One of Axiom’s top traders just lost around $600,000 after falling for a phishing scam while trying to move funds to Arc. The attackers used a fake Cloudflare check to trick him into running a script as an admin on Windows.

How the attack went down

The malicious site showed a bogus Cloudflare “captcha” and prompted the user to run a script with admin rights on Windows. Once he did, the attacker got access to his crypto and started draining the wallet.

Where the funds went

The first chunk—about $115,000—was taken in SOL. After that, the rest was moved out in USDC and USDT stablecoins.

How the phishing link spread

The phishing link was hidden in the token metadata, which gets automatically picked up by aggregators like DexScreener. That made the link look trustworthy and helped lure victims onto the fake site.