HP's security team just flagged an attack specifically targeting crypto users.
Here's how it works:
🔴 Malware disguised as an "AI Crypto Trading Agent" spreads through search results and ads.
🔴 Once installed, it scans your Chromium browser for wallet extensions (MetaMask, OKX Wallet, Phantom, and others).
🔴 When it finds one, it kills the browser process, swaps in a fake extension, and replaces the real one.
When you reopen your browser, everything looks normal.
But the moment you enter your password to unlock your wallet, it goes straight to the attacker, along with your local wallet data.
That's enough for a full takeover.
A few things worth doing:
🔵 Don't download AI agents or trading bots from random search results. If you use a specific tool, get it directly from the official site.
🔵 Keep a separate browser profile for anything crypto-related.
🔵 Store large holdings in a hardware wallet. Even if your hot wallet gets compromised, your funds stay safe.
HP says a fake AI crypto-trading tool delivered malware that replaced browser wallet extensions with credential-stealing copies.
The campaign targeted wallets including MetaMask, Phantom, Coinbase Wallet, Trust Wallet and OKX Wallet after users ran the counterfeit software.