CoinTrust

AI Malware Attack Targets Crypto Wallets Through Claude Download

Malware

A security incident involving Numa Lunah, co-founder of a Web3 project, has highlighted an emerging attack technique in which malicious code can be concealed inside files used to configure artificial intelligence tools. The incident nearly resulted in the loss of control over digital assets after an AI-recommended download link led to the installation of information-stealing malware.

The attack began when Lunah was preparing a work environment and asked Anthropic’s Claude for a download link to a voice transcription application. According to the report, the AI system provided a phishing website that closely resembled the application’s legitimate site. Lunah downloaded the software from the recommended address, unknowingly allowing an infostealer to enter his work laptop.

The malware was designed to obtain sensitive information, including passwords, cryptocurrency exchange credentials and private keys associated with hot wallets. Such information can provide attackers with direct access to digital assets, making the compromise particularly serious for Web3 professionals who frequently keep financial credentials and development tools on the same computers.

Backdoor remained after operating system reset

Lunah identified indications that his device had been compromised and responded by isolating the computer before performing a complete operating system reinstall. However, the security threat persisted through a less obvious part of his backup environment.

While restoring files, Lunah discovered that a SKILL.md document used as a personal AI style and configuration guide had been modified. The attacker had manipulated the structure of the document so that its contents could perform a malicious function when introduced into another environment.

The modified configuration file was reportedly capable of contacting an attacker-controlled server, downloading the infostealer again and restarting the theft of sensitive account information when the file was connected to a clean computer.

The incident demonstrated that reinstalling an operating system may not fully eliminate a compromise if malicious instructions or altered configuration files remain within restored backups. A clean machine could therefore become infected again when previously trusted files are reintroduced.

AI configuration files become a security concern

The case has raised broader concerns about how developers and other users handle files consumed by AI systems. Configuration files commonly use formats such as Markdown or JSON and are generally regarded as documents rather than executable software. However, the incident indicated that this distinction may no longer provide adequate protection when AI tools automatically interpret and act on information contained in those files.


Security observers have increasingly warned that attackers could exploit AI workflows by manipulating the context supplied to autonomous or semi-autonomous systems. Such techniques can potentially cause AI agents to follow malicious instructions without requiring conventional executable malware to remain on a machine.

Illia Polosukhin, co-founder of Near Protocol, also drew attention to the incident. He emphasized the importance of securing infrastructure used by autonomous AI agents and noted that campaigns involving context poisoning had been becoming more common.

Web3 users face elevated exposure

The incident is particularly relevant to Web3 developers because their workstations can contain a combination of highly valuable credentials. Exchange login information, wallet keys, API credentials, and development resources may all be stored or accessed from a single device.

The case underscores the need for developers to inspect AI-related configuration files for unexpected structural modifications and external network connections before restoring them or moving them to another computer.

The episode also illustrates a broader challenge created by the growing use of AI assistants in software and workplace environments. Users increasingly rely on AI systems for software recommendations, configuration instructions and automation, creating new opportunities for attackers to manipulate the information those systems consume.

As AI-assisted development and autonomous agents become more widespread, security practices may need to extend beyond traditional applications and operating-system protections. Backup files, configuration documents and AI skill definitions could increasingly require the same level of scrutiny applied to executable software.

For Web3 developers, the incident serves as a warning that restoring a compromised environment requires more than reinstalling the operating system; every trusted file and AI configuration used afterward may also need to be examined for hidden persistence mechanisms.

Exit mobile version