Meme coin traders have been targeted by phishing pages disguised as Cloudflare verification screens, with one trader reporting a loss of approximately $600,000 after running a malicious script.
Summary
- Fake Cloudflare verification pages linked to meme coins are being used to trick traders into executing malicious scripts.
- Crypto trader @cladzsol reported losing approximately $600,000 after interacting with one of the malicious pages.
- Attackers can place phishing websites in token metadata fields that traders may open while researching newly launched meme coins.
- Users have been warned to close suspicious verification pages that ask them to execute commands or scripts on their computers.
Market reports on Sept. 16 said several popular meme coin pages have been redirecting visitors to fake verification screens that instruct them to execute commands on their computers, allowing malicious scripts to run and potentially steal crypto assets.
Crypto trader @cladzsol said he lost around $600,000 in the incident, while crypto account @insidecalls warned that the attack involved a website displaying a fake Cloudflare check before asking the user to run a payload with administrator privileges on Windows.
The method differs from many wallet-draining attacks that rely on users connecting a wallet and approving a malicious blockchain transaction. In this case, the phishing page attempts to get the victim to execute code directly on the computer.
Meme coin phishing pages use fake verification prompts
The malicious links have appeared through website fields attached to meme coins. Traders scanning newly launched tokens may open those links while researching a project, only to land on a page designed to resemble a legitimate Cloudflare verification check.
Once the user follows the instructions on the page, a malicious script can be downloaded and executed on the computer, according to the reports.
Inside Calls described a similar sequence when discussing the loss suffered by @cladzsol, saying the fake verification process asks the user to run an administrator payload on Windows. The trader subsequently said the incident had cost him $600,000.
The attack relies partly on the routine behavior of meme coin traders, who often move quickly between token pages, social accounts and project websites while looking for newly launched assets.
Some token tracking and trading aggregation platforms display website and social media information pulled from token metadata. Reports on the latest campaign said those fields can be changed by token creators or by people who later claim control of a project’s community presence.
Attackers can therefore place a malicious website in a field that traders may expect to contain the project’s official homepage. The reports raised concerns about delays in reviewing links displayed by aggregation services such as DexScreener, though no evidence presented in the reports showed that DexScreener itself had been compromised.
Crypto phishing attacks increasingly use trusted-looking pages
The latest campaign follows several attacks in which familiar websites, brands or online services were copied to persuade crypto users to interact with malicious software.
In August, a Hyperliquid trader lost around $550,000 after clicking a sponsored Google advertisement that led to a counterfeit version of the decentralized trading platform. Blockchain security firm Salus linked the infrastructure behind the site to the Inferno drainer ecosystem.
The Aug. 13 theft involved a fake Hyperliquid website that was promoted through paid search results. Salus said the infrastructure included malicious scripts, approval-command generation, automated draining, cross-chain withdrawals and tools for consolidating stolen funds.
Crypto.news previously reported in July that wallet drainer services commonly use fake project websites, fraudulent airdrops, malicious social media links and counterfeit token pages to place users in front of dangerous transaction requests.
In those attacks, the malicious site typically asks the victim to connect a wallet and approve a transaction or signature. The approval can give an attacker-controlled contract permission to transfer tokens without obtaining the wallet’s seed phrase or password.
The fake Cloudflare campaign uses a different route described in the Sept. 16 reports: victims are instructed to execute a script on their computers. Once code is running locally, the attack is no longer limited to obtaining an on-chain approval through the website.
Malware has become another route into crypto wallets
Recent campaigns have repeatedly combined phishing with malware designed to collect wallet information and other credentials from computers.
A fake Claude desktop application uncovered in August distributed RevStealer malware capable of targeting more than 50 cryptocurrency wallets, according to cybersecurity company Morphisec.
The malware was hidden inside an application presented as “Claude Opus 5 Free Desktop.” Morphisec said the program could collect information from crypto wallets, password managers and web browsers on Windows systems before sending stolen records to attacker-controlled infrastructure.
Another campaign disclosed in May used malicious developer packages to target cryptocurrency and artificial intelligence developers. Security platform Socket identified at least 34 malicious packages and 384 related versions across npm, PyPI and Rust software ecosystems.
Socket said the TrapDoor campaign was designed to collect wallet data along with GitHub tokens, cloud credentials, API keys and SSH access.
The delivery methods differed, but both campaigns depended on getting victims to install or execute software presented as something legitimate.
Meme coin traders have faced similar malware attacks before
Meme coin trading has previously provided attackers with opportunities to distribute malicious software because traders frequently use third-party tools, social media recommendations and unfamiliar project websites.
In August 2024, Solana decentralized exchange aggregator Jupiter warned users about a malicious Chrome extension called Bull Checker after several users reported having their wallets drained.
The extension was promoted to Solana users as a tool for viewing meme coin holders. Jupiter’s investigation found that it could modify transactions during interactions with decentralized applications and insert instructions that transferred tokens to another address.
A separate November 2024 incident involved a Gigachad meme coin investor who reported losing $6.09 million after clicking a fake Zoom meeting link. The victim said malware was downloaded onto the laptop, after which the attacker drained three wallets containing 95.27 million GIGA tokens.
Onchain Lens said the attacker later sold the stolen tokens for 11,759 SOL, worth roughly $2.1 million at the time.
The Sept. 16 reports advised traders who encounter a supposed Cloudflare verification page asking them to execute commands or scripts to close the page without interacting with it.






