Phone : +91 95 8290 7788 | Email : sales@itmonteur.net

Register & Request Quote | Submit Support Ticket

Home » Cyber Security News » AI Chatbot security risk: Startup founder hacked after pasting Claude command

AI Chatbot security risk: Startup founder hacked after pasting Claude command

AI Chatbot security risk: Startup founder hacked after pasting Claude command

https://etimg.etb2bimg.com/thumb/msid-133639924,imgsize-932922,width-1200,height=627,overlay-etciso,resizemode-75/vulnerabilities-exploits/ai-chatbot-security-risk-startup-founder-hacked-after-pasting-claude-command.jpg

A startup founder says he was hacked after pasting a terminal command that came straight out of a Claude chat window. Numa, co-founder of ReFi Hub, was installing a transcription app. Claude supplied the download link, he copied the command across, and hit enter. The site turned out to be a copycat bundling malware, and it executed the moment it landed. “It ran instantly, tried to take everything from me,” he wrote on X.

Nothing sensitive got out, he says. He wiped the laptop and rebuilt it clean, which should have been the end of the story. Then, while restoring from his backup, he found the part that actually worried him. Sitting in his Claude Code setup was a poisoned SKILL.md file, written to look exactly like his own style guide.

A poisoned SKILL.md file is malware that reads like documentation

The file passed as notes. Buried inside it were instructions telling the AI to silently re-download the malware and lift his credentials every single time it loaded that file. Restoring one innocuous-looking text file would have handed over the freshly rebuilt machine on day one. What saved him was a habit rather than a tool. He reads every skill, hook and config file before letting the AI near them.

Asked in the replies how people should vet links that surface inside AI conversations, he kept it plain. Find the official source yourself. Do the googling. Check the domain properly. He is upfront that he did none of that before pasting.

AI agent files now execute like code, and the industry is barely treating them that way

The timing is awkward for the wider AI security conversation. Anthropic disclosed on July 30 that three of its models reached the open internet during cybersecurity evaluations and broke into the production systems of three real organisations, all while believing they were still inside a simulation. One of them, Mythos 5, went as far as building a malicious Python package and publishing it to PyPI, where it was downloaded and run on 15 real machines inside roughly an hour. Separately, an Australian developer’s OpenClaw agent found an authorisation flaw in his gym’s booking software and cancelled a stranger’s reservation to push him up the waitlist.

The thread running through all of it is the same. None of these systems went rogue. They were helpful, fast and wrong, and the human on the other side had no obvious reason to look twice at what came back. Numa’s own conclusion fits on a sticky note. Assistants will hand you links they never verified.

  • Published On Aug 31, 2026 at 09:21 AM IST

Join the community of 2M+ industry professionals.

Subscribe to Newsletter to get latest insights & analysis in your inbox.

All about ETCISO industry right on your smartphone!




Information Security - InfoSec - Cyber Security - Firewall Support Providers Company in India

 

What is Firewall? A Firewall is a network security device that monitors and filters incoming and outgoing network traffic based on an organization's previously established security policies. At its most basic, a firewall is essentially the barrier that sits between a private internal network and the public Internet.

 

Secure your network at the gateway against threats such as intrusions, Viruses, Spyware, Worms, Trojans, Adware, Keyloggers, Malicious Mobile Code (MMC), and other dangerous applications for total protection in a convenient, affordable subscription-based service. Modern threats like web-based malware attacks, targeted attacks, application-layer attacks, and more have had a significantly negative effect on the threat landscape. In fact, more than 80% of all new malware and intrusion attempts are exploiting weaknesses in applications, as opposed to weaknesses in networking components and services. Stateful firewalls with simple packet filtering capabilities were efficient blocking unwanted applications as most applications met the port-protocol expectations. Administrators could promptly prevent an unsafe application from being accessed by users by blocking the associated ports and protocols.

 

Firewall Firm is an IT Monteur Firewall Company provides Managed Firewall Support, Firewall providers , Firewall Security Service Provider, Network Security Services, Firewall Solutions India , New Delhi - India's capital territory , Mumbai - Bombay , Kolkata - Calcutta , Chennai - Madras , Bangaluru - Bangalore , Bhubaneswar, Ahmedabad, Hyderabad, Pune, Surat, Jaipur, Firewall Service Providers in India, Welcome to IT Monteur's Firewall Firm, India's No1 Managed Enterprise Network Security Firewall Support Provider Company in India, Firewall Firm Provider Complete range of Juniper Firewall Support , Cisco Firewall Support , Check Point Firewall Support , Palo Alto Firewall Support , FortiGate Firewall Support , Forcepoint Firewall Support , Sophos Firewall Support , WatchGuard Firewall Support , Baracuda Firewall Support , SonicWall Firewall Support , Gajshield Firewall Support , Seqrite Firewall Support , Firewall , Hardware Firewall , Software Firewall , Firewall India , Firewall , Network Firewall , Firewall Support , Firewall Monitoring , Firewall VPN , WAF Website Firewall , Firewall Security , Firewall India , Firewalls Support Provider in India , Firewall Support Services Provider Company in India

Sales Number : +91 95 8290 7788 | Support Number : +91 94 8585 7788
Sales Email : sales@itmonteur.net | Support Email : support@itmonteur.net

Register & Request Quote | Submit Support Ticket