Close Menu
xpertsstudio

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    A Crypto Trader Lost Around $600,000 After a Fake Cloudflare Verification

    September 17, 2026

    XRP Open Interest Plunges 23% as Traders Unwind Leverage

    September 17, 2026

    UK watchdog targets three London sites suspected of illegal crypto trading

    September 17, 2026
    Facebook Instagram YouTube WhatsApp TikTok Telegram
    xpertsstudio
    Facebook Instagram YouTube WhatsApp TikTok Telegram
    • Home
    • DeFi News
    • Altcoin News
    • Bitcoin News
    • Ethereum News
    • Crypto Business
    • More
      • Blockchain & Web3
      • Crypto Regulation
      • Crypto Markets
    xpertsstudio
    Home»Crypto Markets»Fake AI trading agent steals crypto wallet passwords
    September 17, 20260 Views

    Fake AI trading agent steals crypto wallet passwords

    EditorBy EditorSeptember 17, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
    Follow Us
    Google News Flipboard
    Fake AI trading agent steals crypto wallet passwords
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Don't want to trade it yourself?

    Our desk runs DEX portfolios on profit share.

    35% Share
    $2.5K Minimum
    Learn more

    Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April and June 2026.

    The Needle campaign targets people who download AI agents from search results or ads, and users of seven browser wallet extensions, among them MetaMask, Coinbase Wallet and Phantom. HP also caught QR code phishing that moves victims onto their phones.

    Example of a website promising an installer for an AI trading agent

    The installer is genuine Microsoft software

    The site, tradingclaw[.]pro, gave its bot a name that echoes a well-known AI assistant and promised an agent that trades crypto around the clock. Inside the ZIP download, Trading Agent.exe is OLEView, a Microsoft-signed program, so Windows SmartScreen’s reputation check trusts it. Its only purpose is to get past that check. When it runs, it loads iviewers.dll, the malicious file beside it, a trick called DLL side-loading.

    That DLL runs Needle Stealer inside a freshly started legitimate process, a technique called process hollowing. Needle looks for any of the seven wallet extensions, kills the browser, and unpacks a malicious copy into the extension’s folder. The fake extension then contacts the attacker’s command server and hands over whatever password the victim types. With the wallet ID and password, the attacker controls the funds.

    If you keep a crypto wallet in your browser, a familiar unlock screen does not prove the extension is the one you installed. HP recommends keeping wallet passwords and payment work out of agent apps you cannot verify.

    The QR code moves the victim to a phone

    Researchers also caught several campaigns that emailed PDF invoices showing a blurred document behind a QR code, with a note telling the recipient to scan it with a smartphone, a method known as quishing. The scan runs through redirects, including a fake email security scanner and a Cloudflare Turnstile check that confirms a person is loading the page, then lands on a page resembling OneDrive that asks for Microsoft credentials.

    A work PC may have email gateways and browser protections that already block a known phishing domain. A phone usually carries fewer defenses, so a link the desktop would stop may load on the phone.

    A stealer sold with customer support

    Phantom Stealer is sold openly on the web as a “penetration testing tool,” alongside a crypter that encrypts it against analysis, feature updates and 24/7 support. Buyers must agree not to use it for malicious purposes. HP isolated several email campaigns delivering it.

    A VBScript in each campaign built a PowerShell command that fetched an ordinary-looking image and pulled a .NET loader out of it, a method called steganography. A component named Phantom Gate, built into the PowerShell script, started that loader. The loader then downloaded the stealer, decoded it and injected it into RegAsm, a legitimate .NET Framework process. Researchers believe the shared name and delivery chain suggest one threat actor may be behind both tools.

    “Users move constantly between devices and applications, like browsers or new AI tools, and attackers are quick to follow. Security needs to work across all of those interactions, without getting in people’s way. That means organizations need a zero-trust approach built around isolation and containment, so untrusted clicks and downloads don’t become a risk,” said James Wright, HP’s Global Head of Security for Personal Systems.

    Hundreds of rigged images

    Other invoice campaigns arrived two ways. Some used HTML smuggling, which assembles the malicious file on the victim’s machine so it can slip past email gateway scanners. Others relied on search results leading to lookalike domains. Both routes ended with loaders that decoded payloads hidden in images and installed XWorm, PureLogs Stealer or Formbook, which steal credentials and system data.

    A perceptual-hash search of VirusTotal, which matches images by how they look, turned up about 400 distinct images tied to these campaigns over three months.

    Fake installers

    HP’s researchers also traced a Russian-language imitation of Microsoft’s site whose installer bundles other products for affiliate payouts and never installs Word. The security product it bundles then flags that installer as dangerous and deletes it. Two signed installers, UltraZip and AllFiles, hijack the default search engine and keep the change after uninstall.

    Download: 2026 Credential Risk Report

    Source: www.helpnetsecurity.com

    Partner offer

    Start trading on Bybit

    Deep derivatives liquidity, tight spreads, and a deposit bonus on your first funding.

    Claim bonus
    agent Crypto Fake Steals Trading
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    K
    Mentioned in this article

    KuCoin

    Spot, futures and trading bots in one account. Our link applies a fee discount at signup.

    Open account

    Related Posts

    A Crypto Trader Lost Around $600,000 After a Fake Cloudflare Verification

    September 17, 2026

    UK watchdog targets three London sites suspected of illegal crypto trading

    September 17, 2026

    Is your crypto investment opportunity a scam?

    September 17, 2026
    Leave A Reply Cancel Reply

    Accepting new clients

    Portfolio Management

    Managed trading on centralised and decentralised markets, handled by our experienced trading desk.

    Professional crypto trading management
    Profit share 35%
    Min. capital $2,500
    Wallet Set up by us
    Execution Full service
    How the service works
    • New to on-chain trading? Our team runs it for you on a profit-sharing basis.
    • We create the wallet and place every trade — no DEX experience needed on your side.
    • The share is 35% of profit on each token traded.
    • Minimum starting capital is $2,500.
    Start DEX Management
    Profit share 00%
    Min. capital $0,000
    Custody Your account
    Execution Full service
    How the service works
    • Your funds remain in your own exchange account while our team manages the trading activity.
    • You maintain control of your account and funds throughout the management period.
    • We provide professional trading management based on the agreed strategy and terms.
    • Works with KuCoin, MEXC, Bybit and Phemex.
    • Receive a monthly report covering positions, trading activity and performance.
    CEX management terms, profit split and minimum capital are agreed in writing before onboarding.
    Apply for CEX Management

    Not financial advice. Crypto trading involves substantial risk and past results do not guarantee future returns. Capital can be lost in full. Full terms are agreed in writing before onboarding.

    Trusted Exchanges

    5

    Open an account through our partner links to claim fee discounts and sign-up bonuses.

    K KuCoin Spot & futures · trading fee discount M MEXC Widest altcoin listings · low maker fees B Blofin Copy trading · no-KYC onboarding Y Bybit Deep derivatives liquidity · deposit bonus P Phemex Contract trading · zero-fee spot plan

    Affiliate disclosure: We may earn a commission when you sign up through these links, at no extra cost to you. Trading carries risk — never invest more than you can afford to lose.

    Top Posts

    XRP Price to $0.18? Analysts Warn of Drop as Brad Garlinghouse Bets on Ripple’s Crypto Winter

    August 19, 20266 Views

    5 Best New Crypto Presales as Uniswap Surges 34% in a Week and DEX Trading Returns to Center Stage

    September 5, 20265 Views

    XRP Branding Hits Florida Field in Reported $5M Annual Ripple Deal

    September 5, 20265 Views
    0% Spot fees

    Phemex zero-fee spot plan

    Sign up with our referral code to activate the plan on a new account.

    CODE · E4G2K
    Redeem
    Most Popular

    XRP Price to $0.18? Analysts Warn of Drop as Brad Garlinghouse Bets on Ripple’s Crypto Winter

    August 19, 20266 Views

    5 Best New Crypto Presales as Uniswap Surges 34% in a Week and DEX Trading Returns to Center Stage

    September 5, 20265 Views

    XRP Branding Hits Florida Field in Reported $5M Annual Ripple Deal

    September 5, 20265 Views
    Our Picks

    A Crypto Trader Lost Around $600,000 After a Fake Cloudflare Verification

    September 17, 2026

    XRP Open Interest Plunges 23% as Traders Unwind Leverage

    September 17, 2026

    UK watchdog targets three London sites suspected of illegal crypto trading

    September 17, 2026

    Stay Ahead of Crypto

    Get the latest crypto, blockchain, and Web3 news delivered straight to your inbox.

    Facebook Instagram YouTube WhatsApp TikTok Telegram
    • About Us
    • Contact us
    • Disclaimer
    • Privacy Policy
    • Terms & Conditions
    © 2026 Xperts Studio. Develop by Pro

    Type above and press Enter to search. Press Esc to cancel.