Case · DiggingBeagle record

Fake AI crypto-trading assistant delivered Needle Stealer and replaced browser wallets

HP Wolf Security observed a Q2 2026 campaign in which a website posing as an AI-powered crypto-trading assistant distributed Needle Stealer. The infection chain used a legitimate Microsoft-signed executable to load a malicious DLL, after which the malware targeted seven Chromium cryptocurrency-wallet extensions and attempted to replace matching wallets with malicious versions capable of collecting wallet credentials.

Evidence boundary

Observed Q2 2026 malware campaign reported by HP Wolf Security. The campaign used a fake AI cryptocurrency-trading assistant as a lure and targeted installed Chromium wallet extensions. The Source supports the infection and credential-theft mechanisms but does not provide an aggregate victim count or realized financial-loss total.

Not yet assessed. The record's Claims and Sources remain available; missing grades do not mean low impact.Assessment method

30-second account

Mechanism and trust boundary

Typed chronology

Dates retain their recorded precision. Partially dated events can overlap; display order does not establish a causal sequence.

  1. 2026-04 (month precision)
    occurrence

    Occurrence began

  2. 2026-06 (month precision)
    occurrence end

    Occurrence ended

  3. Sep 17, 2026
    disclosure

    Public disclosure

Claims & evidence

3 independently addressable Claims. Expand a Claim to inspect support, contradiction and scope.

CLM-NEEDLE-AI-TRADING-LUREHP Sure Click detected a Q2 2026 campaign in which tradingclaw[.]pro posed as an AI cryptocurrency trading assistant and used search-engine poisoning and paid advertising to lead victims to a ZIP installer carrying Needle Stealer.supported

Basis: reported finding

Permanent Claim anchor
CLM-NEEDLE-WALLET-PASSWORDThe replacement extension could transmit an entered wallet password to attacker-controlled infrastructure; HP states that entering the wallet identifier and password into the fake extension gives the attacker access to the wallet's funds.supported

Basis: reported finding

Permanent Claim anchor
CLM-NEEDLE-WALLET-REPLACEMENTNeedle Stealer checked installed browser extensions against hardcoded IDs for seven cryptocurrency wallets: Phantom, Trust Wallet, Atomic Wallet, Coinbase Wallet, OKX Wallet, MetaMask and Tonkeeper, and attempted to replace matching extensions with infected versions.supported

Basis: reported finding

Permanent Claim anchor

Implications within the documented scope

Controls and mitigations

No controls or verified fix are recorded.

Unknowns and contradictions

  • The cited HP report does not establish a complete victim count.
  • The report describes capability to capture wallet credentials and thereby obtain access to funds, but it does not provide a defensible aggregate realized-loss figure.
  • The presence of seven targeted wallet-extension IDs describes targeting breadth and does not establish compromise of every listed wallet product or every user of those products.

Sources and citation

Material revision history

  1. Sep 25, 2026 · Published version · first publication · revision 50

Cite this record

DiggingBeagle. “Fake AI crypto-trading assistant delivered Needle Stealer and replaced browser wallets.” Published by DiggingBeagle Sep 25, 2026 · Public disclosure Sep 17, 2026 · Occurrence began 2026-04 (month precision). https://diggingbeagle.com/cases/fake-ai-crypto-trading-assistant-delivered-needle-stealer-and-replaced-browser-w/

Citation guidance

Independent research

The source stays with the story.

Claims, evidence and corrections remain inspectable. About the project · Our methodology