Refi Hub Co-Founder: Hit by Malicious Claude Link Attack, Contaminated Skill File Attempted to Steal Credentials
Numa Lunah, co-founder of crypto project Refi Hub, said he was hacked after using a download link provided in a Claude chat window to install a transcription app.…
Numa Lunah, co-founder of crypto project Refi Hub, said he was hacked after using a download link provided in a Claude chat window to install a transcription app. The link pointed to a spoofed website bundled with malware that, once executed, attempted to steal all information from his device. Numa Lunah said he wiped and reinstalled the affected laptop and found no evidence of sensitive data leakage. Later, he discovered a contaminated Claude Code skill file, SKILL.md, in his backups, which was disguised as a style guide written by himself and contained instructions to re-download malware and steal credentials on every load. Microsoft Defender Experts had previously warned that attackers have shifted from search engine optimization poisoning to large language model answer poisoning, with tactics including recommending attacker-controlled download links, AI-branded spoofed installers, and contaminated code repositories and agent skills. Crypto industry practitioners may hold irrevocable credentials such as mnemonic phrases, private key files, hot wallet JSONs, exchange API keys with withdrawal permissions, and deployer keys.
insigtX content is informational and educational, not investment advice.