The Silent Interview: How a Fake AI Recruiter Exploits the Trust Architecture of Web3 Hiring

CryptoIvy
Video

The silence in the order book is louder than the news feed. But today, the silence comes from a different source: the quiet installation of a malicious npm package disguised as a job interview tool. Over the past 72 hours, SlowMist’s threat intelligence team has uncovered a coordinated social engineering campaign targeting Web3 professionals. The attack vector? A fake AI meeting application named 'Relay.' The payload? A custom cross-platform information stealer that harvests browser credentials, cryptocurrency wallet data, Telegram sessions, and macOS Keychain entries. This is not a phishing email sent to 10,000 random addresses. This is a precision strike against the very people who build, audit, and trade in decentralized systems. The code does not lie, but it does not care—and this time, the code is a Trojan horse wearing a business suit.

To understand the gravity of this threat, we must first map the landscape it exploits. Web3 hiring has become a gravitational center for talent, especially during the current sideways market (July 2025). Projects are consolidating, and genuine recruitment is happening at scale. Attackers have infiltrated this pipeline by impersonating hiring managers on platforms like LinkedIn and Telegram. They initiate conversations, build trust, and then request candidates to install 'Relay' for a video interview. The application is not available on any official app store; instead, victims are directed to a cloned website that mimics legitimate AI meeting software. Once installed, the malware executes a dual-platform assault: it runs a .dmg on macOS and a .exe on Windows, both compiled with obfuscation and anti-debugging techniques to evade endpoint detection. The theft is silent and immediate—browser credential databases, wallet extension files (such as those from MetaMask, Phantom, and Ledger Live), Telegram session tokens, and system password databases are exfiltrated to a command-and-control server. Based on my own experience auditing ERC-721 contracts during the 2021 NFT mania, I recognize the sophistication here: the attackers did not just steal private keys; they stole the keys to the entire identity of the victim.

The core insight is that this attack exposes a fundamental flaw in the trust architecture of Web3 employment. We have spent years building trustless protocols for value exchange, yet we still rely on centralized, reputation-based platforms for hiring. SlowMist’s analysis reveals that the ‘Relay’ installer includes a signed binary on macOS, meaning it passed Apple’s notarization checks (though that could be a stolen or compromised developer certificate). The malware harvests data from over 20 browser profiles and specifically targets the ~/.config/ and ~/Library/Application Support/ directories where wallet files reside. In a single infection, an attacker can gain access to a user’s DeFi positions, NFT vaults, and Telegram contacts—the latter enabling a secondary wave of attacks against the victim’s network. The market impact is asymmetric: while the Bitcoin ETF narrative has dominated headlines with $50 billion inflows, these incidents chip away at the very trust that underpins self-custody. I wrote in my 2022 essay Liquidity as a Social Contract that crashes are not technical failures but collapses of trust. This is a micro-collapse, but it threatens to erode confidence in the entire remote-work infrastructure of Web3.

Now, the contrarian angle: The popular narrative will frame this as a security awareness problem—'don't install unknown software.' But that is a surface reading. The deeper truth is that this attack exploits a gap in the economic incentives of Web3 hiring. Projects are desperate for talent and often skip rigorous KYC for recruiters. Meanwhile, security companies like SlowMist profit from post-breach analysis, but few are investing in pre-emptive identity verification for hiring. The real blind spot is that we treat recruitment as a social layer separate from the technical stack. Decentralized identity (DID) solutions have been peripheral for years, but this attack vector provides a catalyst. Imagine a protocol where every job offer is signed by a recruiter's DID, verified on-chain, and the interview environment is a sandboxed container that cannot access host files. This is not a pipe dream; it is an economic necessity. Winter reveals who is building and who is waiting—and right now, the builders are the attackers, while the industry waits for the next victim.

The takeaway is both urgent and philosophical. The immediate recommendation is to never install software for a job interview outside of official channels—use a disposable virtual machine or a dedicated hardware device. But the long-term signal is clear: Web3 hiring must become trust-minimized. Every resume, every recruiter profile, every job offer should have an on-chain attestation. Until then, the code does not lie, but it does not care about your portfolio. It waits for a moment of trust, and then it takes everything. The question is not whether your next interview is safe—it is whether your industry will learn to build safety into its hiring DNA before the next wave of attacks arrives. Data whispers what the gatekeepers refuse to shout: the silent interview already happened, and some victims haven't noticed yet.