HP warns fake AI crypto tools are swapping wallet extensions for credential traps
HP Wolf Security says malware disguised as an AI trading assistant replaced browser wallets with malicious lookalikes, turning familiar install flows into a theft vector.
By The Third AnglePublished 4 min read
Security researchers say fake AI trading software can replace trusted wallet extensions on infected computers. Photo: Markus Spiske / Unsplash · Unsplash License
The lure is an AI trading assistant
HP Wolf Security says attackers used fake AI crypto-trading software to deliver malware that replaced legitimate browser wallet extensions with malicious copies. HP’s September threat report describes a campaign in which users were lured by an agentic-AI trading narrative, then received a Windows payload that could target wallet software installed in Chrome and other browsers.HP Wolf Security report
CryptoSlate reviewed the same report and said the malware, identified as Needle Stealer, could swap extensions associated with Coinbase Wallet, MetaMask and Phantom. AMBCrypto independently described the campaign as a credential-theft operation in which the malicious extension sent passwords to an attacker-controlled server. The reporting does not show a breach of those wallet companies’ core infrastructure.Independent coverage
The key risk is familiar branding. A wallet can look normal yet be compromised. Users may type credentials or approve a transaction while believing they are interacting with software they installed previously.
How the replacement attack works
HP says the infection begins with software that appears to be an AI-powered trading tool. Once running, the malware searches for browser wallet extensions and replaces their files with modified versions. The goal is to intercept passwords, recovery information or transaction activity when a user opens the familiar wallet interface.
This is a supply-chain and endpoint problem rather than a failure of a single blockchain. The attacker does not need to break a wallet’s cryptography if the victim supplies a password to a counterfeit extension or signs a malicious request from a hijacked interface. The compromise can also affect multiple assets because the browser is the common access layer.
HP’s findings are based on threats observed from April through June 2026 and published in its September report. That timing matters: the report documents a campaign, but it does not establish how many crypto users were affected or whether every identified wallet extension was successfully replaced.
Practical checks for wallet users
Users should treat unsolicited AI trading tools, cracked software and download links shared in chats as high-risk. Check browser extension names, publishers, install dates and permission scopes; remove anything unexpected; and reinstall wallet software only from the verified vendor page or official extension store listing.
If a device may be infected, do not enter another wallet password into that browser. Move assets from a clean device, rotate credentials and review recent approvals and transactions. Hardware wallets reduce some private-key exposure, but they do not make a compromised browser harmless: a user can still sign a deceptive transaction.
The broader lesson is that AI branding is becoming a social-engineering shortcut. Convenience is not an authenticity check. This is security reporting, not personalized financial advice.