Crypto Trader Loses $600,000 in Fake Cloudflare Phishing Scam
A crypto trader lost approximately $600,000 after falling victim to a phishing scheme that mimicked Cloudflare's human-verification process. The attack, detailed on September 15, 2026, by Inside Calls, involved the trader danny (@cladzsol) executing a malicious command on his Windows computer. The phishing page required no wallet connection or blockchain approval, instead instructing users to paste a command into the Windows Run dialog, which then installed malware to steal assets.
The attackers embedded malicious links within token metadata fields on meme-coin tracking pages, a common research tool for traders. This method, known as ClickFix, bypasses traditional blockchain safeguards by targeting local devices instead of requiring wallet approvals. The trader later stated he retained about $400,000 and acknowledged his mistake in following the prompts.
Security researchers warn that similar tactics have been observed beyond crypto, including compromised Ukrainian business sites serving fake Cloudflare screens. These pages exploit the familiarity of Cloudflare interstitials to lower suspicion. Experts advise closing any verification page that requests command execution, verifying domains independently, and keeping high-value wallets on separate devices.
The incident highlights the evolving nature of crypto phishing, which now often avoids explicit wallet approvals in favor of local device compromise. Ongoing monitoring by researchers continues to uncover new variants of this clipboard-and-execute approach across various platforms.