web3: Cryptocurrency developers accidentally click on fake links; Claude The link is at risk of backdoor attack
U.Today
15h ago
Ai Focus
Hackers used fake Claude links to deploy malware and achieved re-infection after system reinstallation through the AI configuration files.
Helpful
No.Help

An encryption developer recently revealed that while setting up his work environment, he obtained the download link for a transcription application using Claude. As a result, he ended up accessing a phishing website. After downloading the software, his device was quietly infected with a program designed to steal information, which targeted passwords, exchange account credentials, and private keys from hot wallets.

Still get reinfected even after reinstalling.

After discovering the anomaly, the developer immediately isolated the device and performed a complete reinstallation on the work computer. It seemed that the risk had been eliminated, but when restoring the backup files, he found that a AI configuration document named SKILL.md had been manually altered.

This document was originally intended to serve as his personal AI style guide. However, the attacker modified the file structure so that once it was imported into a new, clean device, it would automatically connect to the attacker's server, download the information theft program again, and continue to collect credentials.

Backdoor hidden in configuration files

This means that the risk does not only come from the malware initially downloaded, but also from the trusted configuration files used during subsequent recovery processes. Even if the operating system has been reinstalled, as long as the contaminated files are reused, the malicious programs may still return to the device.

Reports indicate that this incident has exposed a new method of attack: hackers not only forged the download links provided by AI, but also concealed backdoors within the AI skills or configuration files, creating a continuous infection pathway.

Web3 Developers become a key target

NEAR Protocol, co-founder, and Illia Polosukhin have also noticed this matter. He pointed out that security issues surrounding autonomous AI proxy infrastructure are becoming more prominent, and the number of attacks carried out using "context poisoning" is also increasing.

For the developers of Web3, local work devices have always been high-value targets, as they often contain the development environment, account credentials, and wallet keys. This incident demonstrates that seemingly ordinary AI configuration files, such as md or json, can no longer be simply regarded as harmless text.

In the future, such files will need to be checked in the same manner as executable code before import, synchronization, or restoration. Otherwise, attackers may use the AI tools and configuration files within the regular work process to introduce malicious programs onto new devices.

Tip
$0
Like
0
Save
0
Views 61
CoinMeta reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
web3: The scale of compliant crypto transactions in Russia may reach 4 trillion rubles in the first year
The first-year turnover of Russia's compliant cryptocurrency trading market is expected to reach 3.5 to 4 trillion rubles, with ordinary investors facing testing and annual purchase limits.
Cryptonews
·2026-08-31 13:20:42
13
Polygon Launched Private Mempool: Can be hidden before transaction confirmation, but remains in a public ledger after confirmation
The most transparent window for on-chain transactions often appears before they are written to a block. After a user submits a transaction, whether it’s an exchange, payment, or a large-scale settlement, the transaction first enters the public memory pool. Searchers and bots can see the amount, path, and slippage, and then decide whether to place orders ahead of others or re-order around it. Polygon has recently been launched to shorten this exposure time: transactions are no longer broadcast to the public memory pool but are sent directly to the selected block producer through a private endpoint.
币界网
·2026-08-31 13:20:00
20
Ethereum: Bitcoin Falls to April 2021 Lows, Crypto Market Under Pressure
Bitcoin falls to a low not seen since April of last year, with continuous outflows from ETF and large-scale liquidations exacerbating the market decline.
CoinPedia
·2026-08-31 12:47:24
18
Foreign media: Restrictions on robots and drones by the US cannot withstand China's scale advantage
Foreign media reports that after the United States imposes additional restrictions on foreign-made robots and drones, the global market may become further regionalized, yet Chinese companies still hold advantages in scale and cost.
TechCrunch
·2026-08-31 10:58:17
29
Ethereum: Bitcoin spot ETF ends nine consecutive increases; Ethereum ETF continues to attract funds
US spot Bitcoin ETF saw a net outflow of $201.9 million in a single day, ending a nine-day consecutive increase; Ethereum ETF had a net inflow of $102.1 million on the same day, continuing its 10-day net inflow trend.
Coinpaper
·2026-08-31 06:07:45
74
View More