Cybercriminals have disguised malware as an AI-powered crypto trading agent to steal passwords from browser wallets.
In this campaign, seven wallet extensions, including MetaMask, Coinbase Wallet, and Phantom, were targeted. HP revealed this operation in its security report, dated September 17.
Fake crypto trader delivers wallet-stealing malware #
The criminals created a website promoting software that supposedly used artificial intelligence to trade crypto around the clock.
However, users who downloaded the advertised trading agent received malware known as Needle Stealer.
This was noticed by HP between April and June 2026. The attackers were targeting people who were searching online for AI tools that could help automate their crypto trades.
After being installed, the crypto wallet extensions that were supported on the browser were looked for. The browser then closed, with the genuine extension on the browser being removed and replaced by a malicious copy.
The replacement looked like the wallet the user normally uses, but this was not the case. When the victims entered a password, the fake extension sent it to a server controlled by the attackers.
The stolen password and the wallet’s identifying information could allow the criminals have access to the victim’s crypto.
Familiar appearance offered little protection #
The attackers took steps that made the download look legitimate.
The installation package included actual Microsoft-signed software. Because Windows read it as original, the download was able to pass initial security checks.
The trusted program then opened a malicious file placed with it, allowing the wallet-stealing software to begin running in the background.
HP has told users not to enter their wallet passwords or make payments through AI applications that they cannot verify.
Final Summary #
- A fake AI trading agent replaced those actual wallets on the user’s machines with copies that stole passwords.
- It was seen in a campaign lasting from April till June by HP.