NewsLayer

Install NewsLayer

Get the app experience — one tap from your home screen, instant loads and breaking-news alerts.

NewsLayer.com
LatestDaily BriefMarkets
NewsLayer PulseLIVE₿BTC$81,056-0.26%ΞETH$2,619+0.26%◎SOL$110.18-2.84%✕XRP$1.4-0.94%ÐDOGE$0.0871-0.94%₳ADA$0.2269-0.95%Total Cap$2.74T-0.36%24H Vol$107.8BLayer Index58 Neutral
BreakingNorth Korea Hackers Drain 7,000 Crypto Walletshace 5 horas
Markets
HomeArtificial IntelligenceCrypto

Artificial Intelligence|Crypto

Fake AI crypto software is secretly replacing browser wallet extensions

HP Wolf Security, the company's threat-research team, said a fake AI crypto-trading assistant distributed malware that could replace browser crypto wallet extensions on an infected Windows computer and turn the familiar wallet interface…

CryptoSlate

Publisher

Sep 18, 2026 at 5:10 AM UTC · 2 min de lectura

Fake AI crypto software is secretly replacing browser wallet extensions
Image via CryptoSlate
Traduciendo…

HP Wolf Security, the company's threat-research team, said a fake AI crypto-trading assistant distributed malware that could replace browser crypto wallet extensions on an infected Windows computer and turn the familiar wallet interface into a credential trap.

The campaign appeared in HP's September threat report, published Sept. 17 and based on threats observed from April through June 2026. HP described a compromise that began on a user's endpoint after a counterfeit trading tool was downloaded and run, not a breach of Coinbase, MetaMask, or their official extensions.

Malwarebytes had documented the TradingClaw campaign in April and found that Needle Stealer also circulated through other malware loaders. The fake AI assistant was one route into a broader malware operation.

Attackers promoted tradingclaw[.]pro as an AI assistant that could follow a personalized strategy and trade around the clock, according to the full HP report. Search-engine poisoning and paid advertisements directed prospective victims to a ZIP file presented as the software's installer.

Reach crypto's most engaged readers — advertise mid-article on NewsLayer
Sponsored

Reach crypto's most engaged readers — advertise mid-article on NewsLayer

NewsLayer

Ad

The archive contained an executable named Trading Agent.exe and a DLL named iviewers.dll. HP identified the executable as OLEView, Microsoft's legitimate, digitally signed OLE/COM Object Viewer. HP said the signed program helped bypass Microsoft's SmartScreen reputation check, while the malicious payload remained in the accompanying DLL.

Article Intelligence

Topics

aicrypto

Sponsored

Ad
House — Advertise on NewsLayer
NewsLayerLearn more

NewsLayer Premium

Unlock deeper intelligence.

Ad-free reading, exclusive research, and real-time onchain insights.

Go Premium
NewsLayer.com

The front page of the onchain economy. Crypto, Web3 and regulation intelligence — live prices, original research and policy tracking in one layer.

Follow on XTelegram

News

  • Latest News
  • The Daily Brief
  • Crypto
  • DeFi
  • Policy
  • Web3
  • Blockchain
  • Explainers

Markets

  • Market News
  • Layer Index
  • Live Charts
  • DeFi Protocols
  • Regulation Tracker
  • Regulation Radar

Company

  • About NewsLayer
  • Advertise
  • PR Publication
  • Become an Author
  • Our Authors
  • Create Account
  • Sign in

Resources

  • Research
  • NewsLayer Originals
  • My Feed
  • Search
  • AI Sector
  • Quantum Sector

NewsLayer Premium

Read the full layer.

Unlock premium intelligence, original research and an ad-free reading experience.

  • Premium Intelligence briefings
  • Ad-free reading experience
  • Members-only research & data
Go Premium

© 2026 NewsLayer.com — The front page of the onchain economy

Privacy Policy·Terms of Service
NewsLayer

Get the signal, not the noise.

Markets, regulation and onchain intelligence in a 5-minute morning read — plus breaking alerts and Layer Index flips as they happen.

The Daily Brief

Breaking alerts

Index flips

Free · No spam · Unsubscribe anytime