XRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · GreedXRP $3.12 ▲ 4.8% BTC $114,820 ▲ 1.2% ETH $4,380 ▼ 0.6% RLUSD $1.00 ▲ 0.0% XLM $0.41 ▲ 3.1% Fear & Greed 68 · Greed
Home / Markets
● Markets

Counterfeit Claude App Distributes Wallet-Draining Malware to Crypto Users

Security researchers have uncovered a malware campaign using a fraudulent Claude desktop application to compromise cryptocurrency holders, stealing credentials from over 50 digital wallets alongside passwords and banking data.

JM
by Jacob Marquez · Markets Desk
Published September 1, 2026 · 3 min read

Fake AI App Serves as Malware Vector

Cybersecurity firm Morphisec has identified a sophisticated attack campaign that exploits user trust in established technology brands. Attackers created a counterfeit “Claude Opus 5 Free Desktop” application purporting to be from Anthropic, the company behind the legitimate Claude AI assistant, and marketed it as providing complimentary access to premium features. The fake application actually delivers RevStealer, a Windows malware engineered to compromise cryptocurrency wallets and extract sensitive user data. This tactic builds on earlier RevStealer distribution methods, which previously operated through GitHub repositories and gaming-themed cheat websites, but the Claude impersonation represents a more targeted approach toward cryptocurrency users.

Sophisticated Detection Evasion and Data Harvesting

According to Morphisec’s analysis, RevStealer incorporates advanced anti-analysis capabilities designed to evade security researchers and malware analysis environments. The malware first inspects the infected system’s specifications—including available memory, processor core count, hostname configuration, username, and graphics processor details—to determine whether the device appears to be a legitimate user computer or a sandboxed research environment. The malware also specifically watches for debugging delays commonly introduced during professional malware examination. Should the system fail these validation checks, RevStealer discontinues execution rather than proceeding with its payload.

Machines that pass inspection experience full RevStealer activation. The malware decrypts its core payload, assigns it an arbitrary filename, and launches it without user awareness. Once operational, RevStealer systematically harvests browser authentication data, cached cookies, password manager entries, VPN credentials, remote-access configurations, messaging application data, screenshots, and various document files. Critically, the malware is programmed to target more than 50 distinct cryptocurrency wallet applications, placing significant assets at risk for infected users.

Broadening Threat Campaign Against Digital Asset Holders

The RevStealer campaign reflects a wider pattern of specialized malware development targeting the cryptocurrency sector. Kaspersky, a Russian cybersecurity research firm, recently documented OkoBot, a malware framework specifically designed to victimize cryptocurrency investors. OkoBot employs multiple attack strategies: it retrieves wallet files from storage, collects browser-stored data and user login credentials, deploys rogue browser extensions to intercept transactions, and captures window screenshots of active wallet applications to identify theft opportunities. The emergence of multiple sophisticated, wallet-focused malware variants demonstrates that cybercriminals are investing substantial resources into compromising digital asset holders.

For cryptocurrency users, these discoveries reinforce essential security principles. Downloading software exclusively from official vendor websites, maintaining multi-factor authentication on all accounts holding digital assets, and storing substantial crypto holdings in offline cold storage remain critical protective measures. The misuse of established brand names—like Anthropic’s Claude—highlights how attackers weaponize user familiarity and trust to achieve initial system compromise.

Rising malware sophistication targeting crypto wallets underscores the security challenges facing the broader digital asset ecosystem and the need for heightened user vigilance across all sectors.

Source: Morphisec and Kaspersky, via Cointelegraph. Not financial advice.

// DISCLAIMER: This article is for informational purposes only and is not financial, investment, or trading advice. Terminalcraft may earn a commission from affiliate links. Crypto is volatile and high-risk. Always do your own research.
JM

Jacob Marquez — Markets Desk

Jacob Marquez is the founder and editor of Terminalcraft, an independent XRP-first crypto news desk. An XRP holder and market watcher since 2016, he started Terminalcraft to deliver fast, factual crypto news without the hype.