Refi Hub co-founder: Targeted by malicious link attack from Claude, contaminated skill files attempted to steal credentials
Numa Lunah, co-founder of the crypto project Refi Hub, stated that he was hacked after installing a transcription application using a download link provided in the Claude chat window. The link pointed to a counterfeit website and bundled malware that attempted to steal all information from his device upon execution. Numa Lunah mentioned that he cleared and reinstalled the affected laptop and found no sensitive information leaked.
Subsequently, he discovered a contaminated Claude Code skill file SKILL.md in his backup, which disguised itself as a style guide written by him and contained instructions to re-download the malware and steal credentials every time it was loaded. Microsoft Defender Experts had warned that attackers had shifted from search engine optimization poisoning to large language model response poisoning, with related tactics including recommending download links controlled by attackers, AI brand impersonation installers, and contaminated code libraries and proxy skills. Crypto industry practitioners may hold irrevocable credentials such as mnemonic phrases, private key files, hot wallet JSON, exchange API keys with withdrawal permissions, and deployer keys.






