Crypto▼ Bearish

AI Chatbot Delivers Malware to Crypto Workers in Targeted Attack

By AlphaScala Research DeskSource reporting: BitcoinEditorial standards1 views
AI Chatbot Delivers Malware to Crypto Workers in Targeted Attack

Refi Hub co-founder Numa Lunah was hacked after Claude chat sent a download link. Crypto workers face unique risk: stolen seed phrases and keys cannot be revoked. The attack included a poisoned AI skill file.

AlphaScala Research Snapshot
Live stock context for companies directly referenced in this story
Microsoft CorporationMSFTTechnology
$490.30-1.37% todayUpdated

Alpha Score of 70 reflects moderate overall profile with moderate momentum, moderate value, strong quality, moderate sentiment.

Alpha Score
70
Moderate
This panel uses AlphaScala-native stock data — proprietary scoring and live snapshots.

Refi Hub co-founder Numa Lunah said he was compromised after following a download link that appeared inside a Claude AI chat window. He wrote on X that he “got hacked” on Friday while installing a transcription app. “Claude sent the download link, and I pasted the command into the terminal. It all looked legit. It wasn’t, though. It was a copycat site bundling malware. It ran instantly, tried to take everything from me.”

Lunah said nothing sensitive escaped. He wiped the laptop and rebuilt it from a clean install. The problem did not end there. “Restoring from the backup, I found a poisoned SKILL.md for Claude Code. It looked exactly like my own writing style guide. But buried inside: It had instructions to silently re-download the malware and steal my credentials every time the AI loaded it,” he wrote.

The incident is not the first. Microsoft Defender Experts warned earlier this year that cryptojacking attacks had evolved from simple SEO poisoning to LLM answer poisoning. Attacks now come through context-window shared artifacts, chatbots recommending attacker-controlled download links, AI-branded fake installers, and poisoned codebase and agent skills. The Microsoft report covered threats across models including Gemini, Claude, Copilot, and ChatGPT.

A standard knowledge-worker laptop holds secrets that can be revoked after a hack: passwords reset, API keys rotated, sessions invalidated. Crypto workers hold secrets that cannot be revoked. The list includes seed phrases, exported xprv or keystore files, hot-wallet JSON, and exchange API keys with withdrawal rights. Also at risk: deployer keys, Lightning macaroons, hardware-wallet companion data, and session cookies for CEX dashboards. Once stolen, those credentials give an attacker permanent access to wallets and exchange accounts.

Lunah’s experience points to a shift in attack methods. Rather than phishing emails or fake websites, attackers now poison the outputs of AI tools that crypto workers rely on daily. The download link came from inside a trusted chat interface. The SKILL.md file, a configuration file Claude Code reads to customize behavior, had been altered to re-infect the system after a restore. Lunah said he caught it only because he “read every skill, hook, and config file before letting the AI touch them.”

The risk is amplified by the industry’s heavy use of AI for coding, contract analysis, and transaction building. A poisoned AI response that recommends a malicious npm package, a fake ABI, or a compromised wallet library can lead to irreversible theft before the user detects anything wrong. Microsoft’s warning noted that attackers are investing in AI-generated disinformation and fake documentation to make malicious code appear legitimate.

Lunah’s case underscores a hard lesson: the human instinct to trust convenient answers is a liability. Most AI users, he suggested, do not double-check what the model hands them. In crypto, where a single copied seed phrase can drain a wallet, that trust can be fatal. The only defense is pervasive skepticism toward automation, regardless of source. Lunah said he was saved only because he read every file before letting the AI touch them. Most users, he wrote, are not doing that.

How this story was producedLast reviewed Aug 29, 2026

Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.

Editorial Policy·Report a correction·Risk Disclaimer

Related Tools & Research

Asset Profiles