Hackers impersonate VC and hijack the QuickLens plugin, using ClickFix technology to steal cryptocurrency assets
According to Cointelegraph, hackers are using the "ClickFix" attack method to steal cryptocurrencies, with the latest two attacks involving impersonating venture capital firms and hijacking browser extensions.
Cybersecurity company Moonlock Lab reports that scammers impersonate fake VCs such as SolidBit, MegaBit, and Lumax Capital, contacting users via LinkedIn to offer collaboration opportunities, then directing them to click on fake Zoom and Google Meet links. After clicking the link, users are led to a page with a forged Cloudflare "I'm not a robot" verification box; clicking this box copies malicious commands to the clipboard and prompts users to open a terminal to paste the so-called verification code, thus executing the attack.
Moonlock Lab points out that this method turns victims into execution mechanisms, bypassing defenses in the security industry. Meanwhile, hackers are also spreading malware by hijacking the Chrome extension QuickLens. This extension allows users to run Google Lens searches directly in the browser, and after ownership was transferred, the new version contains malicious scripts that can initiate ClickFix attacks and steal information.
The extension has about 7,000 users, and once hijacked, it searches for cryptocurrency wallet data and recovery phrases to steal funds, as well as scraping Gmail inbox content, YouTube channel data, and login credentials or payment information entered in web forms. The extension has been removed from the Chrome Web Store. The ClickFix technique has been popular among hackers since last year, forcing victims to manually execute malicious payloads, affecting thousands of businesses and multiple industries worldwide.
You may also like

Forbes Special Report: The Embrace of AI Agents in the Cryptocurrency Industry

Bitpanda, Vision Web3 Foundation, and Optimism Partner to Onboard European Financial Institutions to the Global Blockchain Economy

What will the early Hyperliquid prediction market look like?

Overseas VC's Two-Week Trip to China AI Leaves Them in Awe of Shenzhen Hardware

Was CZ Also Rug Pulled? BNB Treasury CEA Industries Control Battle

A transaction in 7 seconds, earning tens of millions of dollars, he's seen as the "cancer of meme coins."

Bittensor Ecosystem Token SN Surges 5x in March, What's Behind Richard Heart's One-Liner?

The economy is entering a new cycle, how can the average person prepare?

Access Binance Alpha Box: Sigma.Money to Launch BNB Chain Ecosystem Yield Farming Gateway

Kimi, Chip, and Bean come together for a Crypto Hackathon: What did AI developers build on Monad?

How to Trade Crypto on Mobile Browser & Win LALIGA Tickets (2026 Guide)
Discover how AI automation, natural language trading, and mobile browser trading platforms are shaping automated trading in 2026. Join the WEEX live trading event for early access and rewards like LALIGA VIP tickets.

Connecting encryption, TradFi, and payments, is Gate completing the final puzzle of the "super APP"?

a16z Crypto Operating Partner: Wall Street is undergoing its biggest infrastructure upgrade in 30 years

a16z Crypto's latest research: What is the key to the large-scale application of DeFi?

Founder of Delphi Labs: My observations and feelings about the AI ecosystem in China in two weeks

AI Seating Chart Released | Rewire News Morning Brief

Is the era of Embodied AI's "GPT Moment" Approaching? Axis Robotics Announces End of Testing, Set to Launch on Base Chain

