BlueWallet2026-09-13 00:46:21BlueWallet CTO flags 45 iOS crypto wallets for possible severe security issuesBlueWallet’s chief technology officer said a review of iOS apps labeled as non-custodial crypto wallets identified 45 that may carry severe or high-risk security problems. The screening covered 904 apps, with 494 undergoing analysis. Of the flagged apps, 23 were categorized as potentially severe risk and 22 as high risk. The issues cited include suspected uploading of seed phrases or private keys to servers, insufficient randomness in wallet generation, server-side key storage, the use of hardcoded encryption keys, and loading unsigned JavaScript code capable of interacting with sensitive wallet data. The CTO also cautioned that the findings may include false positives, and that apps not listed should not automatically be considered safe.830
RevStealer2026-09-01 14:10:24Fake Claude Desktop Apps Distribute RevStealer, Targeting 50+ Crypto WalletsFake Claude desktop apps are spreading RevStealer, a Windows malware that steals crypto assets, passwords and browser data while targeting more than 50 cryptocurrency wallets. According to security firm Morphisec, RevStealer previously circulated through GitHub repositories and gaming cheat-themed sites. In this campaign, the malware is disguised as a "Claude Opus 5 Free Desktop" project, impersonating AI developer Anthropic and promising free Claude access. The malware hunts for browser databases, cookies, password manager records, VPN and remote access settings, chat data, screenshots and specific documents. It also checks device memory, processor core count, hostname, username and graphics hardware, and monitors for debug delays typical of malware analysis environments. If it detects an anomaly, it stops the infection flow. If it passes checks, the payload is decrypted, stored under a random name and executed covertly. Separately, Russian security firm Kaspersky earlier found OkoBot, a malware framework aimed at crypto investors that can steal wallet files, browser data and user credentials. Cointelegraph reported the findings.840
Cybersecurity2026-09-01 09:56:45Huntress says hackers are using fake Google Docs and spoofed Claude pages to target crypto usersSecurity firm Huntress said attackers are distributing info-stealing malware to cryptocurrency users through fake Google Docs files, malicious files hosted on GitHub, and spoofed Claude.ai pages. According to the company, the operators impersonated senior CoinDesk staff on X and used invitations to online meetings to trick targets into opening Google Docs documents containing malicious code, then guided them to install malware themselves. Huntress said Mac users face Atomic macOS Stealer, or AMOS, which can steal browser passwords, crypto wallet data, and Telegram files. Windows users are being served a fake Google API Connector update that installs NetSupport RAT and a counterfeit Ledger hardware wallet application. The firm also said attackers bought fake ads on search engines including Bing to steer users to imitation Claude.ai pages where they were prompted to run malicious commands. In that part of the campaign, malware families MacSync and SectopRAT were used to steal cookies, saved passwords, seed phrases, and payment card data. Separately, security company Socket said it found 16 malicious extensions targeting Chrome and Edge that can drain wallets on EVM, Solana, and Tron.890
SlowMist2026-08-28 12:42:53SlowMist flags fake Qwen model GitHub repo tied to Polygon-based C2 fallbackSlowMist has disclosed a malicious GitHub repository posing as a local quantized version of the “Qwen 3.8 27B” model. The security team said the repo claimed the model file should be larger than 16GB, but the actual download was only about 487KB and contained disguised files, a LuaJIT interpreter, and obfuscated Lua scripts. SlowMist added that the official Qwen project itself was not compromised. According to SlowMist’s analysis, the malware collects host information, captures screenshots, and sends the data to an attacker-controlled command-and-control server after execution. If the hardcoded server becomes unavailable, the program can read a backup C2 address from a smart contract on Polygon, allowing the operator to rotate infrastructure through on-chain transactions. SlowMist also said follow-on payloads can steal browser logins, cookies, browsing history, email data, WinSCP and Steam credentials, as well as crypto wallet-related files and extension data. The team found that at least 23 GitHub repositories and 29 similar compressed packages used the same Lua-based delivery chain.830
Bank of Russi2026-08-28 03:40:44Bank of Russia adds 2,600 crypto wallet addresses to illicit activity databaseThe Bank of Russia has added 2,600 cryptocurrency wallet addresses suspected of involvement in illegal activity to a dedicated information system, according to Bits.media as cited by ChainCatcher. The addresses are linked to legal entities, project teams and individual entrepreneurs, and have collectively received about 1 billion rubles in crypto assets. The system is already open to government agencies and law enforcement bodies. The central bank said that if a banking transaction is found to be connected to any of the listed addresses, that transaction is highly likely to be frozen. It also said 74% of the flagged addresses are tied to financial pyramid schemes and fraud. Reported schemes include fake crypto investment offers, fabricated data center projects and illegal crypto lending involving the USDT stablecoin.820
Firefox2026-08-25 14:17:21Socket links 40 malicious Firefox wallet extensions to campaign stealing seed phrasesSecurity firm Socket said it found a cluster of malicious cryptocurrency wallet extensions targeting Firefox users and tied them to an operation it calls "Offside Wallet Theft Factory." The company linked 77 extension identities to the campaign, with 40 confirmed as malicious, and said the activity ran for at least from March to August 2026. The extensions mainly impersonated well-known Web3 wallets including OKX, Rabby Wallet and TronLink, using highly convincing wallet interfaces to trick users into importing existing wallets and handing over seed phrases or private keys. Socket said roughly half of the malicious extensions directly prompted users to enter seed phrases. Another 13 were tampered Rabby builds that sent wallet account data to external servers when users saved account information, while five collected stored credentials and clipboard contents. Socket also found that at least nine of the malicious extensions had previously operated as sports score apps covering football, basketball and the NBA, building up users and reviews before later switching to wallet-stealing code through updates. It warned that anyone who entered a seed phrase or private key into the affected extensions should treat those credentials as permanently compromised and move funds to a brand-new wallet immediately.1070
Firefox2026-08-25 14:10:05Socket Links 77 Firefox Extensions to Crypto Theft Campaign, With 40 Confirmed MaliciousSocket’s threat research team said it linked 77 Firefox extension identities through shared code, infrastructure, and publishing patterns, and confirmed 40 of them as malicious. According to the company, the extensions impersonated crypto wallet and Web3 brands including OKX, Rabby Wallet, and TronLink, with many designed to trick users into importing an existing wallet and entering a recovery phrase or private key. Mozilla signing records placed the campaign between March 9 and August 3, and Socket said several of the extensions were still live when it reported them. The researchers also found that 37 other extension identities were presented as unrelated utilities but actually displayed live sports scores. In nine confirmed cases, football, basketball, NBA, or American football score apps were later updated into wallet-stealing malware, allowing the operators to retain the install base and review history built by the original apps. Socket named the pattern the “Offside Wallet Theft Factory,” while saying it has not established that every extension was run by a single operator. The firm warned that users who entered a recovery phrase or private key into any of the affected extensions should treat those credentials as permanently compromised and move funds to a new wallet.500
Check Point R2026-08-20 16:38:52Check Point says StopAndProtect used nearly 2,000 hacked WordPress sites to spread malwareCheck Point Research said the StopAndProtect ransomware operation used nearly 2,000 compromised WordPress websites to distribute malware, steal data, monitor victims and deploy ransomware. The campaign was discovered in mid-May and had compromised more than 6,000 unique IP addresses as of July 24, according to the researchers. The United States accounted for 1,852 of those IPs, while Russia and India each had 630. The report said the hacked websites were also used to host malware, send commands, and store stolen files, screenshots and activity logs. Researchers said the attackers relied on fake CAPTCHA prompts to trick Windows users into running PowerShell commands. That process was used to steal credentials and cryptocurrency wallet seed phrases, and the malware was able to spread through networks and USB devices. Check Point Research said it collected more than 31,000 screenshots and over 700 compressed data archives during its investigation. The researchers also said the attackers may have accidentally infected themselves.1230