The post Fake AI Crypto Tools Replace Wallet Extensions appeared on BitcoinEthereumNews.com.
Fake AI crypto tools spread malware that swaps wallets and steals user credentials. Attackers use ads and fake sites to trick users into installing malicious software. Malware forces browser restarts and prompts fake logins to capture wallet credentials. A security report by tech giant HP has highlighted the rising threat of attackers using fake AI crypto trading tools to deliver malware that replaces legitimate browser-wallet extensions and steals wallet passwords. HP noted this in its September 2026 Wolf Security Threats Insight Report, describing it as the latest technique cybercriminals deploy against unsuspecting internet users. According to HP’s report, attackers built a website camouflaging itself as an AI-powered crypto trading assistant, borrowing the name of a well-known AI tool to seem trustworthy, and used it to spread Needle Stealer. Hackers’ Soft Targets The hackers targeted users looking for AI bots to grow their portfolio. The users instead downloaded malware that used a legitimate Microsoft-signed program to sneak in a malicious file. The malware quietly swapped their browser’s cryptocurrency wallet for a fake one. Once they typed in their wallet password, the attackers had everything they needed to empty it. Other strategies that HP reported include phishing campaigns that hid a QR code inside a PDF invoice. In this case, attackers coaxed potential victims to use their phones and scan QR codes on the invoice. That strategy moves them away from the protections guarding a work PC. So, even after blocking a threat on a computer, hackers could still access their targets through mobile devices. Nothing to Do With Actual Wallet Breaches Hackers capitalize on the common pattern of integrating crypto wallets into browsers as extensions by implementing these techniques. The malware compares the 32-character IDs of the extensions it finds with a predefined list, searching for the IDs of seven crypto…
