Fake Cloudflare check drains $600,000 from top Axiom trader, no wallet signature required
Traders who never sign a suspicious transaction are losing funds anyway, because this fake Cloudflare scam asks for something else entirely: permission to run code on their own machine.
A meme coin trader who posts as @cladzsol says a fake Cloudflare verification page tricked him into running a malicious script that drained roughly $600,000 from his PC, not his wallet. Unlike typical crypto drainers, the attack never asked for a signature, sidestepping the hardware wallets and transaction simulators traders rely on for protection.
Screenshot: Inside Calls Post on X — Fake cloudflare scam
Why the fake Cloudflare scam slips past wallet security
The standard crypto drainer needs exactly one thing from its target: a signature. Connect a wallet, approve the transaction, and funds move within the bounds of whatever that approval covered. Traders who treat every signing prompt as hostile have a real defence against it.
Nothing in this attack asks for a wallet. The victim is asked to run code, and administrator rights hand over a scope no signing prompt could ever authorise. Wallet files become one target among everything else sitting on the machine.
That is why the fake Cloudflare scam lands hardest on traders whose defences are built around the signing step. Hardware devices, transaction simulators and disciplined approval hygiene all guard a door the attacker never approaches.
Screenshot: Danny’s Post on X — Fake cloudflare scam
The attack has a name and a long paper trail
Security firms have tracked this playbook for well over a year under the label ClickFix. The choreography rarely varies: a verification widget that refuses to work properly, followed by helpful “alternative” steps telling the visitor to press Win+R, paste, and hit Enter. The clipboard already holds an obfuscated command, put there by the page itself.
CyberProof analysts traced one variant in January after alerts fired on clipboard access followed by PowerShell running from memory. That version profiled the machine, checked whether it was virtualised or protected by endpoint tooling, then went after browser credentials, cryptocurrency wallet data and VPN configuration files, keeping itself alive through a registry key that redeployed it at startup.
Crypto professionals were in scope before meme coin traders were. A January campaign used fake Cloudflare overlays on spoofed conference pages to reach Web3 workers, and Mandiant published findings in February attributing related intrusion activity to UNC1069, an actor it tracks with a suspected North Korean nexus.
The links sit exactly where traders go looking
Delivery is what brings the fake Cloudflare scam to meme coin desks. Nobody is blasting these links out through advertising or direct messages. They live in the website and social fields bolted onto freshly launched tokens, which is precisely where a trader looks when working out whether a project is real.
Those fields belong to whoever controls the token listing, and that control can change hands. An attacker holding them can point the website entry at anything, including a page dressed up as a security check.
The result inverts the usual advice. Research, normally the habit that keeps a trader out of trouble, becomes the step that delivers the payload. A trader doing everything right, clicking through to verify a project before buying, arrives at the malicious page by following good practice rather than abandoning it.
The warnings circulating since September 16 reduce the fake Cloudflare scam to a single instruction: a verification page that wants a command typed or pasted anywhere should be closed, not completed. Cloudflare’s genuine checks never involve a terminal.