
A cryptotrader under the pseudonym cladzsol reported losing about $600,000 after his computer was infected with malicious software. According to him, he retained about $400,000 and admitted that he performed actions that allowed attackers to access the device.
Additional details of the incident were published by the Inside Calls account. According to the data presented, the user landed on a site that mimicked a Cloudflare check. The page offered to undergo verification using a Windows system window: open the window with the Win + R combination, paste a pre-prepared command from the clipboard, and press Enter. This sequence effectively prompts the user to run malicious code themselves. The attack mechanism corresponds to the ClickFix social engineering technique. Microsoft previously described campaigns in which attackers, under the guise of Cloudflare Turnstile, showed the user a false verification error message and suggested executing a command via Windows Run or PowerShell. Unlike common cryptocurrency drainers, such a scheme does not necessarily require connecting a wallet and confirming a transaction: the initial point of compromise becomes the device itself.
Initially, Inside Calls suggested that the trader encountered the attack while attempting to use a bridge in the Arc ecosystem. Later, cladzsol clarified that the incident was not related to Arc. Therefore, the specific resource through which the user landed on the fake Cloudflare page remains unidentified. Inside Calls also reported the spread of similar phishing links through memecoin pages. Token profiles on some cryptocurrency aggregators can indeed contain external links to websites and social networks, but there is no independent confirmation that cladzsol accessed the malicious page in this way. The incident demonstrates the peculiarity of ClickFix attacks: attackers use familiar web interface elements and system notifications to convince the user to execute a potentially dangerous command themselves. For crypto users, such attacks are particularly sensitive, as compromising the computer can provide attackers access not only to the browser but also to data related to trading platforms and cryptocurrency wallets.





