Friday, September 18, 2026

Creating liberating content

CLARITY Act needs 3...

Seven Democratic senators said Sept. 16 that CLARITY's failed Senate vote was not...

Buying Bitcoin Is Like...

Top financial advisor Ric Edelman has compared buying bitcoin today to...

Wall Street gains direct...

S&P Global has agreed to acquire smart contract security company OpenZeppelin in a...

Bitcoin ETFs Could Triple...

Bitcoin exchange-traded funds could be three times bigger than their gold...

Fake AI crypto software is secretly replacing browser wallet extensions

HP Wolf Security, the company’s threat-research team, said a fake AI crypto-trading assistant distributed malware that could replace browser crypto wallet extensions on an infected Windows computer and turn the familiar wallet interface into a credential trap.

The campaign appeared in HP’s September threat report, published Sept. 17 and based on threats observed from April through June 2026. HP described a compromise that began on a user’s endpoint after a counterfeit trading tool was downloaded and run, not a breach of Coinbase, MetaMask, or their official extensions.

Malwarebytes had documented the TradingClaw campaign in April and found that Needle Stealer also circulated through other malware loaders. The fake AI assistant was one route into a broader malware operation.

Related Reading

Hackers sneak crypto wallet-stealing code into a popular AI tool that runs every time

Read More:  Avalanche’s Helicon upgrade cuts validator lockups from 14 days to 48 hours

Attackers promoted tradingclaw[.]pro as an AI assistant that could follow a personalized strategy and trade around the clock, according to the full HP report. Search-engine poisoning and paid advertisements directed prospective victims to a ZIP file presented as the software’s installer.

The archive contained an executable named Trading Agent.exe and a DLL named iviewers.dll. HP identified the executable as OLEView, Microsoft’s legitimate, digitally signed OLE/COM Object Viewer. HP said the signed program helped bypass Microsoft’s SmartScreen reputation check, while the malicious payload remained in the accompanying DLL.

Running the trusted-looking program caused it to load that DLL. The code then decrypted Needle Stealer and used process hollowing, a technique that runs malicious code inside a newly launched legitimate process.

Read More:  Bitcoin’s 7 million coin quantum problem just reached the US Treasury