×
Un lien malveillant issu d’un assistant IA tente d’atteindre des wallets et un fichier de sauvegarde

A crypto user claims to have narrowly escaped a malware attack after following a link provided in a conversation with Claude. The trap led to a fake website distributing malicious software. Even more concerning: after cleaning his computer, he reportedly discovered a modified SKILL.md file in his backup, capable of attempting to reinstall the malware.

The case remains an individual testimony, and not all details have been independently verified. The mechanism itself, however, is far from theoretical. Huntress has already identified another campaign linked to fake Claude content that affected at least 29 organizations in just two days.

Crypto: Claude Becomes a Phishing Ground

The attack described by Numa, co-founder of ReFi Hub, begins almost banally. Looking for a transcription application, Claude provided him with a link, and he then executed a command from the indicated site. Behind the legitimate appearance was a cloned website and malware.

The scenario is reminiscent of fake Google emails targeting exchange and DeFi users previously documented by Bref Crypto: attackers are no longer necessarily trying to create obvious traps. Instead, they leverage trust signals from a known service.

Huntress observed a similar mechanism in July. Users searching for Claude Desktop on Bing were redirected to an Artifact hosted on the genuine Claude.ai domain, before being sent to an external site distributing SectopRAT. At least 29 organizations were affected between July 21 and 22. The technical report by Huntress notes that the Artifact had recorded approximately 7,100 views before it was removed.

The SKILL.md File Changes the Threat Landscape

This is the most interesting part of the recent case.

A SKILL.md file is used to provide an AI agent with reusable instructions and capabilities. Anthropic confirms in its own documentation that these files can be loaded from repositories and used automatically when the task matches. The company also warns that a repository containing Skills falls within the agent’s « trust boundary. »

According to Numa, his file had been modified to look like his usual style guide while containing instructions designed to download the malware again and harvest credentials.

In other words, deleting the malware is no longer necessarily enough if its entry point survives in a backup that the agent will later read.

The problem goes beyond Claude. A Snyk study published this year identified at least one security vulnerability in 36.82% of the 3,984 Agent Skills analyzed, with 534 presenting a critical issue.

Crypto Wallets are Directly Exposed

For a crypto user, an infostealer can be highly costly. Passwords, session cookies, browser data, locally stored keys, and wallet extensions can all be targets.

Huntress indicates that some recent infostealers targeting macOS specifically search for Keychain data and over 200 extensions associated with crypto wallets. Stealing a session cookie can also allow attackers to bypass certain MFA protections without needing the password directly.

This risk comes at a time when crypto platforms are heavily automating their anti-fraud efforts using AI. Defenders are making progress, but so are attackers.

For crypto holders, the rules are becoming stricter: do not blindly execute commands suggested by an AI, verify the official domain of any software, and inspect configuration files before restoring a backup. The principles of securing a crypto wallet remain valid, but AI agents now introduce a new layer that must be monitored.

This case does not prove that Claude was hacked. It shows something more subtle: the trust placed in AI assistants is itself becoming an attack surface. For a user whose computer provides access to wallets or exchanges, a malicious URL can cost far more than a simple system reinstallation.

In Brief

  • A co-founder of ReFi Hub claims to have downloaded malware after following a link provided by Claude.
  • He reports subsequently discovering a compromised SKILL.md file in his backup.
  • A separate campaign analyzed by Huntress had already affected at least 29 organizations using fake Claude content.
  • Infostealers can target passwords, browser sessions, and data associated with crypto wallets.

Auteur/autrice

mosengokm@gmail.com

Mosengo Léon est un analyste crypto et rédacteur pour BrefCrypto.com, reconnu pour ses analyses approfondies des marchés Bitcoin et cryptomonnaies, l’impact des événements structurants comme les crises et levées de fonds, et sa capacité à rendre accessibles les enjeux techniques et économiques de la blockchain pour investisseurs et passionnés

Publications similaires

Un bitcoin résiste au-dessus d’un support fissuré marqué 65 000 sur un graphique de long terme

Bitcoin: Je, $65,000 inaweza kweli kuwa sakafu ya bei?

Je, dola 65,000 zinaweza kuwa bei ambayo Bitcoin haitawahi tena kushuka chini yake? Nadharia hiyo imezidi kupata nguvu tangu wastani wake wa...

Lire la suite
Un bitcoin résiste au-dessus d’un support fissuré marqué 65 000 sur un graphique de long terme

Bitcoin: Can $65,000 Really Become a Floor?

Could $65,000 become a price Bitcoin never revisits on the downside? The thesis has gained traction since its 200-week moving average crossed...

Lire la suite
Un bitcoin résiste au-dessus d’un support fissuré marqué 65 000 sur un graphique de long terme

Bitcoin : les 65 000 $ peuvent-ils vraiment devenir un plancher ?

65 000 dollars pourraient-ils devenir un prix que Bitcoin ne reverra plus jamais par le bas ? La thèse prend de l’ampleur...

Lire la suite
Un protocole DeFi ralentit ses pools tandis que sa trésorerie est redistribuée vers les détenteurs de tokens

Crypto: Balancer inaandaa kufungwa baada ya v3 kushindwa

Balancer inaweza kutoweka polepole baada ya zaidi ya miaka mitano miongoni mwa majina makubwa ya DeFi. Itifaki hiyo ya crypto inaandaa kufungwa...

Lire la suite
Un protocole DeFi ralentit ses pools tandis que sa trésorerie est redistribuée vers les détenteurs de tokens

Crypto: Balancer prepares to shut down after v3 fails

Balancer could gradually disappear after more than five years among DeFi’s biggest names. The crypto protocol is preparing an orderly wind-down following...

Lire la suite
Un protocole DeFi ralentit ses pools tandis que sa trésorerie est redistribuée vers les détenteurs de tokens

Crypto : Balancer prépare sa fermeture après l’échec de v3

Balancer pourrait disparaître progressivement après plus de cinq ans parmi les grands noms de la DeFi. Le protocole crypto prépare une fermeture...

Lire la suite