I didn't think I'd be writing about a recruitment scam in 2026. But here we are. Over the past 48 hours, SlowMist dropped a threat advisory that should make every DeFi trader, developer, and yield strategist pause. A new malware strain, disguised as an AI meeting tool named 'Relay', has been targeting Web3 professionals via fake job interviews. The result? Complete wallet compromise—browser credentials, keychain data, Telegram sessions, and private keys. Gone.
Alpha isn't found in yield farms anymore. It's found in your computer's security settings. And most of you are failing that check.
Context We're in a bull market—July 2025, crypto sitting near highs, hiring frenzy across protocols and hedge funds. The same frenzy that pads our portfolios also attracts threat actors. Attackers know that Web3 talent is desperate for the next big role. They exploit that. The 'Relay' malware is not a generic phishing PDF. It's a custom-built binary targeting both macOS and Windows. The lure? A recruiter reaches out on LinkedIn or Telegram, schedules an interview, and sends a link to download a 'secure AI meeting app'. That app is the payload. Once installed, it scrapes everything and exfiltrates via encrypted channels.
I've seen phishing kits before. This one is different. Cross-platform, stealthy, and specifically designed to extract crypto wallets like MetaMask, Phantom, and browser-based keychains. It also steals your Telegram session—meaning attackers can impersonate you to drain your contacts. The social engineering is precise. They don't ask for your seed phrase. They ask for five minutes of your time.
Core: The Technical Breakdown The attack chain is textbook social engineering, but the execution is what makes it dangerous. Based on SlowMist's sample analysis, the malware uses obfuscated code to evade static detection. It requests permissions for screen recording and accessibility services—on both macOS and Windows—under the guise of 'AI meeting features'. Once those permissions are granted, it runs a silent sweep.
Let's break down the data harvest: - Browser credentials: They dump all saved passwords from Chrome, Firefox, Brave, and Edge. - Wallet extensions: They scrape local storage of MetaMask, Phantom, Rabby, and other browser-based wallets. If your seed phrase isn't encrypted at rest, it's taken. - Keychain/iCloud Keychain: macOS users are particularly exposed because the malware requests access to the system keychain. - Telegram session files: This is the sleeper. They steal your tdata folder (Telegram's local session data). With that, they log in as you—no 2FA, no password. They can then message your contacts, including other job recruiters, to propagate the attack.
I don't need to tell you that once a private key is stolen, the funds are gone. There's no chargeback in DeFi.
While the headlines screamed 'AI Will Take Your Job', the real story is that AI is being used to take your assets. The market doesn't punish bad actors; it punishes the unprepared.
Contrarian Angle The typical advice is 'use a hardware wallet'. And yes, that protects your cold storage. But the risk here isn't just your long-term holdings. It's your active trading wallets—the ones you use for yield farming, for DCA, for arbitrage. Most yield strategists keep a hot wallet with significant capital for speed. That's the target.
The contrarian truth is that even if you never install the malware, your reputation is at risk. Attackers can use stolen Telegram sessions to impersonate you, message your network, and spread the same malware to colleagues. I've seen this play out in 2022 with the 'Rug Pull' social engineering waves. The multiplier effect is real.

The blind spot for most traders is the assumption that 'it won't happen to me'. We're battle-tested. We've survived Terra, FTX, and bridge hacks. But we're human. We check LinkedIn daily. We take meetings. That's the attack vector. You don't lose your keys by clicking a DeFi link—you lose them by trusting a fake recruiter with a polished LinkedIn profile and an AI buzzword.
Takeaway This is not a theoretical vulnerability. This is in the wild, active, and succeeding. Here's what I'm doing with my $2M yield strategy portfolio: - Never install unsolicited software. If a recruiter sends a binary, I ask for a video call via a known platform (Zoom, Google Meet). If they refuse, it's a red flag. - Use a dedicated device for interviews. I have a cheap laptop with nothing but a clean OS. No wallets, no browser extensions, no Telegram. I use it for one thing: talking to strangers about jobs. - Verify the recruiter's identity on-chain. If they claim to work for a protocol, check their official Discord or Twitter. Ask for a signed message. - Monitor Telegram. Change your session keys regularly. Use a separate Telegram account for professional networking.
The market doesn't care about your P&L if your wallet is empty. The real alpha right now isn't a yield strategy—it's operational security. Don't let a fake interview cost you everything.
See you on the other side of the bull run with your funds intact.