Generative Artificial Intelligence (AI) is gaining momentum every day, and people working in digital assets and distributed ledgers regularly use this technology in their work. The problem is that this target audience is clearly in the sights of malicious actors, and confidential information, which is not so easy to revoke, can be stolen. On Friday, Refi Hub co-founder Numa Lunah recounted that he had been "hacked."
"Yesterday I got hacked," he wrote on X. "The link came from a Claude chat. I was installing a transcription app. Claude sent a download link, and I pasted a command into the terminal. Everything looked perfectly legitimate. But in fact, it wasn't. It was a fake website containing malware. It launched instantly and tried to steal everything from me."
The developer added that no confidential information was leaked, and he completely wiped the laptop he was using and reinstalled the system from scratch. But that wasn't the end of the problem. "Here's the scariest part," Numa explained. "While restoring data from a backup, I discovered an infected SKILL.md file for Claude Code. It looked exactly like my own style guide. But inside, it contained instructions to stealthily re-download the malware and steal my credentials every time the AI loaded that file."
LLM Responses Open a New Attack Vector, and Crypto Workers Face an Un-revokable Security Problem
Numa's case is not the first where an LLM has provided malicious responses. Several months ago, Microsoft Defender experts warned that cryptojacking attacks have evolved from simple SEO poisoning to "poisoning" LLM responses. Similar attacks stem from AI models such as Gemini, Claude, Copilot, and ChatGPT. These include: artifacts distributed through the context window; chatbots recommending download links controlled by attackers; fake installers under an AI brand; and infected source code and agent skills.

Essentially, a regular content specialist's laptop stores secret data that can be revoked even after a hack, but crypto specialists may store secret data that cannot be revoked. This includes items such as seed phrases, exported xprv/keystore files, "hot" wallet JSON files, exchange API keys with withdrawal permissions, deployer keys, Lightning macaroons, associated hardware wallet data, session cookies for centralized exchange (CEX) dashboards, and much more.
The Most Dangerous Vulnerability May Be Human Trust and Laziness
Recent warnings show that a fundamental shift in security culture is needed. Instead of simply regularly trusting AI tools, comprehensive skepticism towards automation itself is necessary. Employees in this industry would do better to treat every AI suggestion as potentially hostile, regardless of the source. This is not excessive caution or paranoia; it is, quite literally, a matter of survival.

The moral of this story is not about vulnerable code or infected results from our favorite AI models, but about the human instinct to trust convenient answers. In this situation, that instinct is a threat that no patch can fix. In the end, what saved the Refi Hub co-founder, he said, was that he "read every config file, hook, and configuration before letting the AI touch it."
Unfortunately, most modern AI users are likely not to double-check the veracity of the information provided to them by AI and simply trust it for reasons that remain difficult to explain.





