Don't want to trade it yourself?
Our desk runs DEX portfolios on profit share.
Sergey Khukharkin
Choose us on Google
- Trader known as cladzsol reported losing around $600,000.
- He said his computer was infected with malware after interacting with a fake Cloudflare verification.
- The scheme matches the ClickFix technique, where the victim is persuaded to run a malicious command themselves.
<a href="https://xpertsstudio.com/is-your-<a href="https://xpertsstudio.com/sec-and-cftc-vow-crypto-rules-after-senate-kills-clarity-act/” title=”SEC and CFTC Vow Crypto Rules After Senate Kills CLARITY Act”>crypto-investment-opportunity-a-scam/” title=”Is your crypto investment opportunity a scam?”>Crypto trader known as cladzsol reported losing around $600,000 after his computer was compromised.
According to the victim, he managed to save around $400,000. He said the device was infected with malware, and that he himself was responsible for what happened.
The Inside Calls account published additional details about the incident. According to its data, the malicious site mimicked a Cloudflare verification and prompted the user to open the Windows system dialog, paste a pre-copied command, and run it.
In the published screenshot, the instructions include the sequence Win + R, Ctrl + V, and Enter. Unlike a classic crypto drainer, this scheme does not necessarily require connecting a wallet or signing a malicious transaction — the user runs the code on their own device.
Inside Calls initially claimed the incident happened while trying to use a bridge in the Arc ecosystem. However, cladzsol later clarified in the comments that the attack was not related to Arc.
The described mechanism matches the ClickFix social engineering technique. Microsoft previously documented campaigns in which attackers mimicked Cloudflare Turnstile, automatically copied a malicious command to the clipboard, and convinced users to execute it
Inside Calls also claimed similar phishing links are being spreadause token profiles on aggregators can contain external links to websites and social media. For example, the DEX Screener API explicitly supports such links in token profiles
At the time of writing, however, there is no independent confirmation that cladzsol reached the malicious re
Earlier, we reported on a wave of phishing attacks targeting Trezor users. The company linked it to a breach of a third-party email provider.
Source: incrypted.com
