AI Scammers Steal Your Data with Fake ChatGPT 'Help' Guides
Fake AI support guides are tricking users into pasting terminal commands that steal passwords, cookies, and crypto wallets.
Scammers are hijacking your trust in AI tools to drain your passwords, browser cookies, and crypto wallet in seconds.
What Is the Fake AI Support Scam?
A wave of fake "help guides" is spreading across the internet right now. They look exactly like official support pages. Some are hosted on real, legitimate domains. They claim to fix a problem with ChatGPT, Claude, or another popular AI tool.
The guide walks you through a few steps. It looks clean. It looks professional. Then it asks you to open your Terminal and paste a command.
That command is not what it appears to be. The moment you run it, a hidden programme called an info-stealer silently deploys on your machine. You will not see a warning. You will not hear an alert. It just runs.
This technique is called "trust laundering." Attackers borrow the credibility of a real platform or a legitimate-looking domain to make their instructions feel safe.
Why Does This Work So Well?
Most people trust instructions that come from a polished website. When something looks like an Apple Support page or an official ChatGPT guide, your guard drops. That is exactly what attackers are counting on.
AI tools are new to millions of people. When something breaks or behaves unexpectedly, users go searching for help. They land on a convincing page. They follow the steps. They hand over full access to their machine without realising it.
The fake guides also exploit a gap in awareness. Most people know not to click suspicious links or open dodgy email attachments. But pasting a command into Terminal? That feels different. It feels technical. It feels legitimate.
It is not. It is one of the most dangerous things you can do on your computer.
How Does the Info-Stealer Actually Work?
Once you paste and run the malicious command, it contacts a remote server. That server downloads the info-stealer onto your machine in the background.
The stealer then silently scans your system. It looks for saved passwords in your browser. It harvests session cookies, which can let attackers log into your accounts without needing your password. It searches for cryptocurrency wallet files and seed phrases.
Everything it finds gets packaged up and sent back to the attacker. The whole process can take under a minute. By the time you close the page, the damage is done.
The info-stealer does not need admin access in most cases. It runs quietly under your user account. Standard antivirus tools may miss it entirely.
How Big Is This Threat?
This attack targets millions of AI users worldwide. ChatGPT alone has over 400 million weekly active users. Claude, Gemini, and other tools add hundreds of millions more. That is a massive pool of potential victims, many of them new to these tools and unfamiliar with the risks.
Fake support pages and deceptive guides have been circulating since at least early 2026, with researchers flagging a sharp rise in Terminal-based social engineering attacks. The use of legitimate domains makes them harder to flag in search results and browser security filters.
What Should You Do Right Now?
- Never paste a command into Terminal from an online guide unless you found it in an official developer's documentation or a source you deeply trust. Even then, read the command carefully before running it.
- Check the actual domain of any support page. Look for subtle misspellings or unusual subdomains. A polished design does not mean the site is safe.
- Go direct if you have a problem with ChatGPT or Claude. Visit openai.com or anthropic.com directly. Do not search for "ChatGPT help" and trust the first result.
- Review your saved passwords using your browser's built-in password manager and change any that may have been exposed. Use unique passwords for every account.
- Check for suspicious logins in your email, banking, and crypto accounts. Look for sessions from unknown locations or devices.
- Consider a hardware wallet if you hold cryptocurrency. Info-stealers cannot access funds stored offline.
The Bigger Picture
This scam is not a bug in AI. It is a bug in human trust. Attackers will always find the newest, most credible-looking surface to exploit. As AI tools become part of everyday life, they become the perfect disguise for attacks like this.
The best defence is a simple habit: never run a command you did not write yourself or find in official documentation. That one rule stops this attack completely.
Stay invisible. Follow HackDecoded.
Sources
Common Questions About Scam
How do I know if a call is really from a government agency?
Legitimate government agencies never call demanding immediate payment, threatening arrest, or asking for gift cards, wire transfers, or cryptocurrency. Hang up and call the agency directly using their official number from usa.gov.
What is a pig butchering scam?
Pig butchering is a long-con investment fraud where scammers build fake friendships or romances over weeks before introducing a fake crypto investment platform. Losses average $120,000 per victim. Any unsolicited investment tip is a red flag.
What should I do if I have already been scammed?
Report to the FTC at ReportFraud.ftc.gov, the FBI at IC3.gov, and your state attorney general. If a bank transfer was involved, call your bank immediately — you may have a window to reverse it. Document everything: screenshots, phone numbers, transaction records.
More in scam
Stay invisible. Follow @hack_decoded
