The June 17 Security Blog report says the malware has been active since February 2026, using clipboard theft, seed phrase extraction and Tor-routed command traffic to compromise self-custody workflows.
verifying reliability
No specialized terms available for this topic.