AI-Powered Malware Targets Crypto Workers via Compromised Chat Links

AI-Powered Malware Targets Crypto Workers via Compromised Chat Links

First seen 29 Aug 2026, 23:48 UTC News.BitcoinChaincatcher 64.5

Article Content

Browse articles
ThreatCluster

Numa Lunah, co-founder of Refi Hub, was hacked after clicking a malicious download link in a Claude chat window. The link led to a counterfeit site that installed malware designed to steal sensitive information. Although Lunah managed to wipe his laptop and found no sensitive data leaked, he later discovered a poisoned SKILL.md file in his backup that could silently re-download the malware. This incident highlights the growing threat of AI-driven attacks targeting the crypto sector, where workers often hold irrevocable credentials. Microsoft Defender Experts previously warned of a shift from SEO poisoning to LLM response poisoning, with attackers using AI tools to recommend malicious links. The crypto industry must adopt a more skeptical approach towards AI suggestions to mitigate these risks.

Key Points: • Numa Lunah was hacked via a malicious link in a Claude chat. • The attack involved a counterfeit site bundling malware targeting sensitive crypto credentials. • Crypto workers are particularly vulnerable due to the nature of their digital assets.

Timeline

2026-08-28
Numa Lunah hacked
Lunah clicked a malicious link in a Claude chat, leading to malware installation.
News.Bitcoin
2026-08-28
Malware discovered
Lunah found a poisoned SKILL.md file in his backup that could re-download the malware.
Chaincatcher
Recent
Microsoft Defender warning
Experts warned of a shift to AI response poisoning tactics in cyber attacks.
News.Bitcoin