Fake AI Trading App Used to Target Crypto Wallet Extensions

4 min read

Cybercriminals are using the growing interest in artificial intelligence and automated crypto trading to target cryptocurrency users with malware designed to steal wallet credentials.

Security researchers said a campaign observed between April and June 2026 promoted a fake AI-powered trading service called TradingClaw. The operation used a Windows application as the entry point for malware that could replace legitimate cryptocurrency wallet extensions in a user’s browser.

The campaign was publicly detailed by HP Wolf Security on September 17.

Fake AI Trading Platform Used as a Lure

The campaign promoted TradingClaw as an always-on AI trading agent capable of operating around the clock.

Users who followed the service’s download instructions were directed to a Windows executable presented as a legitimate Microsoft-signed application.

The apparent Microsoft signature was used as part of the malware’s delivery process and did not mean the software itself was trustworthy.

The approach was designed to make the download appear legitimate and potentially reduce the likelihood that Windows security protections or users would flag it as suspicious.

Instead of providing the advertised trading service, the software delivered malware that targeted cryptocurrency wallet extensions installed in the victim’s browser.

Malware Replaced Legitimate Wallet Extensions

Researchers identified the malware involved in the campaign as Needle Stealer.

After the malicious program was executed, it reportedly used a legitimate Microsoft-signed OLEView executable to perform DLL side-loading. This technique allows malicious code to be loaded through a legitimate application, helping the malware blend into normal system activity.

The malware then targeted files associated with cryptocurrency wallet extensions.

By replacing legitimate extension files with malicious versions, attackers could create a counterfeit interface that looked like the wallet application the user expected to see.

This meant a victim could continue interacting with what appeared to be a familiar wallet while unknowingly providing sensitive information to the attackers.

Seven Crypto Wallets Targeted

The campaign targeted seven browser-based cryptocurrency wallet extensions:

  • MetaMask
  • Coinbase Wallet
  • Phantom
  • Trust Wallet
  • OKX Wallet
  • Atomic Wallet
  • Tonkeeper

The attack was not limited to a single cryptocurrency network or trading platform. Instead, it focused on browser wallet extensions used across different crypto ecosystems.

The malicious extensions were designed to capture passwords entered through the counterfeit wallet interfaces and transmit the information to servers controlled by the attackers.

The available reporting does not establish how many users were affected or how much cryptocurrency may have been stolen.

AI Hype Used to Increase Credibility

The campaign reflects a broader tactic in which criminals use popular technology trends to make malicious software appear more convincing.

The TradingClaw operation used the growing interest in AI agents and automated trading as its primary lure. An always-on trading system can sound attractive to cryptocurrency users looking for automated ways to monitor or trade digital assets.

In this case, however, the advertised AI trading service served as a delivery mechanism for malware.

The campaign demonstrates why users should be cautious when downloading software promoted through unfamiliar websites, particularly when the application claims to provide financial or cryptocurrency-related services.

Security Risks Extend Beyond the Trading App

The attack also highlights the risks associated with browser-based cryptocurrency wallets.

A malicious application does not necessarily need to break into a cryptocurrency exchange or directly compromise a blockchain network. Compromising the software environment where users manage their wallets can provide another route to sensitive information.

Replacing a legitimate wallet extension is particularly concerning because the interface may continue to look familiar to the victim.

HP’s research indicates that the campaign was active during April, May and June 2026 before the security findings were publicly disclosed in September.

The incident serves as a reminder that the appearance of legitimacy—including a software signature associated with a trusted technology company—does not by itself establish that an application is safe.

Users should verify the source of cryptocurrency software before installing it and avoid downloading wallet or trading applications from unfamiliar websites.

Disclaimer: This article is for informational purposes only and does not constitute legal, tax, investment, financial or other professional advice.

Leave a Comment