HP warns cybercriminals push fake agentic AI trading bots to hijack crypto wallet extensions
HPQ•HP flags fake agentic AI trading tools
HP flagged a rise in crypto wallet theft tied to fake agentic AI trading tools that push malware disguised as legitimate software.
How the malware works and other threat trends
- Malware swaps trusted wallet browser extensions for lookalikes, capturing credentials to enable direct theft of crypto holdings.
- QR-code phishing persisted, shifting victims from PCs to less-protected mobile devices via PDFs that prompt scans to reach credential-harvesting sites.
- Phantom Gate emerged as a new loader linked to Phantom Stealer, lowering barriers to assemble scalable infection chains.
- April–June 2026 data showed 10% of email threats bypassed at least one gateway scanner; executables led delivery at 40%.




