Crypto Workers Fall Prey to LLM Poisoning as Malicious Links Spread
The growing reliance on generative artificial intelligence (AI) in the crypto and blockchain industries has exposed workers to a new wave of security risks. One such risk is LLM poisoning, where malicious attackers compromise AI models to distribute poisoned links or code.
Refi Hub co-founder Numa Lunah recently fell victim to this type of attack, when he followed a download link provided by Claude chat that led to malware installation on his laptop. The compromised link was so convincing that it mimicked the writing style guide of Lunah's own, but contained instructions to silently re-download malware and steal credentials.
Lunah's experience is not an isolated incident; Microsoft warned in 2026 about the risk of LLM poisoning and its potential to steer users towards malicious links. This highlights the need for a fundamental shift in security culture within the industry.
Unlike regular knowledge workers, crypto professionals hold sensitive information that cannot be easily revoked, such as seed phrases, API keys, and session cookies. Therefore, it is crucial for them to treat every AI suggestion with skepticism, regardless of its source. This means being vigilant and double-checking any links or code provided by AI models before executing them.