Market desk Bitcoin Ethereum Altcoins DeFi Stablecoins Markets & Trading

Fake AI Trading Bot Replaces Crypto Wallet Extensions to Steal Credentials

HP Wolf Security discovered a campaign where a counterfeit AI trading assistant delivered malware that replaced seven popular browser crypto wallet extensions with fraudulent versions designed to capture login credentials.
1 hour ago 7 views
Fake AI Trading Bot Replaces Crypto Wallet Extensions to Steal Credentials

HP Wolf Security reported that a fake AI crypto-trading assistant distributed malware capable of replacing browser wallet extensions on infected Windows computers, turning legitimate wallet interfaces into credential-stealing traps.

The campaign, documented in HP's September threat report published September 17, targeted seven wallet extensions: Phantom, Trust Wallet, Atomic Wallet, Coinbase Wallet, OKX Wallet, MetaMask, and Tonkeeper. The attack began after users downloaded and executed a counterfeit trading tool, not through breaches of wallet providers or their official extensions.

How the Attack Worked

Attackers promoted tradingclaw[.]pro as an AI assistant capable of automated trading following personalized strategies. Search-engine optimization tactics and paid advertisements directed users to download a ZIP file presented as the software installer.

The archive contained two files: Trading Agent.exe, identified as OLEView, a legitimate Microsoft tool that is digitally signed, and iviewers.dll, containing the malicious payload. The signed Microsoft executable bypassed Microsoft's SmartScreen reputation check while loading the malicious DLL, which then decrypted Needle Stealer malware using a technique called process hollowing to execute code within legitimate processes.

Once installed, Needle Stealer identified target wallet extensions by their 32-character IDs, shut down the browser, and extracted malicious replacement extensions into the existing extension folder. When restarted, the fraudulent extensions connected to attacker-controlled servers and displayed realistic login screens. Credentials entered into these counterfeit interfaces were transmitted to the attackers.

Scope Unknown

HP's report did not disclose the total number of victims or aggregate financial losses from the campaign, leaving the operation's true scale undetermined. Malwarebytes had previously documented the TradingClaw campaign in April, noting that Needle Stealer circulated through multiple malware loaders as part of a broader malware operation.

Market snapshot

Top cryptocurrency prices

Explore all prices
BitcoinBTC $77,505.59+1.50% EthereumETH $2,484.06+1.94% Tether USDUSDT $1.00+0.01% BNBBNB $753.26+3.96% XRPXRP $1.32+2.01% USDCUSDC $1.00-0.02% SolanaSOL $105.53+6.07% TRONTRX $0.3361+0.12% HyperliquidHYPE $87.69+10.96% ZcashZEC $1,500.19+10.94%
Prices by Coinranking. Informational only.