Clear, fast crypto news
BrefCryptoCrypto · Bitcoin · Africa
Menu
Crypto News

Crypto: Malware Exploits Claude to Target Wallets and Exchange Accounts

Content associated with Claude is being used to distribute malware targeting passwords, exchange accounts, and crypto wallets. Huntress details the threat.

A malicious link from an AI assistant attempting to access wallets and a backup file
Attackers exploit the trust placed in AI assistants to distribute malware targeting crypto accounts and wallets.

A crypto user claims to have narrowly escaped a malware attack after following a link provided in a conversation with Claude. The trap led to a fake website distributing malicious software. Even more concerning: after cleaning his computer, he reportedly discovered a modified SKILL.md file in his backup, capable of attempting to reinstall the malware.

The case remains an individual testimony, and not all details have been independently verified. The mechanism itself, however, is far from theoretical. Huntress has already identified another campaign linked to fake Claude content that affected at least 29 organizations in just two days.

Crypto: Claude Becomes a Phishing Ground

The attack described by Numa, co-founder of ReFi Hub, begins almost banally. Looking for a transcription application, Claude provided him with a link, and he then executed a command from the indicated site. Behind the legitimate appearance was a cloned website and malware.

The scenario is reminiscent of fake Google emails targeting exchange and DeFi users previously documented by Bref Crypto: attackers are no longer necessarily trying to create obvious traps. Instead, they leverage trust signals from a known service.

Huntress observed a similar mechanism in July. Users searching for Claude Desktop on Bing were redirected to an Artifact hosted on the genuine Claude.ai domain, before being sent to an external site distributing SectopRAT. At least 29 organizations were affected between July 21 and 22. The technical report by Huntress notes that the Artifact had recorded approximately 7,100 views before it was removed.

The SKILL.md File Changes the Threat Landscape

This is the most interesting part of the recent case.

A SKILL.md file is used to provide an AI agent with reusable instructions and capabilities. Anthropic confirms in its own documentation that these files can be loaded from repositories and used automatically when the task matches. The company also warns that a repository containing Skills falls within the agent’s « trust boundary. »

According to Numa, his file had been modified to look like his usual style guide while containing instructions designed to download the malware again and harvest credentials.

In other words, deleting the malware is no longer necessarily enough if its entry point survives in a backup that the agent will later read.

The problem goes beyond Claude. A Snyk study published this year identified at least one security vulnerability in 36.82% of the 3,984 Agent Skills analyzed, with 534 presenting a critical issue.

Crypto Wallets are Directly Exposed

For a crypto user, an infostealer can be highly costly. Passwords, session cookies, browser data, locally stored keys, and wallet extensions can all be targets.

Huntress indicates that some recent infostealers targeting macOS specifically search for Keychain data and over 200 extensions associated with crypto wallets. Stealing a session cookie can also allow attackers to bypass certain MFA protections without needing the password directly.

This risk comes at a time when crypto platforms are heavily automating their anti-fraud efforts using AI. Defenders are making progress, but so are attackers.

For crypto holders, the rules are becoming stricter: do not blindly execute commands suggested by an AI, verify the official domain of any software, and inspect configuration files before restoring a backup. The principles of securing a crypto wallet remain valid, but AI agents now introduce a new layer that must be monitored.

This case does not prove that Claude was hacked. It shows something more subtle: the trust placed in AI assistants is itself becoming an attack surface. For a user whose computer provides access to wallets or exchanges, a malicious URL can cost far more than a simple system reinstallation.

In Brief

  • A co-founder of ReFi Hub claims to have downloaded malware after following a link provided by Claude.
  • He reports subsequently discovering a compromised SKILL.md file in his backup.
  • A separate campaign analyzed by Huntress had already affected at least 29 organizations using fake Claude content.
  • Infostealers can target passwords, browser sessions, and data associated with crypto wallets.

À propos de l’auteur

Mosengo Léon

Mosengo Léon

Mosengo Léon est un analyste crypto et rédacteur pour BrefCrypto.com, reconnu pour ses analyses approfondies des marchés Bitcoin et cryptomonnaies, l’impact des événements structurants comme les crises et levées de fonds, et sa capacité à rendre accessibles les enjeux techniques et économiques de la blockchain pour investisseurs et passionnés