As reported by Matthew Griffin in the publication Fanatical Futurist: "The attack sequence typically begins with an attacker gaining access to a user's Claude conversation history or manipulating a user into initiating a conversation that includes specific prompts. Once the attacker controls the conversational context, they can issue commands that appear legitimate to the AI but result in cryptocurrency transfers to attacker-controlled addresses."