Close Menu
AsiaTokenFundAsiaTokenFund
  • Home
  • Crypto News
    • Bitcoin
    • Altcoin
  • Web3
    • Blockchain
  • Trading
  • Regulations
    • Scams
  • Submit Article
  • Contact Us
  • Terms of Use
    • Privacy Policy
    • DMCA
What's Hot

Aptos jumps 18% as Layer 1 rotation accelerates – Is $0.825 next for APT?

September 19, 2026

Bitcoin Price Predictions Draw a Brutal Line Between $84K and $100K

September 19, 2026

Exchanges lower token risk values, leaving leveraged traders with less breathing room

September 18, 2026
Facebook X (Twitter) Instagram
Facebook X (Twitter) YouTube LinkedIn
AsiaTokenFundAsiaTokenFund
ATF Capital
  • Home
  • Crypto News
    • Bitcoin
    • Altcoin
  • Web3
    • Blockchain
  • Trading
  • Regulations
    • Scams
  • Submit Article
  • Contact Us
  • Terms of Use
    • Privacy Policy
    • DMCA
AsiaTokenFundAsiaTokenFund

Fake AI crypto software is secretly replacing browser wallet extensions

0
By Aggregated - see source on September 18, 2026 Trading
Share
Facebook Twitter LinkedIn Pinterest Email

HP Wolf Security, the company’s threat-research team, said a fake AI crypto-trading assistant distributed malware that could replace browser crypto wallet extensions on an infected Windows computer and turn the familiar wallet interface into a credential trap.

The campaign appeared in HP’s September threat report, published Sept. 17 and based on threats observed from April through June 2026. HP described a compromise that began on a user’s endpoint after a counterfeit trading tool was downloaded and run, not a breach of Coinbase, MetaMask, or their official extensions.

Malwarebytes had documented the TradingClaw campaign in April and found that Needle Stealer also circulated through other malware loaders. The fake AI assistant was one route into a broader malware operation.

Related Reading

Hackers sneak crypto wallet-stealing code into a popular AI tool that runs every time

Attackers promoted tradingclaw[.]pro as an AI assistant that could follow a personalized strategy and trade around the clock, according to the full HP report. Search-engine poisoning and paid advertisements directed prospective victims to a ZIP file presented as the software’s installer.

The archive contained an executable named Trading Agent.exe and a DLL named iviewers.dll. HP identified the executable as OLEView, Microsoft’s legitimate, digitally signed OLE/COM Object Viewer. HP said the signed program helped bypass Microsoft’s SmartScreen reputation check, while the malicious payload remained in the accompanying DLL.

Running the trusted-looking program caused it to load that DLL. The code then decrypted Needle Stealer and used process hollowing, a technique that runs malicious code inside a newly launched legitimate process.

The Catalyst

What’s moving crypto. Why it matters.

Get CryptoSlate’s essential stories and what to watch next.

Published on Substack

Seven days a week. Unsubscribe anytime.

Whoops, looks like there was a problem. Please try again.

Check your inbox.

Your signup request was sent. If confirmation is required, follow the email from Substack.

Look in spam or promotions if you don’t see it.

Six-step diagram showing how a fake AI trading tool delivered Needle Stealer and replaced browser crypto wallet extensions with credential-stealing copies.
A fake AI trading tool delivered Needle Stealer through a malicious ZIP, targeting seven wallet extensions and stealing credentials from compromised devices.

How the crypto wallet swap worked

Needle Stealer enumerated Chromium browser extensions and checked their 32-character IDs against a hardcoded list covering Phantom, Trust Wallet, Atomic Wallet, Coinbase Wallet, OKX Wallet, MetaMask, and Tonkeeper.

When it found a target, the malware shut down the browser and extracted a corresponding malicious extension into the existing extension folder.

On its first launch, the replacement connected to a command-and-control server used by the attacker and loaded backup domains. HP said the attackers had built realistic login screens, and a crypto wallet ID and password entered into a counterfeit interface could be sent to the operator.

MetaMask’s guidance says that, for crypto wallets created with a Secret Recovery Phrase, the password unlocks MetaMask locally and cannot restore the wallet elsewhere. Even so, the substituted extension was operating on an already compromised device, leaving locally accessible funds at risk.

Neither HP’s report nor its newsroom summary disclosed a campaign-wide victim count or aggregate crypto-loss figure, leaving the operation’s scale unknown.

Credit: Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email

Related Posts

Exchanges lower token risk values, leaving leveraged traders with less breathing room

September 18, 2026

CFTC Submits Secret Two-Part Crypto Rules Package to White House

September 18, 2026

XRP Price Flashes Bullish Pattern, Eyes 35% Rally Toward $2

September 18, 2026
Leave A Reply Cancel Reply

What's New Here!

Aptos jumps 18% as Layer 1 rotation accelerates – Is $0.825 next for APT?

September 19, 2026

Bitcoin Price Predictions Draw a Brutal Line Between $84K and $100K

September 19, 2026

Exchanges lower token risk values, leaving leveraged traders with less breathing room

September 18, 2026

CFTC Submits Secret Two-Part Crypto Rules Package to White House

September 18, 2026
AsiaTokenFund
Facebook X (Twitter) LinkedIn YouTube
  • Home
  • Crypto News
    • Bitcoin
    • Altcoin
  • Web3
    • Blockchain
  • Trading
  • Regulations
    • Scams
  • Submit Article
  • Contact Us
  • Terms of Use
    • Privacy Policy
    • DMCA
© 2026 asiatokenfund.com - All Rights Reserved!

Type above and press Enter to search. Press Esc to cancel.

Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.