Fake Recruitment Trap: Relay Malicious Meeting Tool Targets Web3

CN
1 hour ago

On July 29, 2026, the SlowFog security team released a security warning directly addressing recruitment scams: their MistEye system recently detected a new type of job scam targeting Web3 practitioners. The attackers masquerade as recruiters, actively reaching out to job seekers under the pretense of offering job opportunities and remote interviews, and casually introducing the excuse of needing to "install a meeting tool for easier communication," thereby luring the victims into installing a so-called "AI meeting tool" named Relay. However, SlowFog revealed that Relay is actually malware that can run on macOS and Windows, and once executed, it will quietly steal browser credentials, encrypted wallet-related information, sensitive data from the system Keychain, and Telegram chat contents in the background. For Web3 practitioners, who heavily rely on browser wallets, desktop wallets, and Telegram communities, this means that not only can their cryptocurrency assets on various public chains be stolen without their knowledge, but their personal or team Telegram accounts could also be hijacked to continue spreading similar scams. Unlike traditional attacks targeting contracts or protocol layers, this attack chain enters through "recruitment - remote interview - tool installation," almost perfectly fitting into the daily workflow of the industry, striking at personal trust and operational habits without triggering technical defenses, posing a direct and realistic threat to wallet asset security and social account integrity.

How an apparently ordinary remote interview becomes a trap

For many Web3 practitioners, the story often begins with a direct message saying, "You are a great fit for our position." Someone claiming to be a recruiter adds you as a friend, and after a brief exchange, presents an opportunity for "senior engineer/researcher/operator," claiming they reached out specifically after reviewing your background. The process then unfolds in a familiar manner: requesting your latest resume, discussing past projects, asking your views on the industry, and even forwarding what appears to be a legitimate JD document, making the entire conversation rhythm align perfectly with the formal recruitment processes you've experienced before. When the other party proposes "arranging an online interview next, along with assessing your adaptation to collaboration tools," most people have already assumed that the other party is a trustworthy recruiter.

The real trap lies just after this step. The other party claims that the company uniformly uses a tool called Relay for "AI meetings," which can automatically record minutes, transcribe multilingual conversations, and sends a download link or installation package under this pretext, requiring you to install it in advance to attend the interview on time. Due to the psychology of "cooperating with the interview process," job seekers often do not view this as a safety issue but merely as a normal meeting preparation: clicking the link, installing the program, granting running permissions, all while thinking, "just get the tool installed to not waste HR and the interviewer's time." Misled into believing this is a meeting software for the recruitment process, the victim has completed the installation and running of Relay, handing over the judgment of "whether to trust this program" that should belong to the technical defenses to the carefully designed recruitment script of the opponent. SlowFog categorizes this entire sequence from job bait to remote interview to tool installation as a social engineering attack route specifically targeting Web3 practitioners.

What privacy and assets does the malicious Relay meeting tool steal?

When the victim clicks to open Relay, what truly starts running is not an "AI meeting tool" but a stealing program with a clear inventory of data. According to SlowFog, Relay can execute on both macOS and Windows, prioritizing the scourge of credentials like account passwords saved in browsers, capturing automatically logged-in websites, commonly used email accounts, and work platforms into its attack surface. For Web3 practitioners, even more fatal is its focus on collecting data related to cryptocurrency wallets, which may include mnemonic phrases, private keys, and even local data in browser wallet plugins. If these core keys are taken, the attackers essentially have the "master key" to the victim's assets across various public chains.

A more covert layer is the loss of system-level keychains and communication tools. The system Keychain often holds numerous account keys for operating systems and applications; once leaked, attackers have the opportunity to take over more service login identities step by step. If Telegram conversation data is stolen, the other party could directly impersonate the victim, using familiar avatars and chat records as cover, to continue spreading similar social engineering attacks within teams, project groups, or between candidates. The cross-platform capability means that regardless of whether the victim mainly uses Mac or Windows for their work, as long as they handle work communication and on-chain operations on this device, once Relay takes control of their wallet, their cryptocurrency assets across different public chains could potentially be transferred remotely at any time.

Why AI meeting tools and remote recruitment have become the best disguise

In recent years, the Web3 industry has been a typical representative of "remote first," with teams distributed globally, and nearly all recruitment steps have moved online: from initial communication to technical interviews, task demonstrations, and even daily collaboration after joining, relying on video conferencing, screen recording, and various collaboration plugins. For candidates, the phrase "please install our commonly used meeting/demonstration tool to improve the interview effectiveness" has become completely normal; many even habitually install new clients as guided by the other party, as long as they can smoothly share screens and run demos, there is little questioning of the security details behind the tools.

The rise of AI narratives further reduces the suspicion of such requests. AI summarizing meeting minutes, automatically translating statements from international team members, and intelligently recording key points of interviews—all these functions sound entirely reasonable in the remote collaboration scenes of Web3. This attack chose to package Relay as an "AI meeting tool," precisely at the intersection of the hot narratives of AI + Web3: it aligns with technological trends and meets the real needs of multinational teams for "smart meeting assistants." SlowFog emphasizes that the attackers seized upon the now routinized request of "please install this tool for the convenience of the interview," causing victims to lower their guard amidst familiar recruitment processes and the seemingly professional language of AI tools, executing the step of running the malicious software as a necessary procedure to enter their desired positions, thereby making the combination of "AI meeting tool + remote recruitment" naturally a best disguise to break through the security defenses of Web3 practitioners.

MistEye warnings expose the weaknesses of the Web3 defense line

While "AI meeting tool + remote recruitment" is regarded by many as a workplace norm, the MistEye system under SlowFog has already sounded the alarm in the background. SlowFog disclosed that MistEye has recently continuously captured and identified this type of fake recruitment attack activity and issued a security warning on July 29, 2026: the attack chain starts with impersonating recruiters, requesting the installation of the "AI meeting tool" named Relay under the pretext of job opportunities and remote interviews. In reality, Relay steals browser credentials, cryptocurrency wallet-related information, system Keychain data, and Telegram conversations on the victim's macOS or Windows terminal, which SlowFog explicitly defines as recruitment scam attacks specifically targeting Web3 practitioners.

From the attack profile provided by this warning, it can be seen that the starting point of the entire attack chain is not the smart contract vulnerabilities we usually discuss, but rather the social engineering inducement revolving around recruitment scripts. What is truly targeted is not a specific public chain or protocol itself, but individual terminals and account systems. Once local wallet information is compromised, the victim's assets across various public chains could be directly transferred away. At this point, project-level audits, multi-signature mechanisms, and permission hierarchies virtually become ineffective, and the defense is directly bypassed to the "personal wallet" side. The alert from MistEye is like holding up a mirror: over the past few years, the Web3 industry has concentrated most of its security investments on on-chain technology and contract audits, while leaving huge gaps at the levels of "people" and "terminal devices," allowing social engineering in conjunction with terminal intrusion to become a new preferred path to circumvent on-chain security boundaries.

How to address job security in Web3 from individuals to teams

For individual practitioners, job searching and remote interviews themselves present high-risk scenarios; the first step is to regard "tools" as equally important as "positions": any meeting software that the other party strongly insists on installing must first undergo a reverse verification process: check whether the company’s official website, public recruitment information, and social accounts are consistent, whether the download link comes from an official channel, use mainstream meeting tools instead of replacing them with unknown "AI meeting tools," and definitely do not run unfamiliar installation packages for the sake of "urgent processes." Secondly, physically isolating assets from daily work is the baseline: according to industry-standard practices, daily browsing, Telegram chats, and cold wallet operations should be separated onto different devices to avoid logging into social accounts or being online for long periods on devices that store cryptocurrency assets. If accounts like Telegram are hijacked, attackers could continue replicating such recruitment scams using your identity within the circle. From a team perspective, companies need to "lock down" recruitment and onboarding processes: set unified communication channels and meeting tool whitelists for HR and interviewers, prohibit asking candidates to install software that has not been assessed by security teams in the name of personal authority, and complete necessary identity verification and device security alerts before issuing employment and onboarding materials. In current public materials, SlowFog reveals more about the attack chain and the types of data Relay steals, without authoritative statistics on the number of victims and the scale of losses. Moving forward, attention is warranted on whether other security institutions will gradually disclose similar cases and more details, and how many Web3 companies will incorporate this incident into their recruitment security norms; these two dimensions’ evolution will determine whether "fake recruitment + malicious meeting tools" will evolve into a new norm that the industry must combat in the long term.

Join our community to discuss and become stronger together!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata

免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。

Share To
APP

X

Telegram

Facebook

Reddit

CopyLink