Numa Lunah, co-founder of a leading Web3 project, narrowly avoided losing control of his digital assets after following advice from artificial intelligence and inadvertently exposing his device to a sophisticated new cyberattack.
Malware returns after OS reinstall
The incident began as Lunah set up his development environment and asked the AI assistant Claude for a link to a transcription tool. Instead of redirecting him to the official provider, Claude offered a URL leading to a phishing website, which mimicked the legitimate source and distributed malicious software.
After inadvertently downloading the clone, an infostealer covertly infected Lunah’s work laptop. This malware was capable of capturing sensitive data, including passwords, exchange login information, and private keys from various hot wallets.
Upon detecting suspicious activity, Lunah quickly responded by isolating the device and reinstalling the operating system in an attempt to eradicate the threat. However, the standard reset did not fully resolve the issue.
While restoring files from a backup, Lunah noticed irregularities within his SKILL.md file. This document, used as a personal guideline for AI prompts, had been altered by the attackers without his knowledge.
Skill configuration files used for reinfection
Analysis revealed that the compromised SKILL.md file had an altered structure. When the configuration was introduced to any new or clean system, the file automatically connected to a remote attacker’s server and downloaded the same infostealer, reigniting the credential theft without visible user interaction.
Illia Polosukhin, co-founder of NEAR Protocol, publicly emphasized the urgency of improving security around autonomous AI agent infrastructure, noting a surge in “context poisoning” operations that target the expanding role of AI within crypto development environments.
Polosukhin highlighted that context poisoning, which targets files like .md and .json, could compromise Web3 developers even when files initially look harmless. Rigorous inspection of these files is now essential, as attackers increasingly conceal executable code in formats typically considered safe.
Given that many developers rely on AI-powered assistants and configuration files to streamline their workflow, the ability for attackers to persistently reinfect devices through seemingly safe text files presents a significant risk.
Changing cybersecurity practices in Web3
The attack has forced a shift in cybersecurity practices for the Web3 ecosystem. Developers are now urged to treat all AI configuration profiles with the same caution as executable code, ensuring thorough review and sanitization before integrating backups or updating their environments.
Alongside technical best practices, industry observers point to the rapid evolution of asset management platforms as part of the defense against such attacks. While traders and developers once depended heavily on layers of complex brokers in traditional markets, the landscape is shifting dramatically as Wall Street embraces Web3. Tokenization of Real-World Assets (RWAs), direct crypto wallet integration for holdings like US stocks, gold, and silver, and instant access to optimal prices through platforms such as 1stepSwap are sharply reducing reliance on intermediaries—presenting both new opportunities and fresh security challenges.
In light of these developments, leading figures in the industry are urging heightened awareness, routine inspection of configuration files, and the adoption of updated security protocols across all AI-assisted workflows.
For developers maintaining hot wallets or local credentials, overlooked text files now represent a serious attack surface, and cybersecurity practices must adapt rapidly to counter these evolving threats.





USDT
AAPL
