The Resume Trap: How a Fake AI Interview Tool Is Draining Web3 Wallets

SamEagle
GameFi

The code reveals what the pitch deck conceals. On July 29, 2025, SlowMist dropped a report that should make every Web3 professional pause before clicking ‘Accept Invitation.’ A new piece of malware, disguised as an AI-powered meeting tool called ‘Relay,’ is targeting job seekers in the crypto space. It’s not a phishing link. It’s a full-spectrum info-stealer that hits both macOS and Windows, and it’s already in the wild.

I’ve spent the last seven years auditing smart contracts and chasing zero-days. When I saw the attack chain, I stopped scrolling. This is not another rug pull. This is a surgical strike on the most trusted part of the hiring process: the interview.

The Context: Why the Bull Market Makes You Vulnerable

We are in the middle of a hiring frenzy. Every Layer 2, every new DeFi primitive, every AI-crypto crossover project is scrambling for talent. Recruiters flood LinkedIn with DMs. ‘Quick call to discuss your background?’ The next message contains a Calendly link and a request to download a ‘lightweight AI meeting assistant’ that supposedly transcribes, summarizes, and analyzes the conversation.

Smart contracts do not care about your narrative. But attackers care deeply about your trust curve. They know that a Web3 developer who has survived three bear markets is paranoid about on-chain scams—but still opens desktop apps from someone they believe is a recruiter. The Relay malware exploits exactly that gap.

SlowMist’s analysis reveals a custom binary that, upon installation, begins scraping browser-stored passwords, cryptocurrency wallet extensions, macOS Keychain data, and Telegram session tokens. It is not a script kiddie operation. The malware is cross-platform, signed with stolen or forged developer certificates, and communicates with a command-and-control server over encrypted channels.

The Core: A Systematic Tear-down of the Attack Vector

Let’s dissect the technical architecture. The malware delivers a standalone Electron app that looks and behaves like a legitimate meeting tool. When the victim installs it, the app requests microphone and camera permissions—standard for any conferencing software. But the real payload is a background process that does not terminate when the app closes.

We audited the soul, and it was hollow. The app’s UI is polished. It shows a fake loading screen, a simulated ‘connecting to AI transcription server’ animation, and then—nothing. The call never starts. The recruiter ghosts you. By then, your machine is owned.

The data harvested includes: - All browser-stored credentials (Chrome, Brave, Firefox, Edge) - Extension data from MetaMask, Phantom, and at least 12 other wallet providers - macOS Keychain entries (which often contain private keys and API tokens) - Telegram session files (allowing the attacker to impersonate you in DMs) - SSH keys and GPG keys

The attacker has no need for exploit chains. They bypass endpoint detection by operating inside the user’s trust boundary. Your antivirus will not flag it because it is not malicious in behavior until it phones home—and by then, your life is already exfiltrated.

Based on my audit experience, I can tell you this is a generational leap in targeted credential harvesting. Traditional spear phishing relies on the victim clicking a link and entering a password. This installs a persistent surveillance agent that captures secrets you did not even know were exposed—like your Telegram session, which can be used to send messages to your team asking for ‘emergency signatures.’

The Contrarian: What the Bulls Got Right

Let me pause and acknowledge the counter-argument. The bullish narrative around AI-powered hiring tools is not entirely wrong. AI transcription and meeting assistants genuinely improve productivity. Many legitimate startups—Otter.ai, Fireflies, Fathom—have proven the model. The attack does not invalidate the product category.

But reproducibility is the highest form of respect. The attacker did not invent a new technology. They weaponized the exact workflow that these startups evangelized: ‘Download our app, give it permissions, let it listen.’ The gap between narrative and implementation is now a liability.

The bulls assumed that if a tool is used by thousands of people and reviewed on Product Hunt, it must be safe. They assumed that Web3 professionals, who are technically literate, would not fall for a desktop binary. They underestimated how easy it is to clone a trustworthy experience.

The Resume Trap: How a Fake AI Interview Tool Is Draining Web3 Wallets

The attack also reveals a blind spot in the industry’s security posture. We spend millions auditing smart contracts, but we ignore the operating system layer. A hardware wallet protects your on-chain signatures. It does not protect against a keylogger that steals your mnemonic phrase when you paste it into a browser. It does not protect against a tool that reads your Keychain.

Logic is the only currency that never inflates. The bulls were right about the demand for AI-enhanced productivity tools. They were wrong to assume that the distribution channel—LinkedIn DMs, personal introductions—has any integrity.

The Takeaway: The Accountability Call

This is not a warning. It is a challenge. Every Web3 company that requires remote hires must now build a security protocol around the interview process. No more ‘just download this app.’ Use sandboxed virtual machines. Use disposable operating system instances. Verify the recruiter’s identity through a separate channel before accepting any software.

A bug in the contract is a feature in the exploit. The bug in this case is the assumption that your desktop is a safe environment. The exploit is a piece of software that does exactly what it claims to do—record your meeting—and then does what it does not disclose: steal your identity.

The next variant of this attack will incorporate deepfake video. The one after that will target mobile devices. The industry needs an immutable standard for verified meeting tools—one that cannot be spoofed.

The Resume Trap: How a Fake AI Interview Tool Is Draining Web3 Wallets

Until then, your safest move is to assume every interview request is hostile until proven otherwise. The cold, hard truth: if you install unknown binaries on the same machine that holds your seed phrases, you are not a victim. You are a participant in your own compromise.