Refi Hub Co-founder Hit by Malicious Claude Link Attack, Contaminated Skill File Attempts to Steal Credentials
Odaily News: Numa Lunah, co-founder of the crypto project Refi Hub, stated that he was hacked after using a download link provided in a Claude chat window to install a transcription application. The link pointed to a fake website bundled with malware, which attempted to steal all information from his device upon execution.
Numa Lunah said he wiped and reinstalled the affected laptop and found no signs of sensitive data leakage. Subsequently, he discovered a contaminated Claude Code skill file named SKILL.md in his backups. The file was disguised as a style guide written by himself and contained instructions to re-download malware and steal credentials every time it was loaded.
Microsoft Defender Experts previously warned that attackers have shifted from search engine optimization poisoning to large language model response poisoning. These tactics include recommending attacker-controlled download links, AI-branded fake installers, and contaminated code repositories and agent skills. Individuals working in the crypto industry may hold irrevocable credentials such as mnemonic phrases, private key files, hot wallet JSONs, exchange API keys with withdrawal permissions, and deployer keys. (Bitcoin.com News)
