Web3 project co-founder Numa Lunah nearly lost control of his digital assets after following recommendations from artificial intelligence.
The incident revealed a new cyberattack vector in which hackers inject hidden backdoors into AI skill configuration files, allowing them to reinfect computers even after a complete operating system reinstall.
Why a system reset failed to protect crypto wallets from malware delivered through Claude
The attack began while Lunah was setting up his work environment and asked Claude for a link to download a transcription app. The AI assistant provided an address that led to a phishing clone of the program’s official website.
After the software was downloaded, an infostealer was silently installed on the developer’s work laptop — malware designed to steal passwords, exchange credentials, and private keys from hot wallets.
The developer detected the compromise in time, isolated the device, and completely reinstalled the operating system.
However, the threat was not eliminated. While attempting to restore files from a backup, Lunah discovered changes to a SKILL.md document that he used as a personal style guide for AI.
The hackers had managed to modify the structure of the text file. When this configuration profile was integrated into any new, clean computer, the file automatically connected to the attackers’ server, downloaded the infostealer again, and resumed collecting credentials.
The incident caught the attention of NEAR Protocol co-founder, Illia Polosukhin. He warned about the critical importance of securing autonomous AI agent infrastructure and the growing number of campaigns using “context poisoning” tactics.
For Web3 developers, whose local machines are priority targets, this case changes the rules of cybersecurity. AI skill configuration files in .md or .json formats can no longer be treated as harmless text. They must be handled like executable code and thoroughly inspected before use.
Source: https://u.today/crypto-developer-dodges-hidden-malware-after-clicking-fake-claude-ai-link





Be the first to comment