Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
A case has emerged in which Numa Lunah, co-founder of a Web3 project, nearly lost control of digital assets after following a download link recommended by artificial intelligence (AI).
On Aug. 30 (all dates local time), blockchain media outlet U.Today reported that the case revealed a new attack path that plants a backdoor hidden in an AI skill configuration file to reinfect a computer even after an operating system reinstall.
The problem began as Numa Lunah set up a work environment and asked Claude for a download link to a voice transcription application (app). Claude provided a phishing address mimicking the program’s official site, and he downloaded the software through it. In the process, an infostealer designed to steal passwords, exchange account information and hot wallet private keys was covertly installed on his work laptop.
Numa Lunah detected signs of compromise in time, immediately isolated the infected device and fully reinstalled the operating system. But the attack did not end there. While restoring backup files, he found that a SKILL.md document he used as a personal AI style guide had been tampered with.
The attacker had altered the structure of the text file itself. If the configuration profile was linked to a new, clean computer, the document was designed to automatically connect to the attacker’s server, download the infostealer again and resume collecting account information. This was why resetting the operating system was not enough to ensure safety.
The case also raised a warning about security practices among Web3 developers. Critics say AI skill configuration files in .md or .json format can no longer be seen as harmless text and should be treated like executable code. The core point is that malware can be revived not only through normal program installation paths but also through document-style configuration files that AI reads and loads.
Illia Polosukhin (일리야 폴로수킨), co-founder of the Near Protocol, also took note of the incident. He warned that securely protecting infrastructure for autonomous AI agents is very important, and pointed out that attack campaigns using the ‘context poisoning’ tactic have been increasing recently.
The attack poses a direct risk in particular to Web3 developers whose local devices are the main targets. That is because exchange credentials and hot wallet private keys often coexist in the same work environment. The case showed a growing need to check for structural changes and the possibility of connections to external servers first, rather than unconditionally trusting AI-related document files during configuration restoration or work environment migration.
About the Author
Seung-a Yooysah@d-today.co.kr
Keyword
#Claude#Numa Lunah#SKILL.md#Near Protocol#context poisoningCopyright © DigitalToday. All rights reserved. Unauthorized reproduction and redistribution are prohibited.
Source: www.digitaltoday.co.kr
