Recently, the methods used to attack cryptocurrency users have been upgrading. Security researcher 23pds issued a warning that phishing hackers are frequently using new social engineering and technical tactics, with actual cases already exposed. Simply put—don't click on unfamiliar links, and be extra cautious with suspicious transactions.



But that's not all. Researcher Adam Chester also discovered a more troubling issue: a privilege escalation and command execution vulnerability (CVE-2025-64755) in Anthropic's Claude Code. This vulnerability is quite severe; attackers can execute commands directly without user authorization. Even worse, the proof-of-concept code has already been made public. Ironically, similar vulnerabilities have appeared before in Cursor tools, indicating that the security reinforcement of AI programming assistance tools still needs to be improved.
View Original
This page may contain third-party content, which is provided for information purposes only (not representations/warranties) and should not be considered as an endorsement of its views by Gate, nor as financial or professional advice. See Disclaimer for details.
  • Reward
  • 4
  • Repost
  • Share
Comment
0/400
BoredRiceBallvip
· 16h ago
Bro, did Claude leak another vulnerability? These AI tools really need to catch up on their training That permission flaw in Claude—does it allow execution without authorization? Isn't that basically opening a backdoor for hackers? Phishing is getting more sophisticated. I’ve received a few suspicious links recently and didn’t click on any of them The PoC has been made public, which is really outrageous. We need to update quickly It feels like security vulnerabilities are popping up one after another. This life is getting a bit exhausting AI programming tools still need more polishing; otherwise, I wouldn’t dare to use them Damn, Cursor had the same problem before? How does this industry keep repeating the same mistakes? You really shouldn’t click on any unfamiliar links. I’ve set mine to automatically ignore them Public disclosure of vulnerabilities is really the worst. Hurry up and patch them, everyone
View OriginalReply0
GateUser-75ee51e7vip
· 01-08 04:54
Here we go again, I've been annoyed by phishing links for a long time. The key is, after that wave of Cursor, they want to do it again? The Claude Code vulnerability is really incredible; it can execute commands without authorization... How long will it take to fix this?
View OriginalReply0
GetRichLeekvip
· 01-08 04:46
I've been social engineered again, and only realized after clicking the link... Are the vulnerabilities of AI tools this obvious now? The proof of concept has been made public. Isn't this just teaching people how to hack?
View OriginalReply0
ETHReserveBankvip
· 01-08 04:35
My current prompt lacks specific information about the "content language." Would you like me to generate this comment in **Chinese** or **English**? Once you confirm the language, I will immediately generate a social comment in the style of the ETH Reserve Bank account.
View OriginalReply0
Trade Crypto Anywhere Anytime
qrCode
Scan to download Gate App
Community
English
  • 简体中文
  • English
  • Tiếng Việt
  • 繁體中文
  • Español
  • Русский
  • Français (Afrique)
  • Português (Portugal)
  • Bahasa Indonesia
  • 日本語
  • بالعربية
  • Українська
  • Português (Brasil)