Don't Trust, Verify: Malicious AI Links Expose a Nightmare Reality for Crypto Industry Workers
Generative AI is becoming increasingly prevalent, with professionals in the digital assets and blockchain space regularly using it. However, this makes them prime targets for attackers seeking to steal sensitive, often irrevocable, information. Refi Hub co-founder Numa Lunah recently reported being "hacked" through a malicious link sent in a chat with the AI model Claude, which appeared to be a legitimate transcription app download. The link installed malware that attempted to steal all his data.
While Numa claimed no sensitive data was leaked—as he wiped and reinstalled his laptop's OS—he later discovered a corrupted `SKILL.md` file in his backups, disguised as a style guide. This file contained hidden instructions to reload the malware and steal credentials whenever the AI accessed it.
This incident highlights a new attack vector: LLMs providing malicious outputs. Microsoft Defender experts have previously warned about the evolution of cryptojacking attacks from SEO poisoning to "poisoning" LLM responses from models like Gemini, Claude, Copilot, and ChatGPT. Threats include malicious artifacts via context windows, chatbot-recommended download links, fake AI-branded installers, and infected source code or agent skills.
For crypto professionals, the risk is heightened because they often manage irreplaceable secrets like seed phrases, private keys, exchange API keys, and wallet data. The article argues that the most dangerous vulnerability is human trust and complacency. A fundamental shift in security culture is needed: treating every AI suggestion as potentially hostile, regardless of its source. This isn't paranoia but a survival necessity. The key takeaway is that the threat lies not in vulnerable code but in the human instinct to trust convenient answers, a flaw no software patch can fix. Numa was saved only because he meticulously reviewed every configuration file before letting the AI interact with it—a level of caution most users likely neglect.
cryptonews.ru3h ago