Meme Coin Phishing Scam Hack
What happened
On September 16, 2026, a social engineering campaign disguised as a Cloudflare human verification check targeted meme coin traders on DEX aggregators like DexScreener and Axiom. Bypassing Web3 wallet signatures entirely, the attack tricking victims into running local OS-level scripts resulted in total reported losses exceeding $600,000.
Attackers embedded malicious URLs within public token metadata fields on DEX aggregators. Visiting these links redirected users to a fake Cloudflare page that silently copied a malicious PowerShell command to the system clipboard while prompting the sequence Win + R + Ctrl + V + Enter. Running the payload via native Windows tools bypassed browser security, installing an infostealer that granted attackers full host access to extract private keys, browser session credentials, and drain irectly ~$600,000 from top trader.
Protocol details
Evidence
- report Report crypto.news
Understand the attack patterns
Build your security review skills
Work through hands-on labs covering real exploit mechanics, review techniques, and defensive patterns.