AI Malware Attack Targets Crypto Wallets Through AI Configuration Files
Nearly losing control over his digital assets was Numa Lunah's harrowing experience after an AI-recommended download link led to the installation of information-stealing malware on his work laptop. The incident has highlighted a new attack technique where malicious code is concealed inside files used to configure artificial intelligence tools.
The attack began when Lunah asked Anthropic's Claude for a download link to a voice transcription application. However, the AI system provided a phishing website that closely resembled the legitimate site. Unbeknownst to Lunah, he downloaded the software from the recommended address, allowing an infostealer to enter his device.
The malware was designed to obtain sensitive information, including passwords, cryptocurrency exchange credentials and private keys associated with hot wallets. This type of attack is particularly serious for Web3 professionals who frequently keep financial credentials and development tools on the same computers.