Fake AI Trading Agent Steals Crypto Wallet Passwords
HP uncovered an April–June 2026 campaign: tradingclaw[.]pro offered an installer for a fake AI crypto trading agent, but it contained a Microsoft-signed OLEView that used DLL side-loading to run Needle Stealer. The malware swaps extensions in seven browser wallets, including MetaMask, Coinbase Wallet and Phantom, and sends passwords to attackers.
- Needle Stealer campaign recorded by HP from April to June 2026
- Attack targets seven browser wallets, including MetaMask and Phantom
- Installer masquerades as Microsoft-signed OLEView
- QR phishing and campaigns with XWorm, PureLogs and Formbook also seen
Read next
Security