HP Warns Fake AI Trading Agents Are Replacing MetaMask and Coinbase Wallet Extensions
HP Wolf Security said on September 17 that criminals promoted fake AI crypto-trading agents to install malware capable of replacing legitimate browser-wallet extensions with malicious copies.
The campaign used a lure for an always-on trading product and a Windows download presented as a trusted Microsoft-signed program, according to research reported by Help Net Security.
Its targets included established wallet-extension brands such as MetaMask, Coinbase Wallet and Phantom, not just the apparently new trading service. HP said criminals were leaning into interest around agentic AI to steal crypto-wallet credentials.
TradingClaw’s AI trading-agent lure
Between April and June 2026, the campaign was observed by Help Net Security. Its site, tradingclaw[.]pro, advertised an AI trading agent supposedly able to operate around the clock.
The offer led victims to a Windows executable presented as Microsoft-signed, according to the report. That framing was intended to evade SmartScreen reputation checks; the reported signature was part of the delivery chain, not evidence that the download was safe.
The campaign’s wider result was the replacement of legitimate browser-wallet extensions with malicious copies, as described in HP’s September 17 research announcement.
Needle Stealer’s execution chain
Researchers identified the malware as Needle Stealer. According to Help Net Security, after the victim ran the download, it used a Microsoft-signed OLEView executable for DLL side-loading, a technique in which a legitimate executable loads a malicious dynamic-link library in its place. In this chain, the signed program executed the malicious component before the wallet-extension files were replaced.
The malware then sent passwords entered through the counterfeit wallet interfaces to an attacker-controlled server. Help Net Security’s reporting identifies those passwords but provides no figures for affected users, losses or the amount of data obtained.
Replacing the local wallet-extension files could leave a visible interface appearing to belong to a familiar service while collecting information for the operator. The program’s Microsoft signing status could also make the downloaded software appear trusted to users.

Screenshot of the fake TradingClaw website advertising an AI trading agent and a Windows download. — Source: Help Net Security / HP Wolf Security
Seven wallet extensions named
The operation targeted seven browser-wallet extensions: MetaMask, Coinbase Wallet, Phantom, Trust Wallet, OKX Wallet, Atomic Wallet and Tonkeeper. The named set spans wallets associated with different crypto ecosystems, but the common element in the campaign was the browser extension, not a particular blockchain or trading venue.
MetaMask, Coinbase Wallet and Phantom were therefore targets of extension-file replacement in the reported activity, rather than the purported providers of the TradingClaw AI service. The same applies to Trust Wallet, OKX Wallet, Atomic Wallet and Tonkeeper.
HP’s account places the campaign in the April-to-June observation window, with the public disclosure arriving on September 17. It also ties together the two elements that made the operation distinctive: an AI trading-agent lure used to persuade a user to install software, and a post-installation process designed to replace wallet extensions and capture passwords through counterfeit interfaces.
Disclaimer: This article is provided for informational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice.