cd /news/ai-tools/fake-ai-trading-agent-replaces-crypt… · home topics ai-tools article
[ARTICLE · art-133383] src=cryptonews.net ↗ pub= topic=ai-tools verified=true sentiment=↓ negative

Fake AI trading agent replaces crypto wallets to steal passwords

HP's September 17 security report detailed a campaign, observed between April and June 2026, in which malware disguised as an AI-powered crypto trading agent replaced seven browser wallet extensions — including MetaMask, Coinbase Wallet, and Phantom — with malicious copies that sent victims' passwords to attacker-controlled servers. The download, named Needle Stealer, bundled genuine Microsoft-signed software to pass initial Windows security checks before launching a malicious file that ran the wallet-stealing code in the background. HP advised users not to enter wallet passwords or make payments through unverified AI applications.

read2 min views4 publishedSep 18, 2026
Fake AI trading agent replaces crypto wallets to steal passwords
Image: Cryptonews (auto-discovered)

Cybercriminals have disguised malware as an AI-powered crypto trading agent to steal passwords from browser wallets.

In this campaign, seven wallet extensions, including MetaMask, Coinbase Wallet, and Phantom, were targeted. HP revealed this operation in its security report, dated September 17.

Fake crypto trader delivers wallet-stealing malware #

The criminals created a website promoting software that supposedly used artificial intelligence to trade crypto around the clock.

However, users who downloaded the advertised trading agent received malware known as Needle Stealer.

This was noticed by HP between April and June 2026. The attackers were targeting people who were searching online for AI tools that could help automate their crypto trades.

After being installed, the crypto wallet extensions that were supported on the browser were looked for. The browser then closed, with the genuine extension on the browser being removed and replaced by a malicious copy.

The replacement looked like the wallet the user normally uses, but this was not the case. When the victims entered a password, the fake extension sent it to a server controlled by the attackers.

The stolen password and the wallet’s identifying information could allow the criminals have access to the victim’s crypto.

Familiar appearance offered little protection #

The attackers took steps that made the download look legitimate.

The installation package included actual Microsoft-signed software. Because Windows read it as original, the download was able to pass initial security checks.

The trusted program then opened a malicious file placed with it, allowing the wallet-stealing software to begin running in the background.

HP has told users not to enter their wallet passwords or make payments through AI applications that they cannot verify.

Final Summary #

  • A fake AI trading agent replaced those actual wallets on the user’s machines with copies that stole passwords.
  • It was seen in a campaign lasting from April till June by HP.
── more in #ai-tools 4 stories · sorted by recency
── more on @hp 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/fake-ai-trading-agen…] indexed:0 read:2min 2026-09-18 ·