Fake AI Tool Hijacks Crypto Wallets

A new cybersecurity threat has emerged targeting cryptocurrency users through deceptive artificial intelligence-powered trading tools. According to a report by HP Wolf Security, attackers are distributing fake AI crypto-trading assistants that secretly replace legitimate browser wallet extensions on infected Windows computers.
The malware, identified as Needle Stealer, is disguised within what appears to be a legitimate AI trading software. Victims are lured to download the fake application, often through search engine poisoning and paid advertisements promoting a tool called TradingClaw. The installer archive contains a legitimate-looking executable that bypasses security checks, while a malicious DLL injects the malware.
Once active, Needle Stealer targets specific cryptocurrency wallet extensions, including popular options like MetaMask, Phantom, and Trust Wallet. It replaces the genuine extension with a fraudulent version, presenting users with a realistic-looking login screen designed to capture their private keys and credentials. This sophisticated attack allows threat actors to gain unauthorized access to users' digital assets.
This is an AI-assisted summary. Original reporting by CryptoSlate.
Read the originalRelated stories

Ex-Robinhood Staff Charged Over Crypto Listing Trades
Former Robinhood engineers face US charges for allegedly profiting from insider information on crypto token listings.

US Seeks $61M in Tether Tied to Iran Oil Sales
Prosecutors are moving to seize $61 million in USDT linked to alleged Iranian oil sales, highlighting stablecoin issuer Tether's role in sanctions

SEC Official Supports Clarity Act, Pushes For Rules
An SEC commissioner endorsed a proposed crypto bill but emphasized the agency's ongoing efforts to establish regulations regardless of its passage.