Bible Network Crypto DeFi Onchain RWA AI Agent Stablecoin CryptoTax DeFAI Chain SAFU AGI Claude Me Claude Skill Claude Design Claude Cowork
Independent Media
Not affiliated with any project
DeFi × AI Convergence: Strategies, Projects & Risks, Decoded
defai-bible.com
LATEST
DeFAI Agents Now Drive Nearly a Fifth of On-Chain Activity — But Lose to Humans 5-to-1 at Open-Ended Trading. Here's Why  ·  An Ad Promising a "24/7 Trading" AI Agent Was Actually Malware That Swapped Out Your Wallet Extension  ·  Morpho's Two-Layer Design: What Vault Curators Like Gauntlet and Steakhouse Can — and Can't — Protect You From  ·  Your DeFAI Agent Has Memory Now — That Also Means It Has a New Attack Surface: Memory Poisoning  ·  31 Flaws, 15 for 15: What the First Systematic Security Study of x402 Payment Infrastructure Found  ·  DCENT App Wallet Breach: What a Two-Hour, 1,552-Wallet Automated Drain Reveals About Software Wallet Risk
news

An Ad Promising a "24/7 Trading" AI Agent Was Actually Malware That Swapped Out Your Wallet Extension

30-Second Version · For the impatient
It didn't fool your wallet — it fooled your eyes. The interface looked identical; your password had already gone somewhere else.

Full Explanation +
01 · Why did this happen?

How is this attack fundamentally different from a typical phishing site that tricks people into entering their password?

A typical phishing site usually fakes a login page and lures users into voluntarily entering credentials there. This attack goes a step further: it directly replaces the "real" wallet extension already installed in the browser, so the user enters their password inside the exact extension interface they already trust and use every day — not by visiting some suspicious new site, but by clicking the icon that's always been sitting in their own browser. That means the usual vigilance of "check the URL bar, verify it's the official site" is completely useless here, because the user never left their own browser environment at all.

02 · What is the mechanism?

Why would attackers go through the trouble of using a legitimate, Microsoft-signed tool (OLEView.exe) to load a malicious DLL, instead of just building a straightforward malicious executable?

A brand-new malicious executable is easy for antivirus software or Windows SmartScreen to flag, using digital signature checks and reputation scoring — an unsigned or unfamiliar-source executable defaults to being marked suspicious. But if what's launched is OLEView.exe, an officially Microsoft-signed and entirely legitimate tool, what the system sees is "a trusted Microsoft utility is running," which substantially lowers the bar of scrutiny protective mechanisms apply. The actual malicious logic hides in the seemingly harmless DLL file sitting alongside it, only executing once the legitimate program loads it. The entire point of this technique is to borrow someone else's credibility as cover.

03 · How does it affect me?

If I've already installed one of these swapped-out fake wallet extensions, is there actually a way to notice it myself?

Since the interface is built to look identical to the original, spotting it by eye alone is nearly impossible. A more practical check is to go into your browser's extension management page and verify each wallet extension's developer information, install source, and extension ID match what's officially published (official wallet sites typically list the correct store link and ID). Also check whether the extension was installed through the browser's official store (like the Chrome Web Store) rather than via a manually installed setup file — a legitimate wallet extension should never require a user to manually install a DLL or executable. Beyond that, if your machine has ever run an unfamiliar "trading software," the safer assumption is that your browser environment has already been tampered with: remove all wallet extensions and reinstall from the official store, and change every wallet password and move funds tied to any Seed Phrase that may have been exposed.

04 · What should I do?

What's the practical takeaway from this incident for a DeFAI user currently evaluating whether to use an "AI trading agent" product?

This specific incident targeted a fake AI trading tool, not a real, on-chain-verifiable DeFAI product — but it highlights a screening principle worth remembering: any product that requires you to first download a desktop executable before you can use its "AI trading" feature carries the same category of risk as any other desktop software, which hinges entirely on whether that executable has been tampered with — a completely different question from whether the underlying AI technology itself is safe. A genuine DeFAI product with on-chain-verifiable execution records typically doesn't require you to install any desktop program, nor does it ask you to hand your wallet's Seed Phrase to any third-party software. Recognizing that distinction is the most direct way to avoid this entire category of attack.

Full Content +

In a threat intelligence report published September 17, 2026, HP Wolf Security documented a malware campaign targeting cryptocurrency users, disguised as an "AI trading agent" — with the observed attack window spanning April through June 2026. The campaign didn't rely on any exotic blockchain vulnerability; it relied purely on how appealing the phrase "AI Agent" sounds, paired with a fairly deliberate set of Windows evasion techniques.

The Bait: "It Trades for You Around the Clock"

The attackers stood up a fake site, tradingclaw[.]pro, packaged as AI trading software that would "trade crypto around the clock," promoted through search-engine poisoning (pushing the malicious site higher in search results) and paid advertisements. What users downloaded was a ZIP archive containing Trading Agent.exe and a DLL file, iviewers.dll.

The Technique Worth Noting: Bypassing Windows Protections

What makes this campaign worth understanding is how it evaded Windows' built-in protections. The program abused OLEView.exe — Microsoft's own, legitimately signed OLE/COM Object Viewer tool — to load the malicious DLL sitting next to it. This technique, DLL side-loading, works because the launching executable itself carries a legitimate Microsoft signature, which is enough to sidestep Windows SmartScreen's warning mechanism. From there, process hollowing — hollowing out a legitimate process and injecting malicious code to run inside it — was used to actually execute a credential stealer called Needle Stealer.

Seven Mainstream Wallet Extensions Targeted

Needle Stealer enumerates installed browser extensions (identifying wallets by their fixed 32-character extension IDs), targeting seven: MetaMask, Coinbase Wallet, Phantom, Trust Wallet, Atomic Wallet, OKX Wallet, and Tonkeeper. Once one of these was detected, the malware replaced it with a visually identical fake version that forwarded whatever password the user entered straight to the attacker's command server. This differs from simple keylogging — the interface the user sees looks completely normal, and the moment a password is typed in, the data has already been sent to the attacker.

Not an Isolated Event — a Continuation of the Same Playbook

HP's report also noted a connection between this tradingclaw campaign and the TradingClaw attack chain documented earlier by security firm Malwarebytes in April, indicating this is an ongoing, iterating operation run by the same group rather than a single isolated incident. The report also noted that during the same window, the attackers deployed QR-code phishing (directing victims to scan a code via a fake PDF invoice) and HTML smuggling to drop other credential-stealing malware — meaning the "disguised as an AI tool" angle was just one of several lures this group ran, while the intent to target crypto wallets stayed consistent.

Sources: HP Says Fake AI Trading Bot Swapped Crypto Wallet Extensions for Credential-Stealing Copies (CryptoSlate), HP Warns Fake AI Trading Agents Are Replacing MetaMask and Coinbase Wallet Extensions (CoinDesk), HP Wolf Security: Phantom Gate, Needle Stealer and Quishing (Cyber Magazine)
Ask a Question
Please enter at least 10 characters
Related Articles
DeFAI Agents Now Drive Nearly a Fifth of On-Chain Activity — But Lose to Humans 5-to-1 at Open-Ended Trading. Here's Why
strategies · Oct 02
Morpho's Two-Layer Design: What Vault Curators Like Gauntlet and Steakhouse Can — and Can't — Protect You From
project-anatomy · Sep 28
Your DeFAI Agent Has Memory Now — That Also Means It Has a New Attack Surface: Memory Poisoning
risk · Sep 28
Your DeFAI Agent's Speed Is Exactly What Makes It an MEV Target — Understanding AI-on-AI Extraction
strategies · Sep 05
Related News
More Related Topics