Skip to content
SeaFlower Malware Targets Web3 Wallets to Steal Seed Phrases

SeaFlower Malware Targets Web3 Wallets to Steal Seed Phrases

First seen 28 Feb 2026, 16:11 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

Cybersecurity researchers have identified a sophisticated malware campaign named SeaFlower, which is targeting users of popular Web3 cryptocurrency wallets. The malware embeds stealthy backdoors in cloned applications to silently steal seed phrases and drain victims' funds, marking it as one of the most advanced threats to Web3 users documented to date.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

Timeline

2026-02-26
SeaFlower campaign reported targeting Web3 wallets
2026-02-28
SeaFlower malware identified by cybersecurity researchers

More articles in this cluster (2)

Following this threat?

Track SeaFlower in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed