Poisoned AI links target crypto employees

Attackers use AI-crafted messages with malicious links to steal credentials or install malware, risking account takeovers and fund loss at crypto firms.

Security teams report that attackers are using large language models to generate highly convincing, personalized messages containing malicious links that target employees at cryptocurrency companies. The links lead recipients to fake sign-in pages, cloud-hosted files or documents that deliver remote access tools and can result in stolen credentials, session tokens or installed malware.

Researchers and incident responders say the campaigns accelerated in recent months. Attackers scrape public profile data and other information to select targets such as engineers, operations staff, product managers and executives who can approve transactions or access signing systems. Messages impersonate colleagues, vendors or legitimate services and are delivered by email, Slack and other messaging channels. Some poisoned links also appear in developer forum comments and fake job postings on professional networks.

Attackers register lookalike domains, create deceptive subdomains or host pages on compromised cloud accounts so links look legitimate in previews. Some use URL shorteners or redirect chains that hide the final destination. In several incidents recipients were directed to shared documents that requested OAuth consent or sign-in, giving attackers valid tokens or session cookies instead of a password.

Security teams report two main outcomes when employees follow the links. Credentials or session tokens can be harvested and used to access internal dashboards, code repositories or wallet infrastructure. Files downloaded from cloud hosts can install remote access software or credential-stealing tools, enabling attackers to move laterally inside networks. Because some staff directly control signing keys or withdrawal processes, a compromised account can lead to unauthorized transfers and drained wallets.

An incident response manager at a mid-size crypto exchange described a case where an engineer clicked a link that appeared to point to an internal S3 file. The link delivered a file that launched a web-based remote management tool. The company revoked access tokens, applied its incident response playbook and blocked the hosting domain before any funds moved, according to the manager.

A security researcher at a blockchain security firm warned, “People expect a hurried, imperfect message from an attacker; now the messages look professional and specific enough that staff lower their guard.” Security teams say the higher quality of copy increases the need for link verification and provenance checks.

Companies are putting technical controls in place. Recommended measures include restricting which domains can host shared links, enforcing hardware security modules and hardware wallets for signing, implementing strict OAuth app approval workflows, and using browser isolation for untrusted content. Multifactor authentication and short session lifetimes reduce the value of stolen credentials. Teams are also increasing phishing training and simulations, and separating duties so no single account can authorize large transfers.

Security teams advise inspecting full URLs rather than relying on preview text, checking hosting domains against approved allowlists, hovering to view destination previews before clicking, and navigating directly to vendor sites instead of following in-message links. Continuous monitoring and rapid incident response remain part of operational practice for firms responding to these attacks.

The material on GNcrypto is intended solely for informational use and must not be regarded as financial advice. We make every effort to keep the content accurate and current, but we cannot warrant its precision, completeness, or reliability. GNcrypto does not take responsibility for any mistakes, omissions, or financial losses resulting from reliance on this information. Any actions you take based on this content are done at your own risk. Always conduct independent research and seek guidance from a qualified specialist. For further details, please review our Terms, Privacy Policy and Disclaimers.

Articles by this author