On September 1, 2026, according to Huntress, a phishing operation targeting cryptocurrency users was uncovered: unknown hackers did not launch their attack from obscured corners but instead disguised themselves as "familiar" figures, using forged Google Docs invitations to gradually lead victims to pre-prepared trap pages, guiding them to download malware from links hosted on GitHub; at the same time, the attackers also set up imitation Claude.ai pages, using almost identical interfaces to lure victims into entering sensitive information, further amplifying the threat. The entire operation was very clearly directed at users holding cryptocurrency wallet assets, regardless of whether they were using Mac or Windows: the former could unknowingly have Atomic macOS Stealer implanted, with risks of exposing keychain and browser data related to wallets; the latter, according to a single-source report cited by TechFlow, was pushed to install forged packages related to Google API or applications, aimed at stealing sensitive information. What appeared to be just an invitation for document collaboration or a familiar AI tool interface was connected to multiple attack vectors involving Google Docs, GitHub, and different operating systems, making this phishing incident seen as a cross-platform, focused test on core data of cryptocurrency wallets.
Fake Google Docs and GitHub
According to Huntress, the starting point of this attack chain is an ordinary-looking Google Docs document invitation. When target users received notifications like "collaborative editing" or "view shared document," the first thing they saw was the familiar Google login and document interface, and the entire process was almost indistinguishable from their daily work. When victims opened the document or the embedded links, the page would further prompt "download related files" or "get the full version," subtly guiding users to an external download address by habitual actions.
The real turning point is hidden within this hop: the malicious file was not directly attached in the email but hosted in a GitHub repository. When victims downloaded what appeared to be tools or programs from GitHub, which seemed to be "tech-savvy" or a "developer's platform," they naturally lowered their guard, unaware that they were obtaining a carefully prepared malicious installation file from the attackers. GitHub has long been misused in the security industry as a platform for distributing malicious binaries or scripts, and this incident continues this risk pattern—from forged Google Docs invitations to GitHub malicious file downloads, leading to the risk of sensitive data related to cryptocurrency wallets being stolen on devices. This chain represented a covert hunt that was hard for predominantly self-hosting wallet cryptocurrency users to detect at first glance.
Fake Claude.ai Page with Social Deception
On the other end, the attackers were not satisfied with completing the loop with forged Google Docs and GitHub; they also specially built a set of imitation Claude.ai pages. According to Huntress, these pages closely aligned with the official interface in color scheme, logos, and layout of the dialogue input box, making it difficult for users opening it for the first time to visually detect any anomalies, treating it as a regular AI collaboration or meeting tool.
To entice the target into this trap, the attackers moved the stage to X. Public information shows they impersonated media professionals, including CoinDesk employees, on X, initially establishing trust with phrases like "interview invitation," "column collaboration," and "closed-door meeting," then tossing out a so-called "meeting link" or "data sharing page," guiding victims to log in and input their contact email, work account, and even project-related information on the imitation Claude.ai page. For users holding cryptocurrency wallet assets, these sensitive data filled out in seemingly professional and formal meeting contexts, once exploited by the malicious program or operators behind it, could become the keys to the next step in stealing wallet-related information.
Atomic Stealer and Fake Google Programs
Once victims clicked the download link in the forged document or imitation Claude page, the subsequent "landings" on their respective devices began to show a clear divergence. According to Huntress, the payload targeting Mac users is a piece of malware named Atomic macOS Stealer, which specifically targets keychain and browser data on macOS systems, exporting from the system layer the sensitive information related to cryptocurrency wallets, allowing the asset clues that were originally sealed in local devices to be fully exposed to attackers.
On the Windows side, according to a single-source report cited by TechFlow, some users were guided to install fake "Google programs"—from the file names to descriptions all pointing to Google API or related tools, appearing to be legitimate components or update packages. Like the Atomic macOS Stealer, these fake Google installation packages also aimed at stealing sensitive information, just disguised with a "skin" more closely resembling habits of Windows users. The different malicious payloads assigned to different operating systems clearly indicate that this operation was not a crude casting of a net but rather an intentional selection of attack tools finely customized according to the user's operating system.
X Identity Impersonation and GitHub Malicious Repositories
Differentiating between Mac and Windows at the payload level is only the second half of the attack; the first half occurred on the social platform X. Huntress revealed that during this operation, attackers directly impersonated media professionals, including CoinDesk employees, on X, sending out meeting invitations or collaboration requests to cryptocurrency professionals and wallet holders. For the targets, this appeared more like a normal industry communication rather than cold spam messages; for the attackers, it was utilizing the long-standing identity impersonation issue on X to gain trust endorsements and communication access at minimal cost, then using forged Google Docs invitations to naturally guide the conversation towards malicious links. Social engineering no longer requires casting a wide net; by selecting a few "high-value" targets, malicious payloads could be introduced into their devices through just one or two DMs.
The documents disguised as collaboration documents point to download links for GitHub repositories. For many developers and cryptocurrency users, GitHub is almost a "default trusted" technical source, and this attack leveraged that psychology: the malware was hosted in public repositories and appeared in seemingly normal release formats. There is already an industry consensus that GitHub, as a code hosting platform, has historically not been used for the first time as a channel for distributing malicious binaries or scripts; this incident merely continues that risk pattern. The problem lies in that X emphasizes open speech and open collaboration, while GitHub, on the other hand, inevitably carries social expectations for content review and security gatekeeping. In the absence of finely defined interfaces and clear responsibility boundaries, attackers can parasitize this gray area, and those truly exposed to risk are ordinary cryptocurrency users who mistakenly treat "platform reputation" as a guarantee of security.
How Cryptocurrency Users Can Protect Themselves and Subsequent Observations
This round of attacks linking forged Google Docs, GitHub malicious files, imitation Claude.ai pages, and social engineering on the X platform has cracked the belief that many people see as “absolutely secure as long as self-hosted”: having the key does not equal peace of mind. When the attack surface shifts to document invitations, meeting requests, and developer tools, self-hosting wallets can also be instantly compromised when devices fall. For individual users, what they can do remains more about subtraction and verification—when facing document and meeting invitations, prioritize verifying the other party's identity through official or familiar channels, and refrain from clicking on links that require downloading executable files within documents; when it involves software installations, strive to obtain installation packages from project official sites or known trusted entries, avoiding running unknown programs directly stemming from random GitHub repositories or "colleague-recommended links"; any requests for inputting mnemonics, private keys, or complete wallet backups on pages by “Claude,” “customer service,” or “partners” should be regarded as warning signs. There are already voices in industry discussions emphasizing the migration of large assets to hardware wallets or other cold storage methods, compressing the cost of compromised everyday devices within an acceptable range, rather than exposing all holdings to the same computer or phone. It needs to be emphasized that there is currently no publicly reliable data indicating the number of victims and total stolen assets in this incident, the identity of the attackers has also not been confirmed, and continued attention is needed on whether platforms like Google, GitHub, and X will introduce clearer governance and disclosure mechanisms regarding identity impersonation and malicious file hosting, as well as whether security companies and project parties can synchronize similar threat intelligence in real time and transform it into visible protective options for users.
Join our community, let's discuss together and become stronger!
AiCoin exclusive Hyperliquid benefits: https://app.hyperliquid.xyz/join/AICOIN88
AiCoin exclusive Aster benefits: https://www.asterdex.com/zh-CN/referral/9C50e2
On-chain Telegram community: https://t.me/AiCoinWhaleData
On-chain community: https://www.aicoin.com/link/chat?cid=N6OVMor5g
AiCoin on-chain Twitter: https://x.com/aicoinwhaledata
免责声明:本文章仅代表作者个人观点,不代表本平台的立场和观点。本文章仅供信息分享,不构成对任何人的任何投资建议。用户与作者之间的任何争议,与本平台无关。如网页中刊载的文章或图片涉及侵权,请提供相关的权利证明和身份证明发送邮件到support@aicoin.com,本平台相关工作人员将会进行核查。



