Meme Coin Phishing Scam Hack

Reported loss $600K
Phishing

What happened

On September 16, 2026, a social engineering campaign disguised as a Cloudflare human verification check targeted meme coin traders on DEX aggregators like DexScreener and Axiom. Bypassing Web3 wallet signatures entirely, the attack tricking victims into running local OS-level scripts resulted in total reported losses exceeding $600,000.

Attackers embedded malicious URLs within public token metadata fields on DEX aggregators. Visiting these links redirected users to a fake Cloudflare page that silently copied a malicious PowerShell command to the system clipboard while prompting the sequence Win + R + Ctrl + V + Enter. Running the payload via native Windows tools bypassed browser security, installing an infostealer that granted attackers full host access to extract private keys, browser session credentials, and drain irectly ~$600,000 from top trader.

Protocol details

Classification Token
Protocol Type Exploit/Phishing

Evidence

Understand the attack patterns

Build your security review skills

Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.