Buy now

You've clicked a thousand of these. A page loads, a box appears saying it needs to check you're human, you tick it and carry on with your day. The fake CAPTCHA scam exists because that reflex is so worn in that nobody reads the box, and in 2026 it has become one of the most effective ways to empty a crypto wallet without ever asking for a password.

Security researchers call the technique ClickFix, and the thing that makes it work is the twist at the end of the box.

How the trick is built

A normal CAPTCHA asks you to click something. This one asks you to do a little more: it tells you the verification needs a manual step, and walks you through pressing a keyboard shortcut and hitting enter. What the page doesn't mention is that JavaScript running behind the box has already dropped a command into your clipboard, so the keystrokes you've been guided through are pasting and running that command on your own machine.

From there it stops being a browser problem. The command pulls down a second-stage payload, and whatever that payload is, it now has the access your user account has. ESET found that detections of this technique climbed 517% between the second half of 2024 and the first half of 2025, putting it second only to conventional phishing among attack vectors, and the lures now cover Windows, macOS and Linux. Microsoft tracks several distinct groups running the infrastructure, and Malwarebytes reported in May 2026 that more than 700 education and technology sites had been hijacked to serve the same box.

The version that hunts crypto traders

In mid-September 2026 the pattern showed up somewhere specific enough to be worth naming. Attackers began seeding malicious links into meme coin metadata, the website and social fields that traders click through when they're researching a token that launched twenty minutes ago. The link served a page imitating a Cloudflare security check, the check asked for the manual verification step, and the script that followed went looking for everything on the machine. One trader was reported to have lost around 600,000 dollars.

Consider the context that makes this land. A meme coin trader is moving fast by definition, opening unfamiliar links dozens of times an hour, and has already trained themselves to dismiss anything that looks like routine infrastructure. A Cloudflare interstitial is the most routine thing on the internet.

Why this defeats defences that work on other attacks

Most crypto phishing advice is built around signatures. Don't approve transactions you don't understand, revoke old allowances, use a simulator to see what a contract will do before you sign it. All of that remains worth doing, and we've covered how drainers use approvals at length.

ClickFix sidesteps the whole category. Once code runs locally with your privileges, the attacker isn't limited to what they can trick you into signing. They can read browser extension storage, copy key files, watch your clipboard for addresses, log what you type, and sit quietly until something worth taking appears. An infostealer on your laptop doesn't need you to make a mistake twice.

That's also why "I'd never fall for it" is a weaker defence than people assume. The lure isn't a badly spelled email you can spot; it's a plain grey box on a page you had a reason to open.

How to not be the person who runs the command

The rule that covers almost every version of this is short: no legitimate website has ever needed you to open a terminal, a Run dialog, or a PowerShell window to prove you're a human. Neither Cloudflare nor Google has ever asked anyone to do it, and no site you use daily will start. If a verification step involves your keyboard doing anything beyond typing letters you can see on screen, close the tab.

A few habits reduce the blast radius around that rule. Treat links inside token metadata, Discord messages and direct messages as unverified by default, since none of those fields are checked by anyone before you click. Keep the machine you use for wallets separate from the one you use for browsing new projects, if your setup allows it. Watch for the tell that this technique can't avoid: a delay, a shortcut, an instruction to paste something you can't read.

If you think you already ran one, treat the whole machine as compromised rather than trying to clean it. Move funds from any wallet that device touched, using a different device.

What it means for your seed phrase and your recovery

Here's the part that decides whether an infected laptop costs you money. If your keys live in software on that machine, in a browser extension or a desktop wallet or a file you once saved, then the malware and your wallet have the same access, and the outcome is arithmetic. A hot wallet is defined by being reachable, and a script running as you can reach it.

Keys generated inside a certified secure element sit outside that. On the Ryder One the private key is created inside an EAL6+ Infineon SLC38 chip and never leaves it, so there is nothing on your computer for an infostealer to copy. The follow-up move, where malware swaps a destination address at the moment you send, runs into the second defence: every transaction is drawn in full on the 1.6-inch AMOLED display and signed only after a button press wired directly to the chip, so the address you read on the device is the address that gets signed.

Your backup deserves the same reasoning. Typing a seed phrase into anything on a compromised machine hands over everything the hardware was protecting, which is why a recovery method that never asks you to type it is worth more than one that does. TapSafe Recovery splits recovery across a Recovery Tag holding half and your paired phone holding the other half, encrypted into your own iCloud or Google Drive rather than stored on the handset, with optional Recovery Contacts holding a quarter each and seeing nothing about your balances. Built on a custom implementation of Shamir's Secret Sharing, it restores by tapping objects together, and the BIP-39 phrase stays on the device as a last resort so you're never locked to our hardware.

The short version

A verification box that asks you to run a command is an attack, every time, with no exceptions worth entertaining. Close the tab. And if the reason this scares you is that your crypto sits in software on the same computer you browse with, the fix is structural rather than behavioural: move the keys somewhere a script can't reach. Setup on the Ryder One is three taps and under a minute, the Starter Combo is 149 USD with the Recovery Tag, wireless charger and pouch included, and the firmware has been independently audited by Halborn. Get your Ryder One.


Meta description: The fake CAPTCHA scam, or ClickFix, tricks you into running malware yourself. How it drained a trader of 600K, why signature defences miss it, what stops it.

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More