A phishing campaign targeting meme coin traders is using fake Cloudflare verification screens to persuade victims into running malicious scripts directly on their computers — an approach that bypasses the wallet-connect and token-approval warnings most drainer defenses rely on. Market reports on September 16, corroborated by separate coverage from Cryptonomist, flagged the campaign after one trader publicly reported a loss of approximately $600,000.
How the lure works
The malicious links are being placed in website fields attached to newly launched tokens — metadata that trading aggregators and token trackers display as a project's official homepage. A trader scanning a new meme coin opens what looks like the project site, lands on a page designed to resemble a Cloudflare verification check, and is then instructed to execute a command or script to "pass" the check.
Crypto account Inside Calls, which publicized the incident on September 15, described the sequence: the fake verification process asks the user to run a payload with administrator privileges on Windows. The trader known as @cladzsol subsequently said the attack cost him around $600,000. The figure is self-reported and has not been independently verified on chain, but the mechanism described matches a known shift in crypto phishing toward direct malware delivery.
This differs structurally from conventional drainer attacks. Wallet drainers typically need the victim to connect a wallet and sign a malicious approval — a flow that security extensions, wallet warnings and blocklists are built to catch. Here the victim never touches their wallet. They hand the attacker code execution on their machine, at which point no on-chain permission model matters: credentials, browser sessions and wallet files are all reachable from the compromised host.
Why the delivery channel matters
Reports on the campaign noted that token metadata fields can be set by token creators — or by people who later seize control of a project's community presence — and that link review on aggregation services such as DexScreener can lag behind changes. No evidence in the reports indicated DexScreener itself was compromised; the exposure comes from aggregator pages faithfully displaying attacker-controlled URLs during the review gap.
That makes the campaign a supply-chain problem at the research layer: the tool traders use to evaluate tokens becomes the distribution mechanism for malware. The faster a trader moves from token page to website, the more effective the lure — and meme coin trading is built on speed.
A familiar brand, a new payload
The campaign extends a trend documented throughout 2026: copying trusted infrastructure to weaponize routine behavior. In August, a Hyperliquid trader lost about $550,000 in USDC after clicking a sponsored Google ad leading to a counterfeit version of the decentralized exchange; blockchain security firm Salus linked the site's infrastructure to the Inferno drainer ecosystem. The Cloudflare variant goes further — it impersonates not the trading venue but the internet's most ubiquitous checkpoint, the "verifying you are human" screen users see dozens of times a day.
The defensive guidance is simple and narrow: no legitimate verification process — Cloudflare or otherwise — will ever ask you to execute a script or command on your computer. Any page that does should be closed, and the token listing that led to it treated as hostile.
TrustGrade tracks the security posture of wallets, trading platforms and the infrastructure around them. Verified registry scores and security scans arrive with TrustGrade Code Scoring in December 2026.