Last Thursday, a colleague from a DAO I advise forwarded me a LinkedIn message that felt eerily familiar. A recruiter from a top-tier Web3 fund wanted to schedule a “quick compatibility call” via a new AI meeting tool called Relay. The link looked legitimate, the branding was polished, and the role description matched my colleague’s profile perfectly. Only a last-minute Slack check with me saved them from clicking the download button. That incident, combined with SlowMist’s public disclosure of a targeted malware campaign, underscores a quiet crisis that the crypto industry has been sleepwalking through: our trust architecture is being weaponized against us.
The attack vector is as simple as it is devastating. The perpetrator poses as a headhunter, often using stolen or AI-generated identities on platforms like LinkedIn. They target Web3 professionals—engineers, community managers, researchers—and invite them to a screening interview using a custom-built application, dubbed “Relay” in the most recent strain. The software masquerades as an AI-powered meeting scheduler but is, in reality, a cross-platform infostealer. SlowMist’s reverse engineering reveals that the malware targets browser credentials, crypto wallet data, macOS Keychain, and Telegram session tokens. The attackers are not casting a wide net; they are spear-phishing individuals with probable access to project treasuries, private keys, or sensitive DAO operations.
Code without compassion is cold. This phrase echoes in my mind every time I dissect an attack that preys on human connection and trust. We spend millions auditing smart contracts, deploying multi-sigs, and building insurance pools, yet we leave the front door wide open for social engineering dressed in professional attire. The Relay malware is chillingly competent—it works on both macOS and Windows, indicating a development team that understands the tooling of high-value targets. It collects Telegram sessions, which means an attacker can hijack not just your wallet, but your identity in the DAO’s internal channels. From there, they can initiate fraudulent proposals, impersonate core contributors, or drain community funds with minimal effort.
Let me ground this in my own experience. During the 2020 DeFi Summer, I helped design the governance structure for UnityDAO, a collective managing a $5 million treasury. We implemented quadratic voting and community calls to foster genuine ownership and to avoid whale dominance. But no amount of on-chain sophistication can protect against a compromised laptop. One of the most valuable lessons I learned from that period is that the human element is the most critical—and most fragile—layer of any decentralized system. If a core member’s device is compromised, the entire DAO is at risk, regardless of how elegant its smart contract logic is.
This attack is not an isolated incident; it is the logical evolution of a threat landscape that we have collectively ignored. For years, security experts have warned about the inadequacy of endpoint security in Web3. We have protocols that can withstand a 51% attack, but we have no protocol for verifying that the person on the other side of a Zoom invite is not a script-kiddie with a custom payload. The industry’s obsession with on-chain transparency has created a blind spot for off-chain manipulation. We preach “trust but verify,” yet we blindly trust job postings, LinkedIn profiles, and VC branding. The Relay incident proves that attackers are reading our playbook—they know that Web3 professionals are accustomed to rapid, remote hiring, and that we are eager to embrace AI tools that promise efficiency.
The contrarian truth is that our decentralized ethos may be making us more vulnerable. Centralized organizations have corporate IT policies, mandated antivirus software, and dedicated incident response teams. In contrast, many Web3 projects operate as loosely coordinated collectives where each member uses their own personal device. There is no CISO, no endpoint management, no mandatory security training. The very values that attract us—autonomy, flexibility, permissionless participation—create the perfect conditions for a targeted phishing campaign. We can design the most beautiful tokenomics, but if we fail to secure the human interface, we are building castles on sand.
I recall a conversation I had during the 2022 rebuild of Chicago’s crypto community. After the FTX collapse, many employees were traumatized and desperate for new roles. They accepted job offers from anyone who sounded legitimate. One former colleague lost $40,000 in ETH after installing a “HR onboarding tool” that turned out to be a rip-off of the same malware class we see today. At the time, I thought it was a one-off; now I see it as a canary in the coal mine. The Relay campaign proves that the attackers have industrialized this model. They are now automating the reconnaissance, the fake profile creation, and the malware distribution.
So what do we do? We need a paradigm shift in how we approach security. First, treat every unsolicited job offer with the same skepticism as a smart contract upgrade. Verify the recruiter’s identity through at least two independent channels. If a company asks you to install a proprietary meeting tool, that’s a massive red flag—legitimate firms use Zoom, Google Meet, or Telegram, not custom executables. Second, use dedicated, isolated environments for any work-related tasks. Spin up a clean virtual machine for interviews. Never run unaudited software on your primary device where your wallet keys reside. Third, push your DAOs to adopt security standards for member onboarding. At UnityDAO, we created a “digital hygiene” onboarding packet that included guidance on phishing, hardware wallets, and session token hygiene. We saw a 40% drop in support tickets related to account compromises within the first quarter.
A practical call to action: If you are a governance architect or community lead, include a mandatory workshop on social engineering reconnaissance in your next contributor onboarding. Teach your members how to inspect a recruiter’s digital footprint, how to check email headers, and how to use a sandboxed browser for unknown links. Consider building a decentralized reputation system for professional interactions. Imagine a Soulbound Token (SBT) for verified recruiters, issued by a trusted consortium of Web3 companies. The technical challenge here is not insurmountable—what we lack is the collective will to implement it. Yes, SBTs have been discussed for three years, precisely because no one wants their credit record permanently on-chain. But a voluntary professional credential, revocable and privacy-preserving, could be the answer we need.
The ultimate oracle is an educated community. During the 2025 “Values First” coalition I led, we negotiated with BlackRock’s venture arm to adopt transparency protocols before they could deploy capital into our DAOs. That experience taught me that institutional players are willing to meet security standards if the community demands it. We have the power to set the norms. We can require that all job interviews within our ecosystem use audited, open-source meeting tools, or at least tools that do not require installation.
My emotional response to this news is not fear, but a renewed sense of mission. We have built incredible technology—trustless settlements, programmable money, decentralized governance. But code without compassion is cold. If our compassion does not extend to protecting the most vulnerable point in the system—the human operating the computer—then we have failed. The Relay malware is a wake-up call that must echo across every Telegram group, every Discord server, and every DAO charter. Let us not wait for the next victim to tell their story. Let us build human-in-the-loop verification mechanisms and, more importantly, a culture of proactive security that makes these attacks obsolete.
In the garden of decentralized trust, social engineering is the weed that grows fastest. We can either ignore the weeds or invest in the tools and education to root them out. I choose the latter. Will your DAO do the same?