More

    Don’t Trust, Verify: Poisoned AI Links Expose a Nightmare for Crypto Workers


    Key Takeaways

    Claude Chat Link Turns Into a Malware Trap

    Generative artificial intelligence (AI) is gathering traction every day, and people who work in the digital asset and distributed ledger sector leverage the technology on a regular basis for their jobs. The problem is, this demographic is explicitly hunted by malicious attackers, and secrets that cannot be easily revoked could be stolen. On Friday, Refi Hub co-founder Numa Lunah explained that he “got hacked.”

    “Got hacked yesterday,” he wrote on X. “The link came from inside Claude chat. I was installing a transcription app. Claude sent the download link, and I pasted the command into the terminal. It all looked legit. It wasn’t, though. It was a copycat site bundling malware. It ran instantly, tried to take everything from me.”

    The developer added that nothing sensitive of his escaped, and he wiped the laptop he was using and rebuilt it from a clean install. But the issue wasn’t over. “Here’s the scary part,” Numa explained. “Restoring from the backup, I found a poisoned SKILL.md for Claude Code. It looked exactly like my own writing style guide. But buried inside: It had instructions to silently re-download the malware and steal my credentials every time the AI loaded it.”

    LLM Answers Open a New Attack Vector, While Crypto Workers Face a Security Problem With No Undo Button

    Numa’s experience is not the first case of an LLM sharing malicious answers. A few months ago, Microsoft Defender Experts warned that cryptojacking attacks had evolved from simple SEO poisoning to LLM answer poisoning. Attacks like these are stemming from AI models like Gemini, Claude, Copilot, and ChatGPT. Attacks include context window shared artifacts, chatbots recommending attacker-controlled download links, AI-branded fake installers, and poisoned codebase and agent skills.

    Image source: X

    Basically, a normal knowledge-worker laptop holds reusable secrets that can be revoked even after a hack, but crypto workers can hold secrets that cannot be revoked. This includes things like seed phrases, exported xprv/keystore files, hot-wallet JSON, exchange API keys with withdrawal rights, deployer keys, Lightning macaroons, hardware-wallet companion data, and session cookies for CEX dashboards, among many others.

    The Most Dangerous Vulnerability May Be Human Trust and Laziness

    The latest warnings show that there needs to be a fundamental shift in security culture. Rather than simply trusting AI tools on a regular basis, a pervasive skepticism toward automation itself must be applied. Workers employed in this industry would be better off treating every AI suggestion as inherently hostile, regardless of source. This isn’t being overly protective or paranoid; it’s quite literally survival.

    X screenshot.
    Attackers are also faking AI model downloads like the Claude and ChatGPT desktop apps. Image source: X.

    The moral of the story is not vulnerable code or poisoned outputs from our favorite AI models; it’s the human instinct to trust convenient answers. That instinct, in this landscape, is a liability that no patch can fix. What saved the Refi Hub co-founder in the long run was the fact that he said he “read every skill, hook, and config file before letting the AI touch them.”

    Unfortunately, most AI users today are likely not double-checking the info AI hands them for veracity, and they are simply trusting it for reasons that remain difficult to explain.



    Source link

    Latest stories

    You might also like...