Attack on crypto developers using Claude AI.



The North Korean hacker group Famous Chollima launched the PromptMink campaign, in which AI models, including Claude from Anthropic, are used to inject malicious code into crypto projects.

Malicious actors publish fake NPM packages, passing them off as legitimate tools for crypto development — for example, validate-sdk/v2, solana-launchpad/sdk, and others. Installing such a package infects the project and can be used to steal private keys, withdraw funds, and remotely access the computer.

Popular libraries and tools for Solana, Ethereum, and other blockchain ecosystems have been targeted.

According to campaign data, the attacks have been ongoing since September 2025. Moreover, one of the similar malware — GhostClaw — stole data from 178 developers in the past month.
SOL-0.49%
ETH-0.13%
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • Comment
  • Repost
  • Share
Comment
Add a comment
Add a comment
No comments
  • Pin