SlowMist said a macOS information-stealing trojan is capable of taking over Telegram (TG) sessions and extracting wallet-related data, while also replacing hardware wallet client software to carry out what it described as a double asset-theft attack. The item points to a compromise flow in which a TG account is lost and a wallet setup is swapped out on the victim’s device. The report was published on July 15, 2026, and appeared via Foresight under the homepage headline category. No additional technical breakdown, affected wallet brands, loss figures, or attack attribution were provided in the supplied source text.
SlowMist said a macOS information-stealing trojan can steal Telegram (TG) session data and wallet data. It can also replace hardware wallet client software, enabling what the firm described as a double asset-theft attack.
The supplied item frames the threat around two outcomes: loss of control over a TG account and a wallet client being swapped on the user’s device. The text does not provide extra technical details beyond that description.
The item was published on July 15, 2026, via Foresight.
This article was originally published by Bit.Fan. For more cryptocurrency news and market insights, visit www.bit.fan. Disclaimer:
The market information, project data, and third-party content displayed on this platform are for industry information sharing only and do not constitute any form of investment advice or return commitment.
Cryptocurrency trading carries high risks. Users should fully assess their risk tolerance and make independent decisions. All profits, losses, and legal responsibilities are borne by the users themselves.