Fake AI Trading Bot Steals Crypto Wallet Passwords

Help Net Security · High sophistication
Last updated September 17, 2026

Researchers observed real campaigns where a fake “AI crypto trading agent” website tricked victims into downloading malware that silently replaces browser wallet extensions and steals the wallet password when it’s typed. The same reporting also describes invoice emails using QR codes to push victims onto their phones and then onto a fake OneDrive-style login page to steal Microsoft credentials.

Key findings

  • HP observed the campaign activity “between April and June 2026.”
  • A fake AI trading-agent site (“tradingclaw[.]pro”) delivered a ZIP whose executable appears legitimate (Microsoft-signed) to bypass trust checks, then installs a stealer.
  • The malware targets users of “seven browser wallet extensions, among them MetaMask, Coinbase Wallet and Phantom.”
  • The stealer replaces the victim’s wallet extension with a malicious copy that “sends the wallet password to the attacker.”
  • Separate campaigns used invoice PDFs with a QR code (“quishing”) to move victims to a phone, then through redirects to a page “resembling OneDrive” that requests Microsoft credentials.
  • The QR workflow leverages a “fake email security scanner” and a “Cloudflare Turnstile check” before credential theft.
  • HP also describes multiple loader delivery methods (HTML smuggling, search lookalike domains, steganography in images) associated with stealing credentials and system data.

Who’s being targeted

  • Commonly targeted roles: Finance / Accounts Payable, All employees (anti-phishing training), Employees using Microsoft 365, Users who manage cryptocurrency wallets, IT/Security helpdesk (to reinforce ‘verify before install/scan’ guidance).
  • Affected industries: Cryptocurrency/consumer finance, Any business receiving invoice emails (accounts payable/finance), General corporate Microsoft 365 users.
  • Attack channels: website, email, smishing.
  • Impersonated: A legitimate-sounding AI assistant / trading bot vendor, Invoice sender / accounts receivable, then a Microsoft/OneDrive-style sign-in page.

Awareness takeaways

  • Treat ‘AI tool/agent’ downloads from search results or ads as untrusted; only install from verified sources and approved app stores/portals.
  • A familiar-looking wallet unlock screen (or branded login page) is not proof it’s legitimate, verify extensions and login URLs before entering passwords.
  • Be suspicious of invoices that require scanning a QR code to view details; use known vendor contact paths and view invoices via established systems.
  • Remember that phones often have fewer protections than work PCs; don’t assume a link is safe just because it opens on mobile.

Red flags to watch for

  • Unknown domain offering a ‘too-good-to-be-true’ trading bot download
  • Installer distributed as a ZIP with an unexpected executable
  • Pressure to run software obtained from search results/ads without verification
  • Invoice content is blurred and requires scanning a QR code to view
  • QR scan leads through multiple redirects and ‘security checks’ before showing the document
  • Credential request appears after QR scan on a mobile browser (harder to validate URLs)
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Imagine installing an ‘AI crypto trading agent’… and it quietly steals your MetaMask or Coinbase Wallet password. HP saw this between April and June 2026: tradingclaw[.]pro gives you a ZIP. Inside, “Trading Agent.exe” looks Microsoft‑signed, but installs malware that swaps your wallet extension and sends your unlock password out the moment you type it. Same play with invoices: a PDF shows a blurred bill and a QR code. You scan it, bounce through a fake email security scanner and a Cloudflare Turnstile check, then land on a OneDrive‑lookalike page that quietly steals your Microsoft login. Here’s the move: if a site or invoice pushes you to install an ‘AI agent’ or scan a QR to log in, stop and go through our approved app store or vendor portal instead, never from ads, random sites, or QR codes.

Similar attacks

Lazarus Lures Staff With Fake Jobs to Drop Malware

Lazarus Lures Staff With Fake Jobs to Drop Malware

Researchers tied North Korea’s Lazarus Group to a real-world campaign that approaches professionals with convincing fake recruiter outreach and job offers. Victims are tricked into opening a malicious PDF or installing a fake PDF viewer from lookalike websites, which then installs backdoors and can…

August 12, 2026
M365 “Direct Send” Abused for Internal-Looking Phish

M365 “Direct Send” Abused for Internal-Looking Phish

Researchers observed a real phishing campaign that abused Microsoft 365’s Direct Send feature to make emails look like they came from the victim organization’s own domain, without compromising an employee account. The campaign was timed to mimic human sending patterns during U.S. Eastern business…

September 14, 2026
Phishing PDF Drops Malware Via Fake Edge Loader

Phishing PDF Drops Malware Via Fake Edge Loader

Researchers describe BraZetsu, a Windows malware framework used by an initial-access broker to turn infected PCs into "access for sale" on a criminal marketplace. While the malware itself is technical, the article includes real-world delivery details pointing to phishing: victims are tricked into…

September 3, 2026
Fake Recruiters & Cloud Email Fuel New Phishing

Fake Recruiters & Cloud Email Fuel New Phishing

This roundup describes real-world social engineering where attackers impersonate recruiters on LinkedIn and lure developers into running “coding tests” that install malware. It also outlines active phishing campaigns that abuse trusted cloud services (Google, AWS, Azure, Cloudflare) to send…

September 2, 2026
Job Offer & Doc-Link Phishing Drive Real Breaches

Job Offer & Doc-Link Phishing Drive Real Breaches

This weekly threat bulletin describes real incidents where attackers used human manipulation to break in, including social engineering at Levi Strauss and a Microsoft 365 credential-theft phish at defense supplier IEH. It also highlights a Lazarus-linked campaign using fake job offers and…

August 17, 2026
Fake IT Calls Push AnyDesk in Brazil Heists

Fake IT Calls Push AnyDesk in Brazil Heists

Mandiant and Google report that the financially motivated group BREEZE COMET compromised Brazilian organizations to enable fraudulent bank transfers. The actor used human manipulation (including fake IT support calls) and believable “tax/receipt” downloads hosted on trusted-looking government…

September 1, 2026