NEAR Co-Founder Polosukhin Flags 'Context Poisoning' After Fake Claude Link Hit Web3 Developer

NEAR co-founder Illia Polosukhin warns on context poisoning after a fake Claude link hit Web3 developer Numa Lunah and a SKILL.md backdoor survived a reinstall.

(04:16 PM UTC)
4 min read
AI SummaryAI
  • Web3 co-founder Numa Lunah was targeted after Claude returned a phishing link instead of the official site.
  • A modified SKILL.md file reinstalls malware on clean devices by connecting to the attackers' server.
  • NEAR Protocol co-founder Illia Polosukhin warned about rising context poisoning campaigns targeting AI agent infrastructure.
  • AI skill files in .md or .json format must now be reviewed like executable code.
k7rq2fdm

Fake Claude Link Installs Infostealer

Web3 project co-founder Numa Lunah narrowly avoided losing control of his digital assets after following a download recommendation generated by artificial intelligence. The chain started while Lunah was configuring a fresh work environment and asked Claude — the AI assistant developed by Anthropic — for a link to a transcription application. Instead of the program's official website, the assistant pointed to a phishing clone of it, and the installer Lunah pulled from that copy silently planted an infostealer on his work laptop. Infostealers are purpose-built to sweep up passwords, exchange account credentials and the private keys held in hot wallets — the same machines where developers often keep a crypto wallet address and direct access to trading balances within easy reach. Lunah disclosed the sequence in his public post on X. What makes the delivery vector notable is the trust layer: the developer did not hunt for the software on the open web, he delegated the lookup to a model he considered reliable, and security teams that spent years hardening against search-engine poisoning and typosquatted domains have no obvious defense against an assistant that volunteers a single canonical-looking link mid-conversation. Users rarely audit a URL handed to them conversationally, and that is precisely the gap this campaign exploited. Lunah caught the compromise in time, disconnected the machine from the network and carried out a full operating system reinstall — the standard playbook any engineer would run in the same position, and one that in almost every malware case ends the incident.

SKILL.md Backdoor Survives a Clean Reinstall

The reinstall did not end it. While restoring files from a backup onto the freshly wiped machine, Lunah discovered modifications to a document named SKILL.md, which he had used as a personal style guide for the AI tools in his workflow. The attackers had restructured the plain-text file so that, once copied onto any clean computer, it automatically reached out to a server under their control, re-downloaded the infostealer and resumed harvesting credentials — turning a configuration document into a persistence mechanism that survived a complete system rebuild. The incident drew the attention of NEAR Protocol co-founder Illia Polosukhin, who warned that securing the infrastructure used by autonomous AI agents has become critical and that campaigns employing what he calls “context poisoning” are growing. Context poisoning, in short, means injecting malicious content into the instructions, memory or configuration data an AI system relies on, so that the model's answers or the actions it triggers drift toward the attacker's objective — in this case, a poisoned skill file that quietly weaponized a restore-from-backup routine. The practical takeaway for Web3 developers is blunt: files ending in .md or .json can no longer be treated as harmless prose, because an AI runtime may execute whatever those files tell it to do. Readers tracking the market in real time can follow live spot and futures prices on Binance.

AI Config Files Become Attack Surface

Our reading of this case is that the attack surface has shifted from the code a developer runs to the context a developer feeds the models — and that is a harder boundary to police. Developers who work with agents that can hold keys, the premise behind the emerging AI crypto wallet segment, now face a threat model where a style guide is as dangerous as a binary. The disciplined response is to review AI skill files like executable code, isolate machines holding Bitcoin holdings and other assets from AI tooling, and treat every restored backup as potentially attacker-written.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.