HP uncovered a cybercrime campaign using a fake AI-powered trading agent to steal passwords from crypto wallet users. Between April and June 2026, hackers targeted seven wallet extensions, including MetaMask, Coinbase Wallet and Phantom, replacing them with malicious copies that captured credentials. The malware, called Needle Stealer, was hidden inside automated trading software that appeared legitimate thanks to a genuine Microsoft certificate. Once installed, it sent passwords and wallet identification information to an attacker-controlled server, potentially allowing the theft of victims’ crypto assets.
Source: Read the original article

