The Fake Interview That Steals Your Keys: Another Lesson in Social Engineering

PompFox
Research

The market is not pricing in the risk that your next job interview might be a malware delivery mechanism.

But SlowMist just published the code. And the code is speaking.

Context: On July 29, 2025, SlowMist’s threat intelligence team disclosed a new phishing campaign targeting Web3 professionals. The attack vector is simple yet surgical: attackers pose as recruiters from reputable crypto firms, invite the target to an “AI-powered interview” using a fake app called “Relay.” Once installed, the app is actually an info-stealer—cross-platform, with builds for both macOS and Windows. It harvests browser credentials, cryptocurrency wallet data, macOS keychain contents, and Telegram session tokens. The sample has been analyzed. The attack chain is confirmed.

This is not a protocol exploit. There is no smart contract bug. The vulnerability is the human being who wants a job.

Core: Why does this work? Because the narrative is calibrated for the current cycle. Bull markets hire. AI tools are the shiny new toy. Every Web3 founder is talking about integrating AI agents into their workflow. So a fake AI interview app fits perfectly into the user’s mental model. No red flags. Just a link and a .dmg file.

From my experience auditing Iconomi’s rebalancing algorithm in 2017, I learned that the most dangerous assumption in finance is that the process is legit because it looks professional. Iconomi had a polished whitepaper. This app has a polished UI. Both hid a structural flaw—one in liquidity fragmentation, the other in trust fragmentation.

The malware is also technically competent. It does not just scrape browser passwords. It targets specific wallet extensions by injecting malicious JavaScript into the browser context. It dumps Telegram’s session data to hijack the victim’s identity for further attacks. It captures macOS keychain entries—meaning it can exfiltrate private keys stored in Apple’s secure enclave if the user granted access. This is not script-kiddie work. This is a team that understands the Web3 stack from the OS level up.

Contrarian angle: Most security analysts will tell you to use hardware wallets and enable 2FA. That is necessary but insufficient. The real blind spot is that we treat “job interviews” as trusted interactions. In traditional finance, interview processes involve background checks, corporate HR systems, and verified email domains. In crypto, the entire process is pseudonymous. The recruiter could be anyone with a LinkedIn profile and a fake company logo.

Algorithms don’t get phished. Humans do. And in a bull market, humans get greedy for opportunity. The decoupling thesis—that crypto assets are becoming independent from traditional market cycles—fails here. This attack is a direct consequence of the macro liquidity environment: cheap money pumps hiring, hiring pumps social engineering surface area. The money printer does not just print tokens. It prints fake job offers.

Takeaway: The best hedge against this attack is not a security token. It is operational paranoia. Before running any executable from a recruiter, verify the person through an independent channel. Use a dedicated virtual machine for interviews. Never store private keys on a machine that runs third-party software.

Yield is just rent for your ignorance. In this case, the yield is the salary you thought you were getting. The rent is the entire contents of your wallet.

Exit liquidity is a social construct. The attacker is creating exit liquidity from your identity. Do not hand them the keys.

Based on my experience in the 2020 DeFi liquidity trap, I built a Python model to correlate Compound’s interest rates with Treasury yields. The insight there was that crypto does not exist in a vacuum. The same is true here: the attack surface is not just the code—it is the economic cycle that drives human behavior. In a bull market, trust inflates faster than token supply. And inflated trust always pops.

I expect this attack to mutate. Next will be deepfake video interviews—the recruiter’s face will be AI-generated, the voice cloned from a public podcast. SlowMist’s report is a warning shot. The question is whether the market will price in the risk before the next wave hits.