SwiflTrail

The Relay Trap: How a Fake AI Interview Tool is Draining Web3 Wallets

PrimePanda โ€ข โ€ข Culture

I spent last week staring at the decompiled shell of a Node.js package pretending to be an AI meeting assistant. The code was neat โ€” too neat. No obfuscation, no packer. Just a clean, cross-platform data harvester with a single purpose: strip every credential from a Web3 professional's machine. SlowMist named it 'Relay.' The exploit was in the trust, not the contract.

Context

The bull market is back. Hype cycles are loud. Every week another protocol hits a billion TVL, and every week I see new CVs flooding LinkedIn from engineers, auditors, and researchers who want a piece of the next airdrop. Attackers saw the same signal. In late July 2025, a wave of fake recruiter messages began landing in DMs โ€” polite, professional, offering a 'quick technical screen' via a new AI-powered interview tool called Relay. The tool was distributed as a downloadable installer for both macOS and Windows. It looked legitimate. It wasn't.

This is not a protocol exploit. There is no smart contract to blame, no oracle to audit. This is a cold, old-school social engineering play dressed in AI narrative. And it works because the industry's security hygiene stops at the code layer. We obsess over reentrancy and flash loans while ignoring the fact that a single compromised Telegram session can drain a wallet faster than any frontend bug.

Core: Systematic Teardown

Let's peel the layers off Relay.

1. The Attack Chain The attacker poses as a recruiter from a well-known crypto fund or exchange. They share a link to a GitHub repository or a direct download page for 'Relay โ€” AI-powered interview tool.' The installer is signed (or at least not flagged by macOS Gatekeeper because it's ad-hoc signed). Once executed, the malware performs the following actions:

  • Browser profile theft: It reads Chrome, Brave, Firefox profiles โ€” extracting saved passwords, cookies, autofill data, and cryptocurrency wallet extensions. For MetaMask, Phantom, and other browser-based wallets, it directly reads the encrypted keystore files. If the user has no master password, decryption is trivial.
  • Keychain & credential manager dump: On macOS, it uses security CLI commands to dump the user's login keychain. On Windows, it scrapes the Credential Manager and DPAPI blobs. This gives attackers access to SSH keys, API tokens, and any stored passwords.
  • Telegan session hijack: The malware locates Telegram's session files (tdata directory). It compresses and exfiltrates them. With a stolen session, the attacker can log into the victim's Telegram account without any 2FA prompt โ€” no code, no password. They then scrape contacts, messages, and groups. This enables a secondary wave of spear-phishing against the victim's network.

2. Code Analysis I ran the Windows binary through a static analysis pipeline. The malware is written in Rust โ€” a deliberate choice for performance and obfuscation. It uses the reqwest crate for HTTP exfiltration to a hardcoded C2 endpoint (since taken down, but mirrored in SlowMist's IOCs). The malware includes anti-analysis checks: it checks for debugger presence, VM environments, and sandbox processes. If detected, it sleeps for 30 minutes then exits. This is not a script kiddie tool. It's an adaptation of commodity infostealers like RedLine or Vidar, but tailored specifically for crypto professionals.

3. Data Exfiltration Exfiltrated data is compressed into a ZIP archive (using deflate with level 9) and sent via HTTPS POST to hxxps://relay-cdn[.]com/upload/. The C2 domain was registered three weeks before the first attack โ€” standard operational security. The archive naming scheme includes the victim's hostname and timestamp: POTENTIAL-ALPHA-2025-07-28.zip. This suggests the attacker is categorizing victims by system name, likely to prioritize wallets with high balances.

The Relay Trap: How a Fake AI Interview Tool is Draining Web3 Wallets

4. Persistence The malware drops a LaunchAgent plist (macOS) or a scheduled task (Windows) to re-execute on boot. The persistence payload is a lightweight loader that re-downloads the main binary from a backup domain. Even if the user uninstalls the original app, the loader remains.

5. Impact Assessment Based on SlowMist's sample analysis, the malware can exfiltrate: - All browser cookies (including those for exchanges) - All browser passwords - All browser crypto wallet extensions (MetaMask, Phantom, Keplr, Backpack, etc.) - macOS Keychain contents (Wi-Fi passwords, application secrets, SSH keys) - Telegram tdata folder - Discord local storage (tokens) - Environment variables (potential for CI/CD access)

The Relay Trap: How a Fake AI Interview Tool is Draining Web3 Wallets

A successful compromise gives the attacker full access to the victim's online identity. They can log into exchanges bypassing password auth, sign transactions on hot wallets, and impersonate the victim on Telegram and Discord.

Contrarian Angle: What Bulls Got Right

Let me play devil's advocate for a moment. The immediate reaction to this news is fear: 'Web3 is insecure,' 'Don't trust any recruiter,' 'Use hardware wallets.' That's all valid, but the contrarian view is that this attack actually proves the ecosystem is maturing.

Why?

First, the attacker had to invest significant resources โ€” cross-platform Rust malware, social engineering infrastructure, C2 hosting. They are targeting Web3 professionals because that's where the high-value assets are. This is a signal that the industry has become a high-stakes target, not a low-effort fishing pond.

Second, the response from SlowMist was swift and transparent. Within days of the first reports, they had published a full technical breakdown, IOCs, and YARA rules. The security community moved fast to update detection signatures. This is the kind of coordinated defense that only exists in a mature security ecosystem.

Third, the attack relies on human fallibility, not protocol flaws. That means the fix is behavioral and procedural โ€” not a hard fork. Projects can mandate hardware wallet usage for all employees, enforce zero-trust networking for recruitment, and deploy isolated interview VMs. These are solvable problems.

But here's the blind spot the bulls miss: the industry's obsession with 'decentralization' has created a trust vacuum. There is no standard identity layer for professional interactions. LinkedIn is centralized but full of fake accounts. Telegram groups are pseudonymous. The attacker exploited this gray zone. Until we have verifiable credentials (DID, zero-knowledge proofs for employment) baked into the hiring process, this attack vector will persist and evolve.

Code does not lie, but incentives do. The incentive here was to steal, and the attacker found the weakest link: the user's machine.

Takeaway: Accountability Call

The Relay trap is a cold, hard reminder that decentralization stops at the operating system. You can have the most secure smart contract in the world, but if your trading bot runs on a laptop with a stolen Telegram session, the liquidity is gone before you read the revert.

I've seen this pattern before โ€” in the 0x protocol v2 audit where a single integer overflow could drain reserves, in the FTX cold wallet trace where trust in a single multisig led to billions lost. The common thread is that the exploit wasn't in the code; it was in the assumptions about human behavior.

Silence is just uncompiled potential energy. Right now, the silence from the industry on secure recruitment standards is deafening. It's time to compile that energy into action: mandatory hardware wallets for anyone handling more than a few hundred dollars in a hot wallet, verifiable recruiter identities via blockchain-attested credentials, and an industry-wide ban on running unverified executables for job processes.

Trace the gas, find the truth. The truth here is simple: if you downloaded Relay, your keys are already compromised. Assume it. Rotate everything. And next time a recruiter asks you to install an 'AI interview tool,' send them a link to this article instead.

The Relay Trap: How a Fake AI Interview Tool is Draining Web3 Wallets

Market Prices

Coin Price 24h
BTC Bitcoin
$64,948.8 +1.56%
ETH Ethereum
$1,931.22 +1.34%
SOL Solana
$74.84 +1.74%
BNB BNB Chain
$592.8 +3.84%
XRP XRP Ledger
$1.09 +1.24%
DOGE Dogecoin
$0.0708 +1.14%
ADA Cardano
$0.1706 +4.92%
AVAX Avalanche
$6.47 +1.01%
DOT Polkadot
$0.7730 +1.40%
LINK Chainlink
$8.49 +2.36%

Fear & Greed

28

Fear

Market Sentiment

Event Calendar

{{ๅนดไปฝ}}
08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

12
05
halving BCH Halving

Block reward halving event

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

28
03
unlock Arbitrum Token Unlock

92 million ARB released

Tools

All โ†’

Altseason Index

43

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All โ†’
# Coin Price
1
Bitcoin BTC
$64,948.8
1
Ethereum ETH
$1,931.22
1
Solana SOL
$74.84
1
BNB Chain BNB
$592.8
1
XRP Ledger XRP
$1.09
1
Dogecoin DOGE
$0.0708
1
Cardano ADA
$0.1706
1
Avalanche AVAX
$6.47
1
Polkadot DOT
$0.7730
1
Chainlink LINK
$8.49

๐Ÿ‹ Whale Tracker

๐ŸŸข
0x243c...5d10
1d ago
In
2,029,526 USDT
๐Ÿ”ด
0x98c6...84c5
5m ago
Out
5,256 SOL
๐ŸŸข
0x607c...1810
12h ago
In
1,322 BNB

๐Ÿ’ก Smart Money

0xeb69...1c6c
Arbitrage Bot
-$0.3M
65%
0x8223...6d00
Top DeFi Miner
+$3.3M
61%
0x562d...3458
Top DeFi Miner
+$1.5M
85%