Skip to content
Cybercriminals Use Fake AI Agents to Steal Crypto Wallets

Cybercriminals Use Fake AI Agents to Steal Crypto Wallets

First seen 17 Sep 2026, 10:55 UTC

Article Content

Browse articles
ThreatCluster AI
ThreatCluster September 17, 2026 at 11:26 UTC
  • Fake AI trading agents are being used to distribute malware targeting crypto wallets.
  • Needle Stealer malware replaces legitimate browser extensions to harvest user credentials.
  • QR code phishing tactics are redirecting users to less secure mobile environments.

Cybercriminals are exploiting interest in Agentic AI by creating fake AI trading agents to lure crypto users into downloading malware. This malware, known as Needle Stealer, replaces legitimate browser wallet extensions like MetaMask and Coinbase with malicious versions that capture user credentials. The attacks were identified between April and June 2026, targeting users of seven specific browser wallet extensions. Additionally, QR code phishing tactics are being employed to redirect victims to less secure mobile environments. HP's Threat Insights Report highlights the growing sophistication of these attacks, including the use of a new malware loader called Phantom Gate. The current status indicates ongoing campaigns with significant risk to crypto users. Organizations are urged to remain vigilant and implement security measures to protect against these threats.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-04-01
Needle campaign identified
HP researchers detected the Needle Stealer malware campaign targeting crypto wallet users.
Helpnetsecurity
2026-06-30
Campaign active until end of June
The Needle Stealer campaign was active and targeting users through fake AI trading agents until June 2026.
Helpnetsecurity
2026-09-14
CVE-2026-90894 published
A vulnerability related to the exploitation techniques used in these attacks was published.
HP
2026-09-17
HP Threat Insights Report released
HP released its latest report detailing the methods and impacts of the current cyber threats.
HP

More articles in this cluster (2)

Following this threat?

Track FormBook and CVE-2026-90894 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed