A security report by tech giant HP has highlighted the rising threat of attackers using fake AI crypto trading tools to deliver malware that replaces legitimate browser-wallet extensions and steals wallet passwords.
HP noted this in its September 2026 Wolf Security Threats Insight Report, describing it as the latest technique cybercriminals deploy against unsuspecting internet users. According to HP’s report, attackers built a website camouflaging itself as an AI-powered crypto trading assistant, borrowing the name of a well-known AI tool to seem trustworthy, and used it to spread Needle Stealer.
Hackers’ Soft Targets
The hackers targeted users looking for AI bots to grow their portfolio. The users instead downloaded malware that used a legitimate Microsoft-signed program to sneak in a malicious file. The malware quietly swapped their browser’s cryptocurrency wallet for a fake one. Once they typed in their wallet password, the attackers had everything they needed to empty it.
Other strategies that HP reported include phishing campaigns that hid a QR code inside a PDF invoice. In this case, attackers coaxed potential victims to use their phones and scan QR codes on the invoice. That strategy moves them away from the protections guarding a work PC. So, even after blocking a threat on a computer, hackers could still access their targets through mobile devices.
Nothing to Do With Actual Wallet Breaches
Hackers capitalize on the common pattern of integrating crypto wallets into browsers as extensions by implementing these techniques. The malware compares the 32-character IDs of the extensions it finds with a predefined list, searching for the IDs of seven crypto wallets, including Phantom, Trust Wallet, Atomic Wallet, Coinbase Wallet, OKX Wallet, MetaMask, and Tonkeeper.
The security threat that HP highlighted does not involve wallet breaches. Instead, it focuses on luring users and deceiving them through search results and ads. They appeal to their eagerness to find efficient trading solutions, particularly AI tools that can help them make money and potentially improve their trading experience.
Key Indicators to Watch
The HP Wolf Security Report highlighted key indicators users should watch out for to keep safe from the identified threat. The malware operates by forcefully killing a target’s web browser process so it can unpack and overwrite the extension folder. Therefore, an abrupt browser shutdown and restart is a red flag.
HP noted that the malware typically terminates and restarts the victims’ internet session and requests them to enter their wallet ID and password on a “familiar” screen. That is a key indicator of a credential trap that crypto users need to be wary of. Attackers often distribute the fake AI trading software via sponsored search results or ads as compressed files.
Crypto users should be highly suspicious of trading tools that require manual zip installation rather than an official deployment from an app store or web store. As a rule of thumb, HP recommends completely avoiding opaque, unverified agent applications and keeping sensitive financial workflows isolated from third-party tools.
The Original Phantom Stealer
The highlighted threat impersonates “Phantom Stealer,” a sophisticated Windows-focused information-stealing malware offered commercially under a Malware-as-a-Service (MaaS) subscription model. Phantom Stealer is designed to covertly harvest sensitive data directly from infected machines, targeting web browsers to siphon saved credentials, session cookies, autofill data, and payment information.
The ethical malware seller offers two components: a stealer, which is the final payload that exfiltrates sensitive data from infected devices, and a crypter that encrypts and protects the payload from analysis and reverse engineering. However, HP noted that virtually no attacker will adhere to the marketer’s ethical condition, which is agreeing not to use the toolkit for malicious purposes.
Related: Hackers Are Using Google Docs and Claude.ai to Spread Crypto Malware
coinedition.com