Crypto Hackers Impersonate VC Firms in Sophisticated ClickFix Scam
-

Crypto scammers are escalating their tactics by posing as fake venture capital firms to lure victims into “ClickFix” attacks, according to cybersecurity firm Moonlock Lab. The attackers reportedly created bogus firms such as SolidBit, MegaBit, and Lumax Capital, contacting targets through LinkedIn with partnership proposals before directing them to fraudulent Zoom or Google Meet links.
Victims who click the links are taken to a fake verification page featuring a counterfeit Cloudflare “I’m not a robot” prompt. The action secretly copies a malicious command to the clipboard, instructing users to paste it into their computer’s terminal — effectively executing the attack themselves. Researchers say this tactic helps bypass traditional security protections by turning victims into the mechanism that deploys the malware.