A recent security incident shared by Refi Hub co-founder Numa Lunah has underscored growing concerns regarding artificial intelligence security in the blockchain sector. Lunah revealed that he was compromised after following a download link provided within a Claude chat window while attempting to install a transcription app.
According to Lunah, he pasted a command into his terminal from a Claude-supplied link that appeared legitimate. The link directed him to a copycat site bundling malware that immediately attempted to access his data. Although Lunah wiped his laptop and performed a clean install, he subsequently discovered a poisoned SKILL.md file for Claude Code within his backups. The file mimicked his personal writing style guide but contained hidden instructions to silently re-download malware and steal credentials whenever loaded by the AI.
This event aligns with broader warnings issued previously by Microsoft Defender Experts regarding large language model (LLM) answer poisoning. Security alerts have highlighted that AI models across the industry can be manipulated to recommend attacker-controlled download links, present AI-branded fake installers, and distribute poisoned codebase and agent skills.
Security experts note that digital asset workers face uniquely high stakes compared to traditional knowledge workers. While standard laptops often hold reusable secrets that can be easily revoked following a security breach, crypto industry workers frequently handle un-revocable assets. These include seed phrases, exported keystore files, hot-wallet JSON files, exchange API keys with withdrawal rights, deployer keys, Lightning macaroons, hardware-wallet companion data, and session cookies.
The incident serves as a reminder that human trust in convenient AI answers remains a significant vulnerability. Security professionals suggest that workers in the digital asset sector should treat all AI-supplied suggestions and links as inherently hostile.


