钓鱼攻击激增:迷因币页面沦为重灾区,虚假验证屏幕窃取巨额资产
近期,加密货币社区对一波激增的钓鱼攻击发出警报。迷因币(Meme Coin)的上市列表及代币展示页面已成为黑客的主要目标。攻击者通过篡改代币元数据,嵌入指向欺诈性 Cloudflare 验证页面的链接,诱导交易者点击。
针对毫无防备的交易者的钓鱼手段
攻击者开始更新社区代币资料中的虚假网站链接,这些链接随后会自动显示在广泛使用的去中心化资产追踪平台上。此类策略已导致重大损失;据报道,一名受害者因此类骗局损失了 60 万美元。
此类攻击的核心手法被称为“ClickFix”。用户被提示点击一个伪造的“验证你是人类”复选框,该操作会通过 JavaScript 秘密将恶意命令复制到用户的剪贴板中。随后,用户会被指示将该命令粘贴到 PowerShell 或终端中并执行。
运行此脚本后,个人会无意中安装如 Lumma Stealer 等恶意软件。该软件旨在搜索系统中的敏感文件、提取浏览器数据,并窃取加密钱包凭证。
Cybersecurity professionals warn users that legitimate authentication services, such as Cloudflare, do not require entering management scripts to pass Captcha checks. Experts recommend closing suspicious token pages immediately and maintaining strict isolation between the main crypto wallet and the browser used to browse unfamiliar memin.
Important note: Legal Cloudflare authentication does not involve entering scripts in PowerShell or the terminal. Following instructions from suspicious pages can result in huge financial losses.
Community issues warnings and offers preventive advice
Crypto users and security analysts have expressed concerns about the growing threat posed by fake verification screens after well-known trader Danny lost $600,000 in such attacks. Sam Security pointed out that the ClickFix attack leverages users 'trust in familiar security tips, emphasizing that the victim's manual input process allows these plans to bypass traditional download-based protections.
Another user recalled that he narrowly missed the trick while visiting a juice store website in the early morning because the site displayed similar malicious scripts. The individual realized the risk at the last minute and reformatted the computer to protect his data. This case highlights how timing, fatigue, and recognizable page elements can cause users to misjudge potential fraud.
Investor Alex Clive recommends that traders verify crypto projects through their official X (formerly Twitter) account and trusted listing platforms such as CoinMarketCap and CoinGecko. Clive urged users to check domain names carefully, warning that taking a few extra seconds to verify could prevent huge losses.
Scammers impersonate venture capital firm and browser extensions hijacked
Threats have expanded their tactics, using LinkedIn to impersonate venture capital firm, founder of targeting crypto project. Moonlock Lab research revealed that people posing as representatives of companies such as SolidBit, MegaBit and Lumax Capital contacted victims under the guise of partner opportunities. They then directed the target audience to fake meeting pages that utilized fraudulent Cloudflare checks as part of a ClickFix scam.
This technology leverages social engineering to persuade users to paste harmful commands into their computer terminals. Moonlock Lab identified a frequent contact person, using the alias Mykhailo Hureiev, who is said to be one of the co-founders of SolidBit Capital.
In related activity, the attacker compromised the Chrome extension QuickLens (previously used for Google Lens searches). Annex Security founder John Tuckner revealed that ownership of the extension changed hands on February 1, and a malicious update was released shortly thereafter. This affected approximately 7,000 users, and the update deployed the ClickFix tool and collected sensitive data, including encrypted wallet information, Gmail access and login credentials.
Glossary: Lumma Stealer
一种信息窃取型恶意软件,会在计算机中搜索敏感文件、浏览器存储的密码以及加密钱包凭证,并将收集到的数据传输给攻击者。

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following