OfCosts

The Relay Trap: How a Fake AI Interview Tool Exposes the Fragility of Trust in Web3 Hiring

Credtoshi
Interviews

We trust because we must. In the decentralized world, trust is the currency that underpins every transaction, every smart contract, every promise of a better system. But what happens when that trust is weaponized? A new attack, uncovered by SlowMist and shared on July 29, 2025, reveals a chilling truth: the very tools we adopt to streamline remote work—AI-driven interview platforms—are being turned into precision instruments for asset theft. This is not a typical phishing email or a fake airdrop link. This is a surgical strike against the most vulnerable node in the Web3 ecosystem: the professional who believes they are walking into an opportunity.

The attack is deceptively simple. An applicant is contacted by someone impersonating a recruiter for a legitimate Web3 project. The conversation feels natural, the job requirements align with the candidate’s profile—after all, LinkedIn and social media profiles are scraped for context. Then comes the bait: a request to install an AI-powered meeting software called “Relay” to simulate an interview experience. The victim downloads the installer, and the trap snaps shut.

But this is no ordinary malware. According to SlowMist’s sample analysis, the “Relay” binary is a cross-platform infostealer targeting both macOS and Windows. Once executed, it quietly exfiltrates browser credentials, cryptocurrency wallet data, keychain contents, and Telegram session tokens. For a Web3 professional, this is a complete compromise: private keys, seed phrases, exchange logins, and even the ability to impersonate them in ongoing negotiations. The attack chain is not novel in technical sophistication—social engineering remains the oldest hack—but its precision and targeting reveal a new level of threat intelligence on the part of the attackers.

I spent the 2017 ICO boom auditing protocol code, and I saw how easily teams sacrificed security for speed. But this is different. This is a direct attack on the human layer, the one that no smart contract can protect. The attackers have studied their targets. They know that a Web3 native will instinctively trust an application branded as “AI” because we have been conditioned to see AI as a productivity boon. They know that the line between professional and personal digital life is thin—your hot wallet is likely on the same machine where you answer emails. They know that the interview process is a moment of vulnerability, where the desire to impress overrides caution.

Let me share a personal observation from my years in product management. I once led a security review for a lending protocol and discovered that the team’s Slack channel contained private keys shared in plain text. We fixed the code, but the cultural habit of trusting internal tools remained. The Relay attack exploits a similar blind spot: the belief that an installer from a supposed recruiter is safe because the invitation came through a trusted channel—LinkedIn, Telegram, or a professional network. The reality is that these channels are porous. Attackers can create convincing profiles, build rapport over days, and strike when the target’s guard is down.

The core insight here is not about the malware’s technical sophistication—it’s about the betrayal of the trust mechanism that powers Web3 hiring. Code betrays when we do. We, as an industry, have built systems that rely on cryptographic truth but ignore human truth. We tell users to “never share your seed phrase” but we do not tell them to “never install an untrusted binary from a recruiter.” The threat model has expanded, and our security education has not kept pace.

Now, the contrarian angle: some will argue that this is an individual responsibility issue—users should be more paranoid, use hardware wallets, run virtual machines for interviews. While these are valid mitigations, they shift the burden entirely onto the victim. The true weakness is systemic. Web3 hiring platforms—whether decentralized job boards or centralized networks like LinkedIn—lack robust identity verification for recruiters. Why is there no decentralized identity proof-of-attestation for job offers? Why can’t a recruiter demonstrate that they hold a verified role in a project via a DAO vote or a signed message? The industry has the primitives—DID, Verifiable Credentials, ZK proofs—but we have not applied them to the hiring process because we prioritize speed of hiring over security.

Consider the cost of this oversight. A single successful attack can drain years of savings, destroy a reputation, and trigger a ripple of secondary attacks as the stolen Telegram credentials are used to target other professionals in the same circle. The damage is not just financial; it is psychological. I know from my own experience during the 2022 crash that betrayal by the ecosystem leaves scars. When I saw the FTX collapse, I withdrew from public discourse for weeks. The erosion of trust is the most expensive tax on innovation. Burnout is the tax on innovation, but betrayal accelerates it irreversibly.

So what do we do? The immediate step is operational: verify every installer before running it. Use a dedicated, ephemeral machine or a sandbox for any interview software from unknown sources. Check if the recruiter has a verifiable on-chain presence—do they hold a governance token from the project they claim to represent? Is their email domain matching the project’s official site? SlowMist has shared indicators of compromise; check them. But longer-term, we need to design systems that embed trust into the hiring process itself.

The takeaway is not a warning; it is a call to build. We have the engineering talent and the financial incentive to create a secure hiring protocol. Imagine a platform where a recruiter must present a zero-knowledge proof of their role without revealing personal data, and where an interview tool is authenticated via a smart contract before installation. The technology exists; what is missing is the collective will. As I draft my manifesto on Human-Centric Decentralization, I see this as a test case. If we can solve trust in hiring, we can solve trust everywhere. But for now, if a recruiter asks you to install an unfamiliar AI tool, pause. Ask for a signed message from their project’s multisig. And remember: in a world where code is law, the weakest link is still the human heart.

Market Prices

BTC Bitcoin
$77,120 -1.99%
ETH Ethereum
$2,408.93 -2.46%
SOL Solana
$99.59 -3.63%
BNB BNB Chain
$679.6 -1.66%
XRP XRP Ledger
$1.34 -2.64%
DOGE Dogecoin
$0.0814 -2.00%
ADA Cardano
$0.1952 -1.91%
AVAX Avalanche
$7.19 -0.50%
DOT Polkadot
$0.8610 +2.92%
LINK Chainlink
$11.18 -1.33%

Fear & Greed

69

Greed

Market Sentiment

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

18
03
unlock Sui Token Unlock

Team and early investor shares released

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
# Coin Price
1
Bitcoin BTC
$77,120
1
Ethereum ETH
$2,408.93
1
Solana SOL
$99.59
1
BNB Chain BNB
$679.6
1
XRP Ledger XRP
$1.34
1
Dogecoin DOGE
$0.0814
1
Cardano ADA
$0.1952
1
Avalanche AVAX
$7.19
1
Polkadot DOT
$0.8610
1
Chainlink LINK
$11.18

🐋 Whale Tracker

🟢
0x87d1...7ae3
6h ago
In
26,880 SOL
🔴
0x6e77...f7c4
5m ago
Out
1,219,603 USDC
🟢
0x0c61...9198
1h ago
In
1,427 SOL

💡 Smart Money

0x1922...c6cd
Arbitrage Bot
+$3.1M
61%
0x7375...70f3
Market Maker
+$1.7M
78%
0x8e41...6768
Early Investor
+$4.1M
85%

Tools

All →