New Recruitment Scam Targets Web3 Professionals with Fake AI Meeting Software, SlowMist Warns
0xLeo
A coordinated social engineering campaign discovered by blockchain security firm SlowMist on July 29, 2025, is specifically targeting Web3 professionals through fake job interviews. The attack leverages the growing trend of AI-powered meeting tools, luring victims to install a malicious application disguised as "Relay," an AI meeting assistant. Once installed, the malware exfiltrates sensitive data including cryptocurrency wallet credentials, browser-stored passwords, and Telegram session tokens.
The attack begins with a direct message on professional platforms like LinkedIn or Telegram. Posing as a recruiter from a legitimate crypto project, the attacker invites the target to a technical interview. The bait often includes a synthetic AI-generated voice or video call invitation to reduce suspicion. The victim is directed to download "Relay" from a cloned website that mimics a legitimate AI meeting tool. The malware is compiled for both macOS and Windows, indicating a sophisticated developer capable of cross-platform deployment.
SlowMist’s analysis revealed that the malware is a custom variant of an information stealer, not a commercially available remote access trojan. It uses runtime decryption to evade signature-based detection and employs a multi-stage execution chain. Initial infection drops a loader that checks for virtual machine environments; if none are detected, it proceeds to fetch the payload from a remote server. The payload then harvests data from the Keychain (macOS) or Credential Manager (Windows), browser profiles for Chrome, Firefox, and Brave, and any installed cryptocurrency wallet extensions such as MetaMask, Phantom, and Ledger Live.
"The actors have done their homework," reads the SlowMist report. "They understand the industry hiring process and have tailored the malware to maximize yield from high-value targets." The report also notes that the Telegram session theft is particularly dangerous, as it can give attackers persistent access to private work channels and enable secondary phishing attacks against colleagues.
This incident arrives at a time when the crypto job market is booming, with major projects expanding their teams and remote work standard. The use of AI tools in hiring has become normalized, creating a perfect storm for exploitation. Traditional security guidance—avoid clicking unknown links, verify software signatures—still applies, but the precision of the targeting demands a more structural response.
The immediate risk is catastrophic asset loss for any victim who uses a hot wallet or stores private keys on their computer. But the ripple effects extend further. Compromised Telegram accounts can be used to spread the same malware within trusted networks, amplifying the attack. For institutional investors, this type of event reinforces the narrative that crypto remains a high-risk environment for operational security. Every successful hack adds friction to the onboarding of large capital, which tends to demand institutional-grade custody and verification protocols.
From a macro-liquidity perspective, this attack does not directly impact Bitcoin or Ethereum spot prices, but it does affect the risk premium assigned to the sector. Incidents that compromise user security raise the bar for entry for traditional finance allocators. The approval of spot ETFs in the US earlier this year was not an end, but a threshold—it lowered one barrier but exposed another: the fragility of the self-custody model under social engineering pressure.
The contrarian angle here is that attacks like this may actually accelerate the adoption of hardware wallets and decentralized identity solutions. Each time a massive phishing campaign succeeds, the market revalues security infrastructure. Companies like Ledger and Trezor may see a short-term bump in sales. More importantly, the incident validates the business model of security firms like SlowMist, who are now indispensable intermediaries in the Web3 ecosystem. The market for on-chain threat intelligence and real-time fraud monitoring is likely to expand as projects seek to protect their hiring pipelines.
Regulatory implications are also on the horizon. While this is a criminal act, not a securities violation, regulators in the EU and US may cite such attacks as evidence that the crypto industry lacks basic consumer protections. The MiCA framework already mandates certain security standards for custodians; future updates could extend those requirements to any platform facilitating crypto employment. Mandatory identity verification for recruiters and audited video interview software could become compliance prerequisites.
The structural takeaway is clear: the security burden is shifting from individual caution to systemic solution. The era of "don’t click suspicious links" is insufficient when the link is part of a credible-looking job application. The ecosystem needs hardened, verified communication channels—perhaps based on zero-knowledge proofs or decentralized identifiers—to restore trust in remote hiring. Until then, every Web3 professional should operate as if their next interview invitation is a potential attack vector. Follow the liquidity of trust, not just the price chart. When trust erodes, liquidity vanishes. Structure remains.
For now, SlowMist advises all users to verify recruiter identities through multiple independent channels, avoid running any unverified software, and use separate dedicated devices or virtual machines for any interviews involving sensitive wallet access. The firm has published the full indicators of compromise (IOCs) on its GitHub, including file hashes and command-and-control domains, for integration into security monitoring tools.
This incident is a stress test for the resilience of the Web3 workforce. The response will determine whether the sector matures into a trust-minimized environment or remains vulnerable to the oldest trick in the book: a wolf in recruiter’s clothing.