InSerHappy

The Fake AI Interview Tool That’s Draining Crypto Wallets – SlowMist Exposes the Most Surgical Attack Yet

CryptoLeo Scams

Hook

Speed kills, but slow kills too in this game. SlowMist just dropped a bomb. A new breed of info-stealer, wrapped in the shiny promise of an “AI meeting tool,” is picking off Web3 professionals by the dozen. 2025, July 29 – the security firm published its sample analysis. The target? Your private keys, your browser credentials, your Telegram sessions. The infection vector? A fake job interview.

I’ve been in this industry since the ICO frenzy of 2017. I’ve seen spear-phishing evolve from Nigerian prince emails to pixel-perfect replicas of exchange dashboards. But this one feels different. It’s surgical. It’s exploiting the one thing crypto natives trust without hesitation: the promise of a better opportunity.

Context

The attack chain is deceptively simple. Threat actors impersonate real recruiters – likely from established Web3 companies – on platforms like LinkedIn. They initiate conversations, build rapport, then send a link to download “Relay,” an AI-powered meeting scheduler. The victim installs the application, thinking they’re one step closer to a dream job. Instead, they’ve just handed over the keys to the castle.

This isn’t a generic phishing campaign. The malware is custom-built, with separate binaries for macOS and Windows. It harvests browser-stored passwords, crypto wallet extensions, keychain data, and even Telegram session tokens. The attackers know exactly who they’re after: developers, traders, and DeFi power users who live in their browsers and hot wallets.

We bought the dip, but the floor kept dropping – and this time the floor is personal. The crypto community has long operated on a culture of openness and rapid hiring. “Get in fast, verify later” is a mantra that worked during the 2021 bull run. Now it’s a liability.

Core

Let’s break down the technicals. SlowMist’s analysis reveals that “Relay” is a signed application that, once launched, executes a multi-stage payload. On macOS, it abuses the accessibility permissions to read system-level keychains. On Windows, it hooks into browser processes to exfiltrate cookies and saved passwords for exchanges, wallet dashboards, and even corporate VPNs.

Based on my experience leading rapid-response threat intelligence at a major exchange during the 2022 crash, I can tell you that this level of cross-platform sophistication is rare. Most malware targets one OS. Building and maintaining two distinct codebases requires dedicated resources – likely a funded group, not a lone actor.

The stolen data includes: - Browser credential stores (Chrome, Brave, Firefox) - Wallet extension data (MetaMask, Phantom, etc.) – not just seed phrases but also encrypted vaults that are decrypted on the fly - macOS Keychain items - Telegram desktop session files (allowing attackers to bypass 2FA on Telegram)

Once the payload executes, it phones home to a command-and-control server. The attackers can then pull fresh data, inject new wallet addresses into clipboard monitors, and even push fake transaction approval popups.

Hype is the fuel, but fundamentals are the engine. And the fundamental here is simple: social engineering bypasses all technical security. You can have the most hardened hardware wallet, but if you install a malware app that reads your screen, your seed phrase is gone.

Where the yield is sweet, the risk is steep. The sweet yield here is the promise of a high-paying Web3 job. The steep risk is your entire portfolio.

Contrarian

Everyone is focused on the malware itself. But the unreported angle is the erosion of trust in the entire remote hiring pipeline for crypto. This attack isn’t just about stealing funds; it’s about poisoning the well of talent acquisition.

Think about it. Web3 companies already struggle to attract top engineers because of volatility and regulatory uncertainty. Now every candidate who receives a recruiter’s LinkedIn message will have to assume it could be a trap. The cost of this attack isn’t the few thousand dollars stolen from victims – it’s the millions in lost hiring efficiency and the chilling effect on legitimate recruiting.

Moreover, the timing is brutal. The bull market is humming, projects are scaling, and demand for talent is at a peak. Attackers know this. They’re exploiting the FOMO that drives both investment and job hunting.

I’ve seen the moon, now I’m looking for the exit – and this attack is a flashing red sign that the ecosystem’s security culture hasn’t matured fast enough. The contrarian take? The real killer isn’t the malware – it’s the broken verification layer. No one is verifying that the recruiter is who they say they are. KYC for job boards? Decentralized identity for hiring? Those conversations are starting now, but they’re years late.

Takeaway

What does this mean for your portfolio? Immediate action: freeze all hot wallet activity in your browser. Offload funds to a hardware wallet. Change your Telegram 2FA and rotate session keys. For the next 30 days, treat any unsolicited job interview request as hostile until you’ve verified the person through a video call using only known software (Zoom, Google Meet).

Longer term, the industry needs a standard for verified employment identity – something akin to ENS for hiring. Until then, the risk of a single malicious download wiping out years of gains is too high.

I’ll be watching for the next variation: deepfake video interviews. The attackers will evolve. Will your security habits?

Market Prices

Coin Price 24h
BTC Bitcoin
$62,422.1 -1.07%
ETH Ethereum
$1,841.32 -1.54%
SOL Solana
$71.25 -2.69%
BNB BNB Chain
$575 -2.21%
XRP XRP Ledger
$1.06 -0.94%
DOGE Dogecoin
$0.0690 -1.60%
ADA Cardano
$0.1719 +0.12%
AVAX Avalanche
$6.24 -3.35%
DOT Polkadot
$0.7694 +0.22%
LINK Chainlink
$7.97 -2.63%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

12
05
halving BCH Halving

Block reward halving event

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

28
03
unlock Arbitrum Token Unlock

92 million ARB released

18
03
unlock Sui Token Unlock

Team and early investor shares released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

🧮 Tools

All →

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$62,422.1
1
Ethereum ETH
$1,841.32
1
Solana SOL
$71.25
1
BNB Chain BNB
$575
1
XRP Ledger XRP
$1.06
1
Dogecoin DOGE
$0.0690
1
Cardano ADA
$0.1719
1
Avalanche AVAX
$6.24
1
Polkadot DOT
$0.7694
1
Chainlink LINK
$7.97

🐋 Whale Tracker

🔴
0x3c2b...678d
12h ago
Out
48,618 SOL
🔴
0xa34f...bf5a
5m ago
Out
3,235,004 DOGE
🔴
0x4227...1072
12m ago
Out
4,127,223 USDT

💡 Smart Money

0xa4f4...a0f3
Market Maker
+$3.9M
63%
0x2341...f5ae
Market Maker
+$1.9M
68%
0xc395...16b0
Experienced On-chain Trader
+$4.3M
65%