Fake AI trading bot silently swaps 7 crypto wallet extensions

Share

Two major campaigns documented by HP Wolf Security and McAfee show how attackers exploit the credibility of artificial intelligence and the familiarity of browser extensions to drain crypto holders’ funds. Victims are lured with seemingly legitimate tools, and their assets are exfiltrated to attacker wallets with no obvious on-chain signature.

🔑 Key takeaways

  • HP Wolf Security details the TradingClaw campaign, which swaps 7 wallet extensions for credential-stealing copies.
  • McAfee identifies Google Notes, a clipper extension that silently rewrites wallet addresses copied to the clipboard.
  • Darktrace enumerates several fake companies (Pollens AI, Swox, Eternal Decay, Solune) used to distribute stealers.
  • Google removed 49 Chrome extensions impersonating Ledger, MyEtherWallet and Trezor.
  • The CrazyEvil group, active since 2021, has reportedly generated millions of dollars according to Recorded Future.

TradingClaw and Needle Stealer: AI as bait

HP Wolf Security published on September 17, 2026 a threat report covering April through June 2026 detailing a campaign exploiting a fake AI trading assistant called TradingClaw. The promotional site tradingclaw[.]pro was indexed via SEO poisoning and sponsored search ads. The distributed archive contained an executable named Trading Agent.exe bundled with a library called iviewers.dll.

The executable matched OLEView (OLE/COM Object Viewer), a Microsoft-signed tool. That legitimate signature helped bypass SmartScreen. At launch, iviewers.dll was loaded via DLL side-loading, then Needle Stealer was decrypted and executed inside a fresh Microsoft process using process hollowing, a technique that replaces the in-memory code of a suspended process.

Once active, Needle Stealer enumerated installed Chromium extensions and compared their 32-character alphanumeric identifiers against a hardcoded list:

ExtensionPrimary ecosystem
PhantomSolana
Trust WalletMulti-chain
Atomic WalletMulti-chain
Coinbase WalletEthereum and L2s
OKX WalletMulti-chain
MetaMaskEthereum and EVM
TonkeeperTON (Telegram Open Network)

On a match, the malware closed the browser, swapped the legitimate extension for a malicious copy, then relaunched the browser. On first launch, the rogue extension contacted a command-and-control (C2) server and loaded fallback domains. Login screens faithfully mimicked official interfaces; the credentials and passwords entered by the victim were exfiltrated to the operator.

HP noted that for wallets protected by a secret recovery phrase, the entered password does not allow re-importing the wallet elsewhere: it unlocks MetaMask locally. However, the substituted extension ran on a device already under attacker control, exposing all locally accessible funds. HP did not disclose the victim count or total amount stolen. Malwarebytes had already documented TradingClaw in April 2026 and confirmed Needle Stealer was also distributed via other loaders.

Phantom Stealer and quishing: the full lure toolkit

In the same report, HP described campaigns delivering Phantom Stealer, openly sold as a penetration testing tool with 24/7 support, an integrated crypter and feature updates. A VBScript generated a PowerShell command that fetched an innocuous image from which a .NET loader was extracted via steganography, hiding code inside a media file. The Phantom Gate component initialized that loader, which then downloaded the stealer, decoded it and injected it into RegAsm, a legitimate .NET framework process.

HP also flagged quishing operations, phishing via QR code, in which PDF invoices emailed to victims showed a blurred document behind a QR code to scan with a phone. The victim passed through a fake security scanner and a Cloudflare Turnstile verification before landing on a page mimicking OneDrive and asking for Microsoft credentials. A corporate PC usually has security gateways blocking known phishing domains; a smartphone is more exposed, letting a URL blocked on desktop load on mobile.

« Users constantly move between devices and applications, such as browsers or new AI tools, and attackers quickly follow them. Security must work across all these interactions without getting in users’ way. This means organizations must adopt a zero-trust approach based on isolation and containment, so that untrusted clicks and downloads do not become a risk. »

James Wright, Global Head of Personal Systems Security at HP

HP’s perceptual image hashing on VirusTotal identified roughly 400 distinct images linked to these campaigns over three months. The shared naming and delivery chain suggest a single actor may orchestrate Phantom Stealer and Needle Stealer.

Google Notes: the clipper rewriting the clipboard

McAfee published on June 30, 2026 the results of its investigation into a separate campaign involving a malicious extension named Google Notes. Marketed as a note-taking tool, it ran a clipper attack: intercept a wallet address copied to the clipboard and replace it with an attacker-controlled address. Unsigned installers were observed in both .NET and Golang variants; they deployed the rogue Chromium extension by directly modifying browser preference files, bypassing normal security prompts, especially on older Chromium builds where developer mode could be exploited.

The extension requested disproportionate permissions for a note-taking app: access to all sites, browsing history and clipboard. It watched copy events and checked the content against regexes targeting Bitcoin, Ethereum, Bitcoin Cash, Ripple and Dash. On a match, the intercepted address was sent to the attacker backend; the backend returned a victim-specific replacement address, which was written back to the clipboard before the user pasted.

The campaign used a technique called EtherHiding: Ethereum smart contracts served as a dynamic source for C2 domains. The attacker could rotate infrastructure by updating a contract value, without redeploying the malware. McAfee observed that, for Bitcoin and Ethereum, each input address produced a unique but deterministic replacement address. For Solana, a single static address was returned for all victims, making a progressive balance accumulation visible. One of the controlled Ethereum addresses held about $1,902 at analysis time. Telemetry showed a notably higher infection concentration in India, suggesting an opportunistic rather than regionally targeted operation. McAfee detects the threat as CryptoStealer.NE.

Darktrace and CrazyEvil: industrial-scale social engineering

Darktrace published, before both HP and McAfee reports, an investigation into a social engineering campaign built around AI, gaming, video conferencing, Web3 and social network themes. In December 2024, Cado Security Labs had already documented the Meeten campaign, which targeted Web3 employees through fake meeting software vendors.

Darktrace confirmed the campaign is still running. Operators used compromised X (formerly Twitter) accounts, often verified, to reach out to victims and build a credible facade. Notion, Medium and Github hosted whitepapers, roadmaps and fake employee profiles. Windows and macOS variants coexisted; Windows binaries were signed with stolen code-signing certificates. macOS versions distributed Atomic Stealer, targeting browsers, crypto wallets, cookies and documents.

Identified fake entities include Pollens AI (collaborative AI), Buzzu, Cloudsign, Swox (a Web3 social network), Wasper, Eternal Decay (a blockchain game) and Solune. Some even ran fake merchandising stores. Recorded Future attributes part of these operations to the traffers collective CrazyEvil, active since at least 2021 and specialized in attacks against crypto users, influencers, DeFi professionals and gaming communities. The group has reportedly generated millions of dollars in revenue according to the threat intel firm.

Google pulls 49 Chrome extensions

The pattern is not new: Google already removed 49 extensions from the Chrome Web Store impersonating wallet apps for Ledger, MyEtherWallet and Trezor. The 49 extensions were identified by Harry Denley, head of security at MyCrypto, then published by ZDNet. According to Denley, they appeared to have been compiled by the same person or group, likely Russian-speaking.

« While all extensions work in the same way, the presentation differs based on the targeted users. »

Harry Denley, Head of Security at MyCrypto

The fake extensions sent data entered during setup to one of the attacker’s servers or a Google Form. Funds were not immediately drained during controlled tests by Denley. He believes the group either targets high-value accounts or has not yet automated the theft. He expects more malicious extensions to surface in the coming months and encourages reporting via CryptoScamDB.


Conclusion

These campaigns confirm a heavy trend: AI and browser extensions have become first-class entry points for attacks against crypto users. The attack surface widens as mainstream tools (trading assistants, note managers, Web3 integrations) gain credibility with the general public. To reduce risk, defenders must combine digital hygiene, manual URL verification, download isolation and systematic hardware wallet use.

As long as attackers can abuse code signing, mobile quishing and EtherHiding to rotate infrastructure on demand, vigilance will remain the price of holding your own keys. The next waves will likely combine voice deepfakes, compromised AI agents and AI-augmented extensions to further automate the outreach phase.

Sources

This article is published for informational and educational purposes only. It does not constitute investment advice in any form. Do your own research (DYOR) before any decision.

Telemac
Telemachttp://cryptoinfo.ch
Passionné de nouvelles technologies, j’explore l’univers de la blockchain et des cryptomonnaies pour partager l’actualité et les innovations du secteur.

Lire la Suite

Articles