Crypto news report · source clearly identified
Poisoned AI Links Pose New Threats for Crypto Professionals
This week, the co‑founder of Refi Hub, Numa Lunah, explained that he was compromised by following a download link delivered inside a Claude chat window. The warning is a wake‑up call to blockchain and crypto industry workers, as links, skills, and other packages can lead to irreversible theft.

Crypto developers and analysts increasingly rely on generative AI tools for daily tasks. A recent incident involving Refi Hub co‑founder Numa Lunah highlights how malicious actors can exploit AI‑generated links to deliver malware and steal sensitive credentials.
Malicious Link Delivered via Claude Chat
Lunah posted on X that a download link sent from a Claude chat window appeared to be a legitimate transcription‑app installer. After copying the command into his terminal, the site delivered a copycat package that executed malware, prompting him to wipe and reinstall his laptop.
Poisoned Skill File Extends the Attack
During restoration from backup, Lunah discovered a tampered SKILL.md file for Claude Code. The file mimicked his own style guide but contained hidden instructions to re‑download the malware and exfiltrate credentials each time the AI loaded the skill.
Broader Trend of LLM Answer Poisoning
Microsoft Defender experts have warned that cryptojacking attacks are evolving from SEO manipulation to LLM answer poisoning. Similar threats have been reported across AI models such as Gemini, Claude, Copilot and ChatGPT, including attacker‑controlled download links, fake installers and poisoned codebases.
Why Crypto Workers Are Especially Vulnerable
Unlike typical knowledge‑worker environments, crypto professionals often store non‑revocable secrets—seed phrases, private keys, hot‑wallet JSON files, exchange API keys, deployer keys, Lightning macaroons and session cookies. Compromise of these assets can lead to irreversible loss.
Recommended Security Practices
- Treat every AI‑generated link or code snippet as hostile until verified.
- Manually review all AI‑provided skill, hook and configuration files before execution.
- Maintain offline backups of critical secrets and rotate keys regularly.
- Implement strict network segmentation for devices used with AI tools.
Adopting a skeptical stance toward AI outputs is essential to protect against this emerging attack vector.
Source & attribution
News Source
- Publisher
- Bitcoin.com News
- Original date
- August 29, 2026, 7:35 PM
- Original headline
- Don’t Trust, Verify: Poisoned AI Links Expose a Nightmare for Crypto Workers