SeaFlower Malware Targets Web3 Wallets to Steal Seed Phrases

SeaFlower Malware Targets Web3 Wallets to Steal Seed Phrases

First seen 28 Feb 2026, 16:11 UTC CybersecuritynewsMexc 26.6

Article Content

Browse articles
ThreatCluster

Cybersecurity researchers have identified a sophisticated malware campaign named SeaFlower, which is targeting users of popular Web3 cryptocurrency wallets. The malware embeds stealthy backdoors in cloned applications to silently steal seed phrases and drain victims' funds, marking it as one of the most advanced threats to Web3 users documented to date.

Timeline

2026-02-26
SeaFlower campaign reported targeting Web3 wallets
2026-02-28
SeaFlower malware identified by cybersecurity researchers