Advertisement
AD

Crypto Developer Dodges Hidden Malware After Clicking Fake Claude AI Link

Sun, 30/08/2026 - 14:27
A crypto developer narrowly escaped malware from a fake Claude AI link, only to find a poisoned backup file ready to reinfect his clean laptop.
Advertisement
Crypto Developer Dodges Hidden Malware After Clicking Fake Claude AI Link
Cover image via depositphotos.com

Disclaimer: The opinions expressed by our writers are their own and do not represent the views of U.Today. The financial and market information provided on U.Today is intended for informational purposes only. U.Today is not liable for any financial losses incurred while trading cryptocurrencies. Conduct your own research by contacting financial experts before making any investment decisions. We believe that all content is accurate as of the date of publication, but certain offers mentioned may no longer be available.

Google

Web3 project co-founder Numa Lunah nearly lost control of his digital assets after following recommendations from artificial intelligence.

Advertisement

The incident revealed a new cyberattack vector in which hackers inject hidden backdoors into AI skill configuration files, allowing them to reinfect computers even after a complete operating system reinstall.

Why a system reset failed to protect crypto wallets from malware delivered through Claude

The attack began while Lunah was setting up his work environment and asked Claude for a link to download a transcription app. The AI assistant provided an address that led to a phishing clone of the program's official website. 

HOT Stories
Ripple Pledges Significant Donation to Nepal XRP, Shiba Inu (SHIB), Stellar (XLM) and Bitcoin (BTC) Price Analysis for August 28: Moment Where Bulls Should Take the Lead

After the software was downloaded, an infostealer was silently installed on the developer's work laptop — malware designed to steal passwords, exchange credentials, and private keys from hot wallets.

Advertisement

You Might Also Like

The developer detected the compromise in time, isolated the device, and completely reinstalled the operating system.

However, the threat was not eliminated. While attempting to restore files from a backup, Lunah discovered changes to a SKILL.md document that he used as a personal style guide for AI.

Advertisement

The hackers had managed to modify the structure of the text file. When this configuration profile was integrated into any new, clean computer, the file automatically connected to the attackers' server, downloaded the infostealer again, and resumed collecting credentials. 

You Might Also Like

The incident caught the attention of NEAR Protocol co-founder, Illia Polosukhin. He warned about the critical importance of securing autonomous AI agent infrastructure and the growing number of campaigns using "context poisoning" tactics.

For Web3 developers, whose local machines are priority targets, this case changes the rules of cybersecurity. AI skill configuration files in .md or .json formats can no longer be treated as harmless text. They must be handled like executable code and thoroughly inspected before use.

Advertisement
Advertisement
Advertisement
Advertisement

Recommended articles

Our social media
There's a lot to see there, too
Advertisement
Advertisement
AD