A trader using the account @cladzsol recently lost approximately $600,000 to a phishing trap. The loss occurred not from mistakenly signing a blockchain transaction, but from running a script from a page masquerading as a Cloudflare security verification screen.
Crypto account @insidecalls warned that this attack displays a spoofed Cloudflare verification check in the user’s browser window. The fake page then prompts visitors to execute a payload with administrator privileges on the Windows operating system.
This hack differs from typical wallet-draining tactics that rely on transaction approvals via digital wallet connections. Instead, the attack directly prompts victims to execute malicious code on their machines. Once the on-screen instructions are followed, the malicious script is automatically downloaded and executed.
Infiltrating Through Coin Metadata
The malicious link was embedded in the website information field attached to the meme coin’s profile. When a trader scans for new tokens and opens the project’s link to conduct research, they land directly on the fake Cloudflare verification page.
The vector stems from how token tracking platforms and trading aggregators operate. Various aggregator platforms commonly display website details or social media accounts by pulling information from token metadata. Attackers manipulate this metadata field to insert their malicious trap URLs.
Exploiting the Fast Pace of Retail Traders
The meme coin category was targeted because the niche is populated by many novice users who are susceptible to scams. The attack also exploits the habit of meme coin traders moving rapidly between token pages, social media accounts, and project websites.
That lightning-fast trading pace makes it easy for victims to overlook suspicious details on the fake Cloudflare verification screen. The @cladzsol incident serves as a warning that hacking threats are no longer limited to rejecting suspicious crypto wallet connections, but also require extra vigilance when a website suddenly requests permission to execute programs on a user’s computer. Reported by crypto.news.
Also read: Revolut Handed Customer Passports and Selfies to Scammers - Started from a Single ‘Government’ Email
Disclaimer: This article is for informational and educational purposes only, not financial advice. Cryptocurrency assets are highly volatile and carry significant risk. Always do your own research (DYOR) and never invest more than you can afford to lose.




