A crypto trader using the pseudonym cladzsol said he lost around $600,000 after malware compromised his computer, though he added that he was able to save roughly $400,000. He said the infection stemmed from a fake Cloudflare verification page and took responsibility for the incident.
The reported attack did not depend on a wallet connection or a signed blockchain transaction. Instead, it appears to have relied on social engineering that persuaded the victim to run a malicious command directly on a Windows device.
How the compromise reportedly happened
According to the details shared about the incident, the site imitated a legitimate Cloudflare-style verification prompt. Rather than performing a normal browser check, it instructed the user to press Win + R, paste a command that had already been copied to the clipboard, and then press Enter.
That sequence launches the Windows Run dialog and executes whatever text has been inserted. In this case, the command was malicious, allowing malware to infect the trader’s computer after he ran it himself.
A ClickFix-style attack
The method matches a social-engineering technique widely referred to as ClickFix. In these attacks, the victim is guided step by step into executing harmful code, often under the impression that they are completing a security check or solving a website access issue.
Because the code is run locally by the target, the attacker may not need the usual prompts associated with crypto theft, such as asking the user to connect a wallet or approve an onchain transaction. That can make the attack harder to recognize for people expecting theft attempts to begin inside a wallet interface.
Confusion around Arc was later rejected
Early reports suggested the incident may have happened while cladzsol was using a bridge in the Arc ecosystem. The trader later said the compromise was not related to Arc, narrowing the scope of what can be confirmed about where the malicious page was encountered.
The source material also notes that there is no independent confirmation that he reached the harmful link through a memecoin profile, token page, or an aggregator. While similar lures have circulated through those channels, that connection has not been established in this case.
Part of a broader phishing pattern
The reported setup is consistent with broader phishing campaigns that mimic Cloudflare Turnstile checks and silently place a command into a user’s clipboard. Victims are then told to open Windows Run or PowerShell and execute it, turning a fake verification flow into a malware delivery mechanism.
The incident fits into a wider stream of attacks aimed at crypto users. Earlier reporting also described phishing waves targeting Trezor users, with those campaigns linked to breaches involving third-party providers.
For now, the clearest confirmed points are the trader’s own account of the loss, his estimate that about $400,000 was saved, and his clarification that Arc was not involved.
Source: incrypted.com