web3: Cryptocurrency developers accidentally click on fake links; Claude The link is at risk of backdoor attack
U.Today
08-30 22:50
Ai Focus
Hackers used fake Claude links to deploy malware and achieved re-infection after system reinstallation through the AI configuration files.
Helpful
No.Help

An encryption developer recently revealed that while setting up his work environment, he obtained the download link for a transcription application using Claude. As a result, he ended up accessing a phishing website. After downloading the software, his device was quietly infected with a program designed to steal information, which targeted passwords, exchange account credentials, and private keys from hot wallets.

Still get reinfected even after reinstalling.

After discovering the anomaly, the developer immediately isolated the device and performed a complete reinstallation on the work computer. It seemed that the risk had been eliminated, but when restoring the backup files, he found that a AI configuration document named SKILL.md had been manually altered.

This document was originally intended to serve as his personal AI style guide. However, the attacker modified the file structure so that once it was imported into a new, clean device, it would automatically connect to the attacker's server, download the information theft program again, and continue to collect credentials.

Backdoor hidden in configuration files

This means that the risk does not only come from the malware initially downloaded, but also from the trusted configuration files used during subsequent recovery processes. Even if the operating system has been reinstalled, as long as the contaminated files are reused, the malicious programs may still return to the device.

Reports indicate that this incident has exposed a new method of attack: hackers not only forged the download links provided by AI, but also concealed backdoors within the AI skills or configuration files, creating a continuous infection pathway.

Web3 Developers become a key target

NEAR Protocol, co-founder, and Illia Polosukhin have also noticed this matter. He pointed out that security issues surrounding autonomous AI proxy infrastructure are becoming more prominent, and the number of attacks carried out using "context poisoning" is also increasing.

For the developers of Web3, local work devices have always been high-value targets, as they often contain the development environment, account credentials, and wallet keys. This incident demonstrates that seemingly ordinary AI configuration files, such as md or json, can no longer be simply regarded as harmless text.

In the future, such files will need to be checked in the same manner as executable code before import, synchronization, or restoration. Otherwise, attackers may use the AI tools and configuration files within the regular work process to introduce malicious programs onto new devices.

Tip
$0
Like
0
Save
0
Views 267
HKWDB reminds readers to view blockchain rationally, stay aware of risks, and beware of virtual token issuance and speculation. All content on this site represents market information or related viewpoints only and does not constitute any form of investment advice. If you find sensitive content, please click“Report”,and we will handle it promptly。
Submit
Comment 0
Hot
Latest
No comments yet. Be the first!
Related
Solana Mainnet enables 4096-byte transactions: More space, but also brings upgrade pressure on indexers
Solana will enable v1 transaction-related functions on the mainnet Epoch on September 15th at 01:20 UTC. The maximum size of a single transaction will be increased from 1232 bytes to 4096 bytes, which is approximately 3.3 times the original size. The official upgrade page indicates that the activation is expected to occur at this time, and the mainnet status will be marked as activated. The new format provides more space for zero-knowledge proofs, large multi-signatures, batch processing, and some on-chain signature schemes, reducing the need for developers to split a single operation into multiple transactions. The existing legacy and v0 transactions will continue to function, so this is not a hard fork that requires all wallets and applications to switch immediately.
币界网
·2026-09-16 10:17:03
184
Final Launches Shannon Development Network: An "Adaptive Blockchain" Begins with Restricted Testing
The new public chain Final announced on September 15th that its first major version, Shannon, is already running on the development network. The project positions itself as an “adaptive blockchain network” and showcases a structure composed of a main chain and a transaction chain, with plans to provide core facilities such as derivatives, spot trading, and stablecoins at the protocol layer. What needs to be clarified at this point is that what has been launched is Devnet, not the mature mainnet intended for everyone. The official website states that Shannon will be open to the public “in the near future,” and the current page still provides an application access link; functions such as wallets, bridges, and documentation are also marked as upcoming.
币界网
·2026-09-16 10:15:56
165
Google Launches Engineering Center in Singapore: The Next Step for AI Competition is to Turn Research into a Deployable System
Google Cloud launched on September 15th in Singapore as Singapore Engineering Center. This is not a traditional regional sales or after-sales office. According to the company's positioning, the center will bring together professionals in AI, machine learning, data, computing, core networking, storage, and frontline support, working together with enterprises to transform basic research into deployable cloud and AI systems. It is located at the same site as Google DeepMind's first research laboratory in Southeast Asia, aiming to bring research, product engineering, and customer implementation closer together on a shorter chain of operations. Google also mentioned that the center had already been publicly announced in February of this year.
CoinMeta
·2026-09-16 10:12:25
46
Gemini Integrates seven business systems into Workspace: AI Assistant begins to compete for corporate job inflows
On September 15th, Google announced the opening of a batch of third-party connectors in Gemini, for, and Google Workspace. The initial list includes Asana, Atlassian Rovo, HubSpot, Intuit Mailchimp, Intuit QuickBooks, monday.com, and Salesforce. The connection method uses the model context protocol MCP. For ordinary users, the change is quite direct: when asking questions in the sidebars of Docs, Sheets, Slides or within Google Chat, Gemi
CoinMeta
·2026-09-16 10:10:42
40
web3: The U.S. Senate fails to advance the CLARITY bill, leading to a decline in the crypto market
After the U.S. Senate failed to advance the CLARITY bill, the crypto market declined, with Bitcoin briefly falling below $75,000.
CoinPedia
·2026-09-16 03:51:21
184
View More