{"slug": "fake-ai-trading-agent-replaces-crypto-wallets-to-steal-passwords", "title": "Fake AI trading agent replaces crypto wallets to steal passwords", "summary": "HP's September 17 security report detailed a campaign, observed between April and June 2026, in which malware disguised as an AI-powered crypto trading agent replaced seven browser wallet extensions — including MetaMask, Coinbase Wallet, and Phantom — with malicious copies that sent victims' passwords to attacker-controlled servers. The download, named Needle Stealer, bundled genuine Microsoft-signed software to pass initial Windows security checks before launching a malicious file that ran the wallet-stealing code in the background. HP advised users not to enter wallet passwords or make payments through unverified AI applications.", "body_md": "Cybercriminals have disguised malware as an AI-powered crypto trading agent to steal passwords from browser wallets.\n\nIn this campaign, seven wallet extensions, including **MetaMask, Coinbase Wallet, and Phantom**, were targeted. HP revealed this operation in its security report, dated **September 17**.\n\n## **Fake crypto trader delivers wallet-stealing malware**\n\nThe criminals created a website promoting software that supposedly used artificial intelligence to trade crypto around the clock.\n\nHowever, users who downloaded the advertised trading agent received malware known as Needle Stealer.\n\nThis was noticed by HP between **April and June 2026**. The attackers were targeting people who were searching online for AI tools that could help automate their crypto trades.\n\nAfter being installed, the crypto wallet extensions that were supported on the browser were looked for. The browser then closed, with the genuine extension on the browser being removed and replaced by a malicious copy.\n\nThe replacement looked like the wallet the user normally uses, but this was not the case. When the victims entered a password, the fake extension sent it to a server controlled by the attackers.\n\nThe stolen password and the wallet’s identifying information could allow the criminals have access to the victim’s crypto.\n\n## **Familiar appearance offered little protection**\n\nThe attackers took steps that made the download look legitimate.\n\nThe installation package included actual Microsoft-signed software. Because Windows read it as original, the download was able to pass initial security checks.\n\nThe trusted program then opened a malicious file placed with it, allowing the wallet-stealing software to begin running in the background.\n\nHP has told users not to enter their wallet passwords or make payments through AI applications that they cannot verify.\n\n## **Final Summary**\n\n- A fake AI trading agent replaced those actual wallets on the user’s machines with copies that stole passwords.\n- It was seen in a campaign lasting from April till June by HP.", "url": "https://wpnews.pro/news/fake-ai-trading-agent-replaces-crypto-wallets-to-steal-passwords", "canonical_source": "https://cryptonews.net/news/security/33459061/", "published_at": "2026-09-18 04:58:00+00:00", "updated_at": "2026-09-18 05:23:39.403463+00:00", "lang": "en", "topics": ["ai-tools", "ai-products"], "entities": ["HP", "MetaMask", "Coinbase Wallet", "Phantom", "Needle Stealer", "Microsoft", "Windows"], "alternates": {"html": "https://wpnews.pro/news/fake-ai-trading-agent-replaces-crypto-wallets-to-steal-passwords", "markdown": "https://wpnews.pro/news/fake-ai-trading-agent-replaces-crypto-wallets-to-steal-passwords.md", "text": "https://wpnews.pro/news/fake-ai-trading-agent-replaces-crypto-wallets-to-steal-passwords.txt", "jsonld": "https://wpnews.pro/news/fake-ai-trading-agent-replaces-crypto-wallets-to-steal-passwords.jsonld"}}