Huntress says fake Google Docs and Claude pages target crypto wallet data

  • Huntress identified fake Google Docs and Claude.ai pages targeting crypto wallet data.
  • Attackers sought seed phrases, private keys, passwords and browser-extension wallet access.
  • The wider campaign included 16 malicious extensions affecting EVM, Solana and Tron wallets.

Attackers built counterfeit Google Docs and Anthropic Claude.ai pages to lure victims into a phishing campaign targeting crypto wallet data, according to security firm Huntress. The operation exploited familiarity with mainstream productivity and artificial-intelligence tools rather than relying only on conventional account theft. The reported objective was to obtain high-value wallet access material, including seed phrases, private keys, wallet passwords or browser-extension access, which can give attackers irreversible control of funds. The wider activity previously described also involved malicious GitHub files, fake Claude.ai websites promoted through Bing advertisements, impersonation of CoinDesk employees on X and malware targeting Mac and Windows users. Researchers identified Atomic macOS Stealer, NetSupport RAT, a fake Ledger application, MacSync and SectopRAT, as well as 16 malicious Chrome and Edge extensions affecting EVM, Solana and Tron wallets. Huntress found no evidence that Google or Anthropic themselves were breached; the pages were impersonations. Users should verify domains manually, avoid entering recovery phrases online and isolate valuable assets in dedicated wallets or devices.

The information on this website is generated using AI and we cannot guarantee its accuracy. Please use it as reference information only.