Gelalens

Market Prices

Coin Price 24h
BTC Bitcoin
$63,097.4 -1.04%
ETH Ethereum
$1,869.07 -0.92%
SOL Solana
$72.98 -1.10%
BNB BNB Chain
$579 -2.36%
XRP XRP Ledger
$1.06 -0.78%
DOGE Dogecoin
$0.0701 +0.56%
ADA Cardano
$0.1753 +2.45%
AVAX Avalanche
$6.35 -1.90%
DOT Polkadot
$0.7716 +1.30%
LINK Chainlink
$8.11 -1.83%

Fear & Greed

27

Fear

Market Sentiment

Event Calendar

{{年份}}
15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

18
03
unlock Sui Token Unlock

Team and early investor shares released

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

12
05
halving BCH Halving

Block reward halving event

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

Altseason Index

44

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$63,097.4
1
Ethereum
ETH
$1,869.07
1
Solana
SOL
$72.98
1
BNB Chain
BNB
$579
1
XRP Ledger
XRP
$1.06
1
Dogecoin
DOGE
$0.0701
1
Cardano
ADA
$0.1753
1
Avalanche
AVAX
$6.35
1
Polkadot
DOT
$0.7716
1
Chainlink
LINK
$8.11

🐋 Whale Tracker

🔵
0x3482...8010
6h ago
Stake
3,914 ETH
🟢
0x9f77...d751
1h ago
In
12,174 BNB
🔴
0x866e...c38d
5m ago
Out
24,081 SOL

💡 Smart Money

0xf617...f566
Market Maker
+$3.9M
88%
0x5383...9435
Market Maker
+$1.9M
66%
0xde04...71d0
Arbitrage Bot
+$1.1M
91%

🧮 Tools

All →
NFT

The Relay Trap: How a Fake AI Interview Tool Exposes Web3's Structural Trust Flaw

CryptoCobie
A fresh malware sample hit my desk this week. It calls itself 'Relay', an AI meeting software. The bytecode tells a different story. SlowMist flagged it—a social engineering attack targeting Web3 professionals. The installer masquerades as a recruiter's interview invitation. Once executed, it steals crypto wallet data, browser credentials, macOS keychain, and Telegram sessions. This is not a generic phishing wave. It is a precision strike on the people who manage digital assets. The attack chain is complete. The code is cross-platform. The impact is direct asset loss. During the ICO boom of 2017, I audited over 40 smart contracts for integer overflows. The principle then was simple: verify every line. Now the attack surface has shifted from code to trust. This Relay malware exploits the weakest link in Web3—the human's willingness to run unverified binaries. The attacker uses a plausible narrative: a job interview in an AI-powered tool. The narrative fits the bull market hype. The code does not. Context: The attack begins on platforms like LinkedIn. The recruiter profile is likely fake, built with stolen or generated data. The victim receives a link to download 'Relay', an AI-powered meeting assistant. The installer is a trojan—no actual meeting software. On macOS, it grabs Keychain passwords and browser cookies. On Windows, it searches for wallet files and Telegram session tokens. The payload exfiltrates via encrypted channels. SlowMist has released IOCs: file hashes, C2 domains, registry paths. The attack is not speculative; it is in the wild. Based on my experience modeling liquidation risks in 2020, I know that stress tests reveal hidden weaknesses. This attack is a stress test on the hiring layer of Web3. Core: Let me walk through the evidence chain. The malware's persistence mechanism is simple—it installs as a launch agent on macOS. It targets specific file extensions: .wallet, .dat, .json, .keystore. These are not random; they match the default wallet export files from MetaMask, Phantom, and Ledger Live. The attacker wants private keys. The Telegram session theft is equally dangerous. It allows lateral movement—the attacker can impersonate the victim in group chats, DM colleagues, and request additional access. In my 2021 NFT wash-trading analysis, I traced whale wallet clusters. The same pattern of trust exploitation applies here. The victims are not retail users; they are developers, analysts, project managers—people with privileged access to protocol treasuries or private keys. The signal is clear: Web3 is under a targeted credential harvesting campaign. The bytecode lies; the transaction log does not. But here the transaction log is irrelevant because the private key never hits the blockchain—it is stolen before any transaction occurs. This is the structural flaw. We audit smart contracts, we analyze on-chain data, we monitor mempools. But we ignore the pre-chain attack surface. The Relay malware exploits that blind spot. The market focuses on DeFi hacks and bridge exploits. Meanwhile, a simple trojan can drain a wallet with no code exploit at all. Contrarian: Most analysis will focus on the malware itself—its indicators, its detection. I argue the real vulnerability is the trust model of remote hiring. Web3 prides itself on decentralization and permissionless access. Yet the hiring process is centralized: a LinkedIn profile, an email, a Zoom link. No decentralized identity. No proof of credential verification. The attacker simply mimics a recruiter. This works because the bull market has increased hiring volume. The noise drowns out the red flags. Volatility is noise; structural flaws are signal. The structural flaw here is the lack of cryptographic identity verification for job applicants and interviewers. In the physical world, a badge or a reference check exists. In Web3, a fake profile is trivial to create. The market spends millions on smart contract audits but zero on social engineering audits. This attack will repeat. The next version will likely use deepfake audio or video. The data does not dream; it only records. And the record shows that human trust is the weakest perimeter. Takeaway: The next week demand for hardware wallets and sandboxed interview environments will increase. I expect security firms like SlowMist to receive more corporate contracts for social engineering testing. But the long-term fix is identity—on-chain attestations of professional credentials. Web3 companies should adopt Verifiable Credentials for HR processes. Until then, verify the execution path of every installer. Trust the hash, verify the hash. But also verify the human behind the screen. The bytecode lies; the transaction log does not. And neither does a LinkedIn profile.

The Relay Trap: How a Fake AI Interview Tool Exposes Web3's Structural Trust Flaw