Refi Hub Founder Hacked via Claude Chat Link That Sought Bitcoin (BTC) Seed Phrases

Refi Hub co-founder Numa Lunah was hacked after a Claude chat link delivered malware, exposing crypto workers' seed phrases and exchange API keys to theft.

(09:43 PM UTC)
4 min read
AI SummaryAI
  • Refi Hub co-founder Numa Lunah was hacked after pasting a Claude chat download link into his terminal
  • The attacker planted a tampered SKILL.md file that re-downloaded malware each time Claude loaded it
  • Lunah wiped his laptop and reinstalled the operating system, reporting no sensitive data leaked
  • Microsoft Defender researchers warned cryptojacking evolved from SEO poisoning to LLM answer poisoning
k7rq2fdm

Claude Chat Link Delivered Malware

Numa Lunah, co-founder of tokenization platform Refi Hub, says he was hacked last week after following a download link that Claude — the AI assistant built by Anthropic — served him inside a chat window. Lunah, who was installing a voice transcription application at the time, received the link directly from the chatbot and pasted the accompanying command into his terminal. He disclosed the incident in a post on X, writing that the link came from the Claude chat interface and that everything appeared normal on the surface. It was not: the destination was a mimic site bundling malware, and the payload began executing the moment it ran, attempting to exfiltrate everything on his machine. Critically, Lunah reports that no sensitive information actually left his device. His response was aggressive — he wiped the laptop he was using and performed a clean reinstall of the operating system. The episode is a warning shot for digital-asset professionals specifically. Unlike an office worker whose compromised passwords can simply be rotated after an incident, practitioners in this industry hold secrets that are effectively impossible to revoke once stolen: hardware wallet pairing data, seed phrases for mobile wallets, hot wallet JSON files, exchange API keys with withdrawal permissions, deployer keys, Lightning macaroons, and session cookies for centralized exchange dashboards. Any one of those items can translate directly into the loss of Bitcoin (BTC) and other holdings with no recourse, which is precisely why attackers have begun treating people who work in crypto as a distinct and unusually valuable target class.

Malicious SKILL.md Hid in the Backup

The most troubling discovery came after the cleanup, during restoration from backup. Lunah found a tampered SKILL.md file built for Claude Code — a file that looked, by his own account, almost identical to the writing style guide he had authored himself. Buried deep inside were instructions designed so that every time the AI loaded the file, it would silently re-download the malware and harvest his credentials without his knowledge. The technique was not improvised on the spot; it belongs to an evolving playbook. Microsoft Defender researchers warned months ago that cryptojacking campaigns had progressed from simple search-engine-optimization poisoning toward outright poisoning of large language model answers. The documented attack patterns against models such as Gemini, Claude, Copilot and ChatGPT include tricking chatbots into recommending attacker-controlled download links, distributing fake installers dressed up with AI branding — including counterfeit Claude and ChatGPT desktop applications — seeding polluted code repositories, and planting tampered agent skills like the one Lunah uncovered. The exposure is broad: developers building on networks such as Arbitrum or LayerZero, and indeed anyone in the industry who relies on AI coding assistants daily, face the same vector. For traders and institutions selecting venues through resources like our guide to the best crypto exchanges, the parallel risk sits in the session cookies and API keys those accounts generate — credentials an attacker can lift straight from a compromised machine. Readers tracking the market in real time can follow live spot and futures prices on Bitget.

Verify Before the AI Touches Anything

COINOTAG's reading is that the load-bearing document here is Lunah's own firsthand account on X, which states plainly that the link originated from the Claude chat interface — a primary-source admission that AI output was the attack delivery channel. What saved him was not antivirus software but procedure: he says he now reads every skill, hook and configuration file before letting the AI touch any of them. That is the correct default in an environment where the most dangerous vulnerability is the instinct to trust a convenient answer. Treating every AI suggestion as inherently hostile is not paranoia; for anyone holding irrevocable crypto keys, it is operational survival.

COINOTAG News Desk

COINOTAG News Desk

COINOTAG's editorial and research desk.

How our News Desk works
AI-Assisted

AI-generated, AI-reviewed, under COINOTAG editorial oversight.

Price-Impacting News

More News Articles