Memecoin phishing is targeting traders with fake Cloudflare verification screens. One trader reported losing about $600,000 after running a malicious script.
Market reports on September 16 said several popular meme coin pages redirected visitors. These pages showed fake verification screens. They told users to execute commands. As a result, malicious scripts could run and steal crypto assets.
Meme coin phishing uses fake verification prompts
Crypto trader @cladzsol said he lost around $600,000. Meanwhile, crypto account @insidecalls warned about the attack. It said a website displayed a fake Cloudflare check. Then it asked the user to run a payload. That payload required administrator privileges on Windows.
This method differs from many wallet-draining attacks. Those attacks rely on connecting a wallet. They also rely on approving a malicious transaction. In contrast, this phishing page tries to make the victim execute code directly.
How the attack spreads
The malicious links appeared through website fields attached to meme coins. Traders scanning new tokens may open those links. They might do this while researching a project. However, they land on a page that resembles a legitimate Cloudflare check.
Once the user follows the instructions, a malicious script can download. Then it can execute on the computer. Inside Calls described a similar sequence. It discussed the loss suffered by @cladzsol. The fake verification process asked the user to run an administrator payload. The trader later said the incident cost him $600,000.
The attack relies partly on routine behavior. Meme coin traders often move quickly between pages. They check token pages, social accounts, and project websites. Consequently, they may not pause to verify every link.
Some tracking and trading platforms display website and social media information. That information comes from token metadata. Reports on the latest campaign said token creators can change those fields. People who later claim control of a project’s community presence can also change them.
Therefore, attackers can place a malicious website in a field. Traders may expect that field to contain the project’s official homepage. The reports raised concerns about delays in reviewing links. These links appear on aggregation services such as DexScreener. However, the reports showed no evidence that DexScreener itself was compromised.
Crypto phishing attacks increasingly use trusted-looking pages
The latest campaign follows several attacks. In those attacks, attackers copied familiar websites and brands. The goal was to persuade crypto users to interact with malicious software.
In August, a Hyperliquid trader lost around $550,000. The trader clicked a sponsored Google advertisement. That ad led to a counterfeit version of the decentralized trading platform. Blockchain security firm Salus linked the infrastructure to the Inferno drainer ecosystem.
The August 13 theft involved a fake Hyperliquid website. Paid search results promoted that site. Salus said the infrastructure included malicious scripts. It also included approval-command generation and automated draining. Cross-chain withdrawals and consolidation tools were also present.
Crypto.news previously reported in July about wallet drainer services. Those services commonly use fake project websites and fraudulent airdrops. They also use malicious social media links and counterfeit token pages. These methods place users in front of dangerous transaction requests.
In those attacks, the malicious site typically asks the victim to connect a wallet. Then it asks the victim to approve a transaction or signature. That approval can give an attacker-controlled contract permission. The contract can then transfer tokens. It does not need the wallet’s seed phrase or password.
The fake Cloudflare campaign uses a different route. The page instructs victims to execute a script on their computers. Once code runs locally, the attack moves beyond an on-chain approval.
Malware has become another route into crypto wallets
Recent campaigns have repeatedly combined phishing with malware. That malware aims to collect wallet information. It also collects other credentials from computers.
A fake Claude desktop application appeared in August. It distributed RevStealer malware. According to cybersecurity company Morphisec, that malware targeted more than 50 cryptocurrency wallets.
The malware hid inside an application. Attackers presented it as “Claude Opus 5 Free Desktop.” Morphisec said the program could collect information from crypto wallets. It also targeted password managers and web browsers on Windows systems. Then it sent stolen records to attacker-controlled infrastructure.
A separate campaign emerged in May. It used malicious developer packages. It targeted cryptocurrency and artificial intelligence developers. Security platform Socket identified at least 34 malicious packages. It also found 384 related versions across npm, PyPI, and Rust ecosystems.
Socket said the TrapDoor campaign aimed to collect wallet data. It also targeted GitHub tokens and cloud credentials. API keys and SSH access were also at risk.
The delivery methods differed. Nevertheless, both campaigns depended on getting victims to install or execute software. That software appeared legitimate.
Meme coin traders have faced similar malware attacks before
Meme coin trading has previously given attackers opportunities. That is because traders frequently use third-party tools. They also rely on social media recommendations. They often visit unfamiliar project websites.
In August 2024, Solana DEX aggregator Jupiter warned users. It flagged a malicious Chrome extension called Bull Checker. Several users had reported wallet drains. Attackers promoted the extension as a tool for viewing meme coin holders. Jupiter’s investigation found it could modify transactions. It inserted instructions that transferred tokens to another address.
A separate November 2024 incident involved a Gigachad meme coin investor. The investor reported losing $6.09 million. This happened after clicking a fake Zoom meeting link. The victim said malware downloaded onto the laptop. Then the attacker drained three wallets. Those wallets contained 95.27 million GIGA tokens.
Onchain Lens said the attacker later sold the stolen tokens. The sale brought 11,759 SOL. That was worth roughly $2.1 million at the time.
The September 16 reports advised traders to close any supposed Cloudflare verification page. They should not interact with it if it asks them to execute commands or scripts.
How to protect yourself
First, never run commands from a verification page. Second, verify project links through official channels. Third, use hardware wallets for large holdings. Additionally, keep software updated and avoid unknown browser extensions. Finally, treat urgent verification prompts as a red flag. In short, pause before you click or execute.