This Sneaky ClickFix Attack Just Added a New Way to Drain Crypto Wallets

ยท
Listen to this article~5 min
This Sneaky ClickFix Attack Just Added a New Way to Drain Crypto Wallets

ClickFix attacks now target macOS with Go-based malware that steals crypto wallets, browser passwords, and iCloud Keychain data. Learn how the infection works and how to protect yourself.

You've probably seen those fake CAPTCHA pages that tell you to copy and paste a command into your terminal. They look harmless enough, right? Wrong. Security researchers have spotted a new wave of these so-called ClickFix attacks that are now targeting macOS users, and the payload is a nasty piece of work. The malware is built with Go, which makes it fast and hard to analyze. Once it's on your Mac, it goes straight for your cryptocurrency wallets, but that's not all. It also digs through your browser-stored passwords, pulls data from Apple iCloud Keychain, and grabs any cached credentials it can find. In other words, if you store it on your Mac, this thing wants it. ### How the Attack Unfolds The infection chain is pretty clever, and it starts with a simple shell script. That script's first job is to profile your system. It checks what kind of CPU your Mac hasโ€”whether it's an older Intel model or one of the newer Apple Silicon chips. Why does that matter? Because the attackers don't want to send you a payload that won't run. They tailor the malware to your specific hardware. Once the script figures out your architecture, it reaches out to a remote server and pulls down the actual malware payload that's compatible with your machine. This isn't a one-size-fits-all attack. It's a targeted delivery system that maximizes the chances of the malware running successfully on your computer. ### Why ClickFix Works So Well The genius (and the terror) of ClickFix is in its social engineering. The whole thing feels routine. You're on a website, a popup appears saying you need to verify you're human. It tells you to open Spotlight, paste a command, and press Enter. It looks like a standard security check, so you do it without thinking. That command, however, is the first step in the infection. It downloads the shell script, which then does its dirty work. The attackers are betting on the fact that most people won't question a familiar-looking prompt. And honestly, they're right to bet on that. We've all been conditioned to click through verification steps without reading the fine print. ### What's at Stake Let's break down what this malware can actually steal, because the list is longer than you might think: - **Cryptocurrency wallets:** Any wallet extension or app on your Mac could be drained. - **Browser passwords:** Chrome, Safari, Firefoxโ€”if it's saved, it's vulnerable. - **iCloud Keychain data:** That includes Wi-Fi passwords, website logins, and credit card info. - **Cached credentials:** Any stored tokens or session cookies that could let attackers impersonate you. For anyone who manages crypto assets or handles sensitive client data, this is a nightmare scenario. A single successful infection could wipe out years of savings or expose confidential business accounts. ### How to Protect Yourself The first line of defense is skepticism. If a website asks you to run a command in your terminal, stop. Legitimate sites never ask you to do that. Close the tab and move on. It's that simple. Beyond that, you should also consider using a dedicated browser for sensitive activities. Many security professionals swear by antidetect browsers for managing multiple accounts or handling crypto transactions. These tools isolate your sessions and make it harder for malware to grab your credentials in the first place. If you're serious about protecting your digital assets, looking into the best antidetect browser options is a smart move. You should also enable two-factor authentication on every crypto exchange and wallet you use. Even if the malware steals your password, it won't be able to complete a transaction without the second factor. Finally, keep your Mac updated. Apple regularly patches vulnerabilities, and staying current closes the doors that attackers love to slip through. ### The Bottom Line ClickFix attacks aren't new, but they're getting more sophisticated. This Go-based stealer is a clear sign that threat actors are investing time and resources into macOS-specific malware. The days of thinking "Macs don't get viruses" are long gone. Your best defense is a combination of caution and the right tools. Don't run random commands, use a browser that prioritizes privacy, and never underestimate what a single bad click can cost you.