• Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
HP Wolf Security finds fake AI trading bots hijacking crypto wallets

HP Wolf Security finds fake AI trading bots hijacking crypto wallets

09/19/2026
Report says Christine Lagarde intervened to derail Binance's Greek MiCA bid

Christine Lagarde intervened in Binance’s Greek MiCA license bid

09/18/2026
Robert Garcia vows sweeping Trump family probes if Democrats win House

Robert Garcia vows sweeping Trump family probes if Democrats win House

09/18/2026
  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
HP Wolf Security finds fake AI trading bots hijacking crypto wallets

HP Wolf Security finds fake AI trading bots hijacking crypto wallets

09/19/2026
Report says Christine Lagarde intervened to derail Binance's Greek MiCA bid

Christine Lagarde intervened in Binance’s Greek MiCA license bid

09/18/2026
Robert Garcia vows sweeping Trump family probes if Democrats win House

Robert Garcia vows sweeping Trump family probes if Democrats win House

09/18/2026
Saturday, September 19, 2026
  • Login
The Bit Gazette
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion
No Result
View All Result
The Bit Gazette
No Result
View All Result
Home Crypto News

HP Wolf Security finds fake AI trading bots hijacking crypto wallets

Fake AI Trading Tools are being used to spread malware that replaces legitimate crypto wallet extensions and steals users’ credentials.

by Moses Edozie
28 minutes ago
in Crypto News
Reading Time: 5 mins read
0
HP Wolf Security finds fake AI trading bots hijacking crypto wallets

HP Wolf Security finds fake AI trading bots hijacking crypto wallets

Share on FacebookShare on Twitter

Cybercriminals are exploiting growing interest in agentic AI by promoting fake AI Trading Tools designed to infect users with malware, according to research from HP Wolf Security covering activity between April and June 2026.

The campaign targets users with fraudulent AI trading agents that appear to offer automated cryptocurrency trading capabilities. Once the malicious software is installed, it scans the victim’s browser for cryptocurrency wallet extensions, including Coinbase and MetaMask.

MetaMask has also added real-time questions to catch romance and investment scams.

The malware can then replace legitimate wallet extensions with malicious copies. When victims enter their login information into the spoofed extensions, those credentials are captured and transmitted to the attackers, potentially giving them access to cryptocurrency holdings.

“Lots of users have already played with AI chatbots and now are interested in trying different AI agents that are available but it is difficult to distinguish an AI agent that is benign or malware,” said Patrick Schläpfer, Principal Threat Researcher at HP, during a media briefing for the HP Wolf Security Threat Insights Report.

The campaign illustrates how criminals can use legitimate interest in emerging technology as a delivery mechanism for malware. Rather than relying solely on conventional phishing messages, attackers are presenting malicious software as useful AI-powered products.

Patrick Schläpfer, Principal Threat Researcher at HP

Schläpfer said the malware also uses DLL side-loading to help bypass security checks before executing its payload.

“Threat actors make use of a technique called DLL side-loading. First the windows defender smart screen checks the executable for threats. So, naturally, the detection lets the executable run without interruption,” Schläpfer said.

Once executed, the malware uses a technique identified by HP as Needle Steeler to search browsers for cryptocurrency wallet extensions. The discovery of a wallet installation provides the malware with a specific target for credential theft.

AI Trading Tools are used to disguise wallet-stealing malware

The use of fake AI Trading Tools is particularly significant because users may approach automated trading products expecting them to interact with cryptocurrency wallets or exchanges.

In the campaign described by HP, however, the apparent trading functionality serves as a lure. The malware’s actual purpose is to identify cryptocurrency wallets and replace legitimate browser extensions with malicious lookalikes.

The affected extensions can imitate familiar interfaces closely enough to encourage users to enter sensitive information. Once credentials are submitted, the information is sent to the threat actor.

The approach creates a security risk beyond simply downloading a malicious application. Users may believe they are installing a new trading assistant while unknowingly granting malware an opportunity to inspect their browser environment and target digital-asset credentials.

HP’s research also points to a broader problem: malicious actors can package malware inside software that appears to have legitimate business or technical purposes.

That trend is also visible in the Phantom Gate campaign identified by researchers. Phantom Gate is described as a malware loader that appears to extend the Phantom Stealer campaign. Phantom Stealer itself has been openly marketed as penetration-testing software, while the Phantom Gate mechanism can be used to deliver the final malicious payload.

“Phantom Gate encrypts the malware to make it more difficult to recognise,” Schläpfer said.

“The idea of PhantomGate is to download and decode the final payload. The ecosystem is growing, giving less experienced technical criminals materials to act.”

The development means attackers with less technical expertise can potentially use existing malware components and delivery mechanisms to assemble campaigns rather than developing every component themselves.

QR-code phishing moves victims to less-protected phones

HP also identified another technique that complements the broader campaign: quishing, or phishing attacks that use QR codes.

Instead of directing victims immediately to a malicious website on their computers, attackers send PDF documents containing apparently protected or blurred content. The documents instruct recipients to scan a QR code with a mobile phone.

The QR code then redirects the victim to a phishing page that may be inaccessible from the computer because of corporate security controls.

Schläpfer described the tactic as a deliberate attempt to move users away from devices with stronger security protections.

“Users are forced from a well protected device like a business laptop to go to a less-secure device like a mobile phone,” Schläpfer said. “The phishing URL stored within the QR code might be blocked in the laptop but naturally on a mobile phone, you don’t have the same protection systems and therefore the link may not be blocked.”

The phishing process can then display a fake security verification message while the system supposedly checks whether the destination URL is safe.

“This is a fake message to trick the user,” Schläpfer said. “They [the malware systems] are trying to blend into a normal business process to make the user feel comfortable to lead them into a turnstile capture.”

The turnstile mechanism acts as an initial verification step before redirecting victims to a OneDrive-branded page containing email information. The information can then be captured by the attackers.

HP said 10% of email threats identified by its Sure Click technology successfully bypassed one or more traditional email gateway scanners, highlighting the limitations of relying solely on conventional email filtering.

AI Trading Tools add to a wider digital security challenge

The findings place fake AI Trading Tools within a wider ecosystem of attacks that combine social engineering, malware loaders and credential theft.

The threat is not limited to individual crypto traders. The use of familiar enterprise services such as Microsoft OneDrive in phishing flows demonstrates how attackers can exploit trusted brands and normal workplace processes to make malicious activity appear legitimate.

Youtube Placeholder
HP recommends multiple layers of protection, including HP Sure Click, HP Sure Access and HP Sure Recover.

“Sure Click doesn’t trust anything,” said Pelle Aardewerk, CISO Cyber Security Advisory Lead at HP. “It’s always opening in a micro-virtual machine, so even if what they click on is bad, it cannot escape or impact the host or network. It’s a preventative mechanism that still gives people the productivity they need to do their normal work.”

Sure Access is designed to isolate sensitive tasks in a separate hardened session, while Sure Recover provides mechanisms for restoring compromised devices.

“Digital resilience is a key topic at conferences… it will never 100% exist in security,” Aardewerk said. “Hackers are creative so if things go wrong, the question is how quickly can we recover and go back to productive business-critical operations.”

Tags: agentic AIAIBitcoincoinbasecryptocybersecurityfraudmalwareMetamaskphishingprivacyQuishingsecuritytechnologyThreatstradingwallets
Share197Tweet123
Moses Edozie

Moses Edozie

Moses Edozie is a writer and storyteller with a deep interest in cryptocurrency, blockchain innovation, and Web3 culture. Passionate about DeFi, NFTs, and the societal impact of decentralized systems, he creates clear, engaging narratives that connect complex technologies to everyday life.

  • Trending
  • Comments
  • Latest
Ian Issa explains how HashNet turned Zcash's $50-to-$600 rally into Bitcoin without holding a coin

Ian Issa explains how HashNet turned Zcash’s $50-to-$600 rally into Bitcoin without holding a coin

07/18/2026 - Updated on 07/19/2026
Leaked Chainalysis Video Raises Concerns Over Monero Traceable Transaction Claim

Chainalysis sues US government over $94.66 million ICE contract awarded to TRM Labs

08/18/2026
The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

The Louvre needed police escorts to move crypto attendees: Decentralised money just decentralised the danger

04/18/2026 - Updated on 05/25/2026
Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

Polygon Discord Channel Hacked, Throws Crypto Community in Turmoil

2
Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

Bitcoin reclaims $107,000 as Iran-Israel ceasefire cools market tensions

2

Hello world!

1
HP Wolf Security finds fake AI trading bots hijacking crypto wallets

HP Wolf Security finds fake AI trading bots hijacking crypto wallets

09/19/2026
Report says Christine Lagarde intervened to derail Binance's Greek MiCA bid

Christine Lagarde intervened in Binance’s Greek MiCA license bid

09/18/2026
Robert Garcia vows sweeping Trump family probes if Democrats win House

Robert Garcia vows sweeping Trump family probes if Democrats win House

09/18/2026
The Bit Gazette

Copyright © 2025 - The Bit Gazette.

Navigate Site

  • About
  • Advertise
  • Privacy & Policy
  • Contact

Follow Us

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Crypto News
  • Expert Analysis
  • Finance
  • Tech
  • Sponsored
  • Press Release
  • Opinion

Copyright © 2025 - The Bit Gazette.