant access to insider groups and OTC deal flows.

SlowMist's disclosure is a signal. They've published the indicators of compromise (IOCs) — file hashes, domains, and persistence mechanisms. But the damage is already done for victims who installed it before the warning. The attack vector is low-cost for the attacker: set up a fake LinkedIn profile, craft a convincing job description (Senior Solidity Engineer, DeFi Analyst, etc.), and send the interview link. The ROI is enormous. One successful hit can yield millions in stolen assets.

Liquidity doesn't flow to protocols with weak security. That's a crypto axiom. But here, the liquidity is inside your wallet, and the security hole is your trust. The attacker didn't need a 51% attack or a flash loan exploit. They needed a fake job offer.

Red Flag: The New Web3 Hiring Scam That Steals Your Private Keys

Core: the technical breakdown.

Let me walk you through the attack chain based on the available intelligence. First, the payload. It's a signed binary? Unclear from the report, but likely not signed with a legitimate Apple Developer ID or Microsoft Authenticode certificate — though attackers can steal or forge these. SlowMist's analysis shows the malware uses a layered approach: initial dropper, then a second-stage payload that establishes persistence.

The data exfiltration is aggressive. It scrapes: - Chromium-based browser cookies and saved passwords (Chrome, Brave, Edge). - Electrum, Exodus, and other wallet files from default directories. - macOS Keychain entries — which can include private keys, hardware wallet seed phrases if stored insecurely. - Telegram desktop session tokens — giving the attacker full access to the victim's Telegram account, including all chat history, groups, and channels.

The cross-platform aspect is critical. The attacker compiled two separate binaries. That requires non-trivial development effort. They didn't just clone a GitHub repo. This is a custom campaign aimed at high-value targets.

Arbitrage is the market's method of correcting inefficiency. The inefficiency here is the gap between how much trust we place in remote hiring and how little verification exists. Attackers are arbitraging that trust gap. They exploit the asymmetry: a recruiter can pretend to be anyone, and the candidate has no real-time way to verify identity or software legitimacy.

SlowMist's forensic work reveals that the malware communicates with a command-and-control (C2) server. The C2 domains are likely registered ephemerally. The stolen data is compressed and exfiltrated via encrypted channels. The attacker probably uses a mix of Telegram bots and pastebin-like services to exfiltrate.

But here's the deeper insight: the 'Relay' name is a double entendre. It plays on the trend of AI-meeting-tools like Otter.ai, Fireflies, and Grain. The attacker capitalized on the 'AI interview' buzz. This is social engineering with a timestamp — it exploits a real-time cultural meme.

Contrarian: the unreported angle.

Everyone is focused on the malware. But the real blind spot is the erosion of trust in remote hiring itself. If this attack becomes widespread, the natural response will be centralization: companies will demand background checks, ID verification, or even camera-on interviews. That's a step backward for a permissionless ecosystem. Web3's ethos of 'trustless' is about protocols, not people. But this attack proves that when human trust is a prerequisite (e.g., hiring), the trustless ideal fails.

The contrarian take: this is a leading indicator that the Web3 labor market will consolidate around reputation identity systems (like ENS with verified attestations) or zero-knowledge proof-based verification. Recruiters might need to prove they are who they say they are via on-chain identity. The alternative is worse — a return to centralized employer platforms that gatekeep access.

Also, note the timing. July 2025. The market is in a bull run for the bear: funding is flowing, projects are hiring. Attackers always follow the money. This scam is not the end. It's the prototype. Expect variants that use deepfake voice or video to simulate a real interview. The next version will ask you to share your screen — and that screen will reveal wallet balances.

Takeaway: what to watch next.

Don't install any software for an interview. That's the blunt rule. If a recruiter sends you a .exe or .dmg before even a first video chat, it's a red flag. Use a dedicated device or a virtual machine for any interview that requires software installation. The real threat isn't the scam itself — it's the complacency that allows it to work. Next watch: monitor SlowMist's IOC feed. If you see a new variant targeting Linux or mobile wallets, the attack surface expands. And if the stolen Telegram sessions are used to phish the victim's network, the damage becomes systemic.

The Web3 hiring boom just got a security tax. Pay it now, or pay it later with your private keys.

Market Prices

BTC Bitcoin
$65,065.5 +1.67%
ETH Ethereum
$1,932.98 +1.28%
SOL Solana
$74.92 +1.77%
BNB BNB Chain
$594.1 +3.92%
XRP XRP Ledger
$1.09 +1.38%
DOGE Dogecoin
$0.0709 +1.07%
ADA Cardano
$0.1704 +4.93%
AVAX Avalanche
$6.47 +0.81%
DOT Polkadot
$0.7720 +1.26%
LINK Chainlink
$8.52 +2.42%

Fear & Greed

28

Fear

Market Sentiment

Event Calendar

{{年份}}
22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

12
05
halving BCH Halving

Block reward halving event

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

7x24h Flash News

More >
{{快讯列表(10)}} {{loop}}
{{快讯时间}}

{{快讯内容}}

{{快讯标签}}
{{/loop}} {{/快讯列表}}

Tools

All →

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$65,065.5
1
Ethereum
ETH
$1,932.98
1
Solana
SOL
$74.92
1
BNB Chain
BNB
$594.1
1
XRP Ledger
XRP
$1.09
1
Dogecoin
DOGE
$0.0709
1
Cardano
ADA
$0.1704
1
Avalanche
AVAX
$6.47
1
Polkadot
DOT
$0.7720
1
Chainlink
LINK
$8.52

🐋 Whale Tracker

🔵
0x926d...ceac
12h ago
Stake
3,862.08 BTC
🟢
0x2080...252a
3h ago
In
3,760,741 USDC
🔵
0x482e...caa7
2m ago
Stake
5,362,052 DOGE

💡 Smart Money

0xc982...2175
Arbitrage Bot
-$2.1M
86%
0xb1cf...76d3
Market Maker
-$1.2M
70%
0xb569...d98c
Experienced On-chain Trader
+$1.0M
83%