Don't Trust, Verify: Malicious AI Links Expose a Nightmare Reality for Crypto Industry Workers

cryptonews.ruPubblicato 2026-08-29Pubblicato ultima volta 2026-08-29

Introduzione

Generative AI is becoming increasingly prevalent, with professionals in the digital assets and blockchain space regularly using it. However, this makes them prime targets for attackers seeking to steal sensitive, often irrevocable, information. Refi Hub co-founder Numa Lunah recently reported being "hacked" through a malicious link sent in a chat with the AI model Claude, which appeared to be a legitimate transcription app download. The link installed malware that attempted to steal all his data. While Numa claimed no sensitive data was leaked—as he wiped and reinstalled his laptop's OS—he later discovered a corrupted `SKILL.md` file in his backups, disguised as a style guide. This file contained hidden instructions to reload the malware and steal credentials whenever the AI accessed it. This incident highlights a new attack vector: LLMs providing malicious outputs. Microsoft Defender experts have previously warned about the evolution of cryptojacking attacks from SEO poisoning to "poisoning" LLM responses from models like Gemini, Claude, Copilot, and ChatGPT. Threats include malicious artifacts via context windows, chatbot-recommended download links, fake AI-branded installers, and infected source code or agent skills. For crypto professionals, the risk is heightened because they often manage irreplaceable secrets like seed phrases, private keys, exchange API keys, and wallet data. The article argues that the most dangerous vulnerability is human trust and complacency. A ...

Generative Artificial Intelligence (AI) is gaining momentum every day, and people working in digital assets and distributed ledgers regularly use this technology in their work. The problem is that this target audience is clearly in the sights of malicious actors, and confidential information, which is not so easy to revoke, can be stolen. On Friday, Refi Hub co-founder Numa Lunah recounted that he had been "hacked."

"Yesterday I got hacked," he wrote on X. "The link came from a Claude chat. I was installing a transcription app. Claude sent a download link, and I pasted a command into the terminal. Everything looked perfectly legitimate. But in fact, it wasn't. It was a fake website containing malware. It launched instantly and tried to steal everything from me."

The developer added that no confidential information was leaked, and he completely wiped the laptop he was using and reinstalled the system from scratch. But that wasn't the end of the problem. "Here's the scariest part," Numa explained. "While restoring data from a backup, I discovered an infected SKILL.md file for Claude Code. It looked exactly like my own style guide. But inside, it contained instructions to stealthily re-download the malware and steal my credentials every time the AI loaded that file."

LLM Responses Open a New Attack Vector, and Crypto Workers Face an Un-revokable Security Problem

Numa's case is not the first where an LLM has provided malicious responses. Several months ago, Microsoft Defender experts warned that cryptojacking attacks have evolved from simple SEO poisoning to "poisoning" LLM responses. Similar attacks stem from AI models such as Gemini, Claude, Copilot, and ChatGPT. These include: artifacts distributed through the context window; chatbots recommending download links controlled by attackers; fake installers under an AI brand; and infected source code and agent skills.

Image source: X

Essentially, a regular content specialist's laptop stores secret data that can be revoked even after a hack, but crypto specialists may store secret data that cannot be revoked. This includes items such as seed phrases, exported xprv/keystore files, "hot" wallet JSON files, exchange API keys with withdrawal permissions, deployer keys, Lightning macaroons, associated hardware wallet data, session cookies for centralized exchange (CEX) dashboards, and much more.

The Most Dangerous Vulnerability May Be Human Trust and Laziness

Recent warnings show that a fundamental shift in security culture is needed. Instead of simply regularly trusting AI tools, comprehensive skepticism towards automation itself is necessary. Employees in this industry would do better to treat every AI suggestion as potentially hostile, regardless of the source. This is not excessive caution or paranoia; it is, quite literally, a matter of survival.

Attackers are also forging downloads of AI models such as Claude and ChatGPT desktop applications. Image source: X.

The moral of this story is not about vulnerable code or infected results from our favorite AI models, but about the human instinct to trust convenient answers. In this situation, that instinct is a threat that no patch can fix. In the end, what saved the Refi Hub co-founder, he said, was that he "read every config file, hook, and configuration before letting the AI touch it."

Unfortunately, most modern AI users are likely not to double-check the veracity of the information provided to them by AI and simply trust it for reasons that remain difficult to explain.

Domande pertinenti

QAccording to the article, what new threat vector has emerged for crypto industry workers?

AAccording to the article, a new threat vector for crypto industry workers comes from LLM (Large Language Model) responses. Attacks like LLM answer poisoning, where AI models provide malicious links, fake installers, or infected code, are targeting this group.

QHow did the co-founder of Refi Hub, Numa Lunah, get compromised according to the article?

ANuma Lunah was compromised by clicking on a link he received in a chat with Claude AI. He thought it was a legitimate link to download a transcription app but it led to a fake website containing malware that executed instantly and attempted to steal his information.

QWhat is described as the most dangerous vulnerability for crypto professionals in the article?

AThe article describes human trust and laziness as potentially the most dangerous vulnerability for crypto professionals. The instinct to trust convenient answers from AI, without verification, is a fundamental security threat.

QWhat saved Numa Lunah from a more serious compromise after the initial attack?

AWhat saved Numa Lunah was his thoroughness during system recovery. He manually read every setup file, hook, and configuration before allowing the AI to interact with them, which allowed him to spot a maliciously infected SKILL.md file for Claude Code.

QWhat type of data is highlighted as particularly dangerous for crypto workers to have compromised, and why?

AThe article highlights that crypto workers often possess irreplaceable secret data like seed phrases, private keys (e.g., xprv/keystore files), hot wallet JSON files, exchange API keys with withdrawal permissions, and Lightning macaroons. These are dangerous because, unlike passwords, they often grant immediate and irrevocable access to assets.

Letture associate

From Contract to Cryptocurrency Payment: Sberbank Unveils Legal Scheme for Settlements with Foreigners

Sber Bank plans to launch international business settlements in digital currencies via its SberBusiness app by the end of 2026. The bank's deputy chairman, Anatoly Popov, announced this ahead of the Eastern Economic Forum, stating the goal is to simplify digital currency use for businesses in cross-border trade. The legal basis is Federal Law No. 282-FZ "On Digital Currency and Digital Rights," effective September 1, 2026, which permits foreign trade crypto settlements through licensed intermediaries. A published guide outlines the process: a company signs a contract, transfers rubles to a licensed intermediary, who then buys and sends cryptocurrency to the recipient, with reporting for regulators generated automatically. This service is positioned as an alternative channel for foreign trade, especially where traditional bank transfers face sanctions. Sber aims to integrate crypto payments into standard business tools within SberBusiness, avoiding the need for specialized technical knowledge. Development will depend on the practical application of the new law. From a macro perspective, this initiative is seen not just as a technical innovation but also within the context of sanctions pressure on crypto markets. The article notes that licensed intermediaries could become targets for secondary sanctions, as seen with UK actions against crypto exchanges in summer 2026. The long-term viability of Sber's scheme may depend more on political dynamics than technology, following a historical pattern where new payment channels face regulatory countermeasures.

cryptonews.ru11 min fa

From Contract to Cryptocurrency Payment: Sberbank Unveils Legal Scheme for Settlements with Foreigners

cryptonews.ru11 min fa

Trading

Spot
活动图片