Crypto news

29.07.2026
12:10

A new threat: fake interview apps steal crypto wallets from Web3 professionals

SlowMist analysts have uncovered a new sophisticated campaign targeting Web3 professionals. The attackers pose as recruiters and suggest installing a special application for an interview. In reality, the victim launches malware that steals passwords and gains access to cryptocurrency wallets.

How the scheme works

The scammers contact job seekers and offer to discuss job details. After that, they direct the victim to a fake website that poses as an online meeting platform called Relay. The site looks convincing and promises features such as speech transcription, collaborative notes, and AI-based summaries.

Depending on the operating system, the user is asked either to drag a file into the terminal (macOS) or simply wait for the "Update" progress bar to fill (Windows). In both cases, this is a deception: the installer contains no application, but rather hidden malicious code. The user themselves launches a program that then disables built-in security warnings.

What the virus steals

The main goal is access to crypto assets and accounts. On macOS, the program displays a fake window requesting the system password, masquerading as an operating system prompt. The entered password is combined with the user's credential database, allowing the attacker to unlock the device's keychain.

The program is not limited to a single wallet. It steals passwords and cookies from browsers, password manager data, local Telegram files, and note contents. Targets include cryptocurrency wallet extensions such as MetaMask, Phantom, and Trust Wallet, and it also checks for the presence of Ledger Live and Trezor Suite.

The Windows version behaves even more aggressively: it establishes persistence in the system for automatic startup after reboot and scans browser extension memory for data to unlock wallets.

How to protect yourself

If you have only downloaded the program but have not yet run it, simply delete it and empty the trash. However, if the virus has already been executed, the situation is much more serious. Analysts advise immediately disconnecting the device from the network, but not restarting it, in order to preserve traces for investigation.

Passwords and access credentials will need to be changed from a clean device, and all active sessions in the browser and Telegram should be revoked. Special attention should be paid to crypto assets: if you used wallet extensions, create new wallets on a clean device and transfer your digital funds there. For an infected Windows computer, the most radical and reliable advice is to completely reinstall the operating system.

Expert comment from Cryptalist: This campaign is a vivid example of how social engineering and technical disguise combine into one of the most dangerous threats for the crypto community. Even experienced users can fall for it if they do not check every application before running it. I recommend always using hardware wallets to store significant amounts and never entering system passwords in applications that are not part of the operating system.