• 4 mins read
  • Published

Fake AI Crypto Tool Swaps Out Wallet Extensions for Credential-Stealing Copies

Catheryne Nicholson Crypto infrastructure writer EgonCoin

Post by Catheryne Nicholson

Fake AI Crypto Tool Swaps Out Wallet Extensions for Credential-Stealing Copies EgonCoin © egoncoin.com
Fake AI Crypto Tool Swaps Out Wallet Extensions for Credential-Stealing Copies © egoncoin.com

A counterfeit AI trading assistant distributed malware that secretly replaced trusted browser wallet extensions with credential-stealing lookalikes, putting user funds at risk. The true scale of losses remains unknown.

Browser wallet extensions have become a popular target for attackers using fake AI crypto tools to steal funds. HP Wolf Security reports that a recent campaign, disguised as an AI trading assistant, has been swapping out legitimate wallet extensions on Windows PCs for credential-stealing copies. These lookalike interfaces trick users into handing over their wallet credentials.

Malware Hidden in AI Trading Software

The attack starts when someone downloads what looks like an AI-powered crypto trading assistant from tradingclaw[.]pro. The installer, promoted through search ads and manipulated search results, includes both a legitimate Microsoft-signed executable and a malicious DLL. This setup lets the malware slip past Windows security and run Needle Stealer, a payload built to hijack browser wallet extensions.

Needle Stealer targets seven major Chromium-based wallet extensions, including MetaMask, Coinbase Wallet, and Trust Wallet, by replacing them with credential-stealing copies.

HP Wolf Security

Once running, Needle Stealer scans Chromium-based browsers for wallet extensions like MetaMask, Coinbase Wallet, Phantom, Trust Wallet, Atomic Wallet, OKX Wallet, and Tonkeeper. If it finds any, it closes the browser and swaps the real extension for a fake one. The next time the user opens their wallet, the counterfeit extension connects to the attacker's server and shows a convincing login screen. Any credentials entered go straight to the attacker, putting any accessible funds at risk.

Attack Scope and Technical Details

HP Wolf Security's September threat report, covering activity from April through June 2026, explains that the attackers used OLEView, a legitimate Microsoft tool, to avoid detection. The malicious DLL, loaded by OLEView, decrypts and launches Needle Stealer using process hollowing-running malicious code inside a trusted process. This makes the attack harder for both users and security software to spot.

The campaign did not involve a breach of official wallet providers like MetaMask or Coinbase. Instead, it took advantage of the trust users place in browser extensions. The attackers built convincing replicas of wallet login screens, making it more likely that victims would enter their credentials without realizing anything was wrong. HP did not share how many users were affected or how much crypto was stolen, so the full impact is still unknown.

Browser-based wallets such as MetaMask and Coinbase Wallet are widely used for interacting with DeFi protocols and NFT marketplaces, but their exposure to browser malware makes them a frequent target for credential theft. Hardware wallets, by contrast, store private keys offline and are less susceptible to such attacks.

Broader Malware Landscape

This is not the only campaign of its kind. Malwarebytes previously documented the TradingClaw operation in April, noting that Needle Stealer was also spread through other malware loaders. The use of search-engine poisoning and paid ads to attract victims shows how crypto-focused cybercriminals are adapting their tactics. Even after major botnets are taken down, as seen in recent reports, malware targeting crypto wallets continues to evolve and pose risks to users.

For people using browser-based wallets, the danger goes beyond password theft. MetaMask, for example, points out that a password alone cannot restore a wallet on another device, but on a compromised computer, any funds accessible through the extension are still vulnerable. This attack shows that even software that looks legitimate can be used to bypass security and steal digital assets.

Security Implications for Wallet Users

Without public numbers on victims or losses, it's hard to know how far this campaign reached, but the technical skill behind it is clear. By using trusted software and realistic interfaces, the attackers have made it riskier for anyone managing crypto through browser extensions. The incident is a reminder to check the authenticity of any software before installing it and to be wary of extension updates or replacements that happen without clear permission.

Browser wallet extensions are convenient but come with unique security risks. Unlike hardware wallets, which keep private keys offline, browser-based wallets can be manipulated or replaced by malware. Even a familiar login screen can be a front for credential theft if the extension has been swapped out. Regularly reviewing installed extensions, downloading only from reputable sources, and considering hardware wallets for larger amounts can help reduce the risk of these attacks.

Related articles