A new wave of targeted attacks is sweeping through the Web3 job market, and it is not your typical phishing email. Over the past 48 hours, security firm SlowMist has uncovered a malicious campaign that weaponizes the promise of AI-powered recruitment to compromise the machines of blockchain developers, DeFi analysts, and crypto fund managers. The attack chain is chillingly simple yet devastatingly effective: impersonate a recruiter on LinkedIn, invite the target to a video interview using a fake AI meeting tool called 'Relay,' and deploy a cross-platform info-stealer that drains browser credentials, crypto wallet data, Telegram sessions, and even macOS Keychain secrets.
History repeats, but liquidity decides the tempo. We are seeing an old playbook—social engineering—rediscovered with modern tools. And in a bull market where talent is scarce and hiring is rushed, the tempo is set by a community that trusts too quickly.
The Anatomy of the Attack
According to SlowMist's analysis, the campaign began in mid-July 2025. Attackers created fake LinkedIn profiles posing as senior recruiters for well-known Web3 projects. After establishing rapport, they would send a calendar invite for a remote interview and request the candidate to download a 'Relay' application, described as an AI-powered meeting assistant that would analyze facial expressions and communication patterns.
What the candidate actually downloads is a sophisticated infostealer compiled for both macOS and Windows. Once installed, the malware performs the following: - Scans browser profiles for stored passwords, cookies, and autofill data. - Targets browser extensions for MetaMask, Phantom, and other popular crypto wallets. - Extracts private keys and seed phrases from local file systems. - Grabs Telegram session tokens, enabling the attacker to impersonate the victim in group chats and direct messages. - On macOS, it accesses the user's Keychain, which often contains API keys, SSH passwords, and exchange credentials.
My own experience auditing early ICOs in 2017 taught me that community trust is the most valuable asset—and the easiest to exploit. This attack preys on the eagerness of professionals to engage with legitimate opportunities, turning that trust into a vulnerability.
Why This Matters Beyond the Individual
This is not just another crypto phishing scam. It is a targeted, cross-platform assault on the very infrastructure of the Web3 workforce. The attackers clearly understand the industry's culture: fast hiring, remote-first, and heavy reliance on Telegram and browser-based wallets. By compromising a single developer, they gain access to the project's internal Telegram group, GitHub repositories, and possibly vault contracts.
Culture is the code that compels human adoption. But here, that culture—of openness and rapid trust—becomes the attack surface.
Market and Ecosystem Implications
While no specific token price has been affected, the psychological impact is real. Over the past 7 days, I have noticed a subtle shift in community chatter: skepticism around unsolicited job offers is rising. This is a good thing. However, the direct financial risk is concentrated on individuals who store significant funds in hot wallets or who manage treasury multisigs from their primary machine.

I see a familiar pattern from my 2022 bear market resilience work: once trust breaks, it takes months to rebuild. The affected individuals may face not only asset loss but also reputational damage if their Telegram account is used to phish colleagues.
The Contrarian Angle: What You Are Not Being Told
Most warnings will tell you to 'be careful' and 'verify the recruiter.' That is necessary but not sufficient. The real blind spot is that many Web3 professionals use their work machine for personal crypto trading. A clean interview machine is rarely enforced. Even if you are not applying for jobs, if you are active on LinkedIn or Discord, your profile could be scraped for a future wave of this attack.
Moreover, the attackers may be assembling a 'hit list' of high-value targets—fund managers with large portfolios, core developers with multisig access. The current campaign is likely a reconnaissance phase. The real theft may come weeks later, after trust has been fully established.
What You Should Do Right Now
Based on my experience managing a $2 million DeFi fund in 2020, I know that proactive isolation is the only reliable defense. Here is my checklist:
- Never install unverified software for any interview or collaboration. Legitimate companies use Zoom, Google Meet, or dedicated HR platforms—not custom tools.
- Use a dedicated hardware wallet for any significant holdings. Do not connect it to your daily laptop.
- Run all interviews in a virtual machine or a separate, clean operating system. Treat it as a disposable environment.
- Revoke Telegram session tokens immediately if you have recently downloaded any suspicious app. Go to Settings > Devices > Terminate all other sessions.
- Monitor your LinkedIn DMs for recruiter requests that seem too good to be true or that push you to download an unknown application.
Patience pays in crypto, but speed burns in security. Take an hour to verify before you participate.

The Future of Web3 Recruitment Security
This attack will accelerate the adoption of decentralized identity (DID) and credential verification in hiring. Projects like Veramo and Ceramic Network offer a way to prove professional background without relying on centralized platforms. I expect to see 'verified recruiter' badges using on-chain attestations within six months, similar to how ENS domains are now used for wallet addresses.
Meanwhile, security providers like SlowMist, Trail of Bits, and Halborn will see increased demand for enterprise-grade endpoint monitoring in Web3 companies. The narrative around 'AI tool abuse' will persist for months, especially as deepfake voice and video become part of the toolkit.
Final Thought
We are in a sideways market where chop is for positioning. This attack gives us a clear signal: position your security defenses now, because the next bull run will bring even more sophisticated social engineering. Trust is the currency of Web3, but it must be earned, not given freely.
History repeats, but liquidity decides the tempo. Right now, the liquidity of trust is draining fast. Keep yours safe.