Attackers built counterfeit Google Docs and Anthropic Claude.ai pages to lure victims into a phishing campaign targeting crypto wallet data, according to security firm Huntress. The operation exploited familiarity with mainstream productivity and artificial-intelligence tools rather than relying only on conventional account theft. The reported objective was to obtain high-value wallet access material, including seed phrases, private keys, wallet passwords or browser-extension access, which can give attackers irreversible control of funds. The wider activity previously described also involved malicious GitHub files, fake Claude.ai websites promoted through Bing advertisements, impersonation of CoinDesk employees on X and malware targeting Mac and Windows users. Researchers identified Atomic macOS Stealer, NetSupport RAT, a fake Ledger application, MacSync and SectopRAT, as well as 16 malicious Chrome and Edge extensions affecting EVM, Solana and Tron wallets. Huntress found no evidence that Google or Anthropic themselves were breached; the pages were impersonations. Users should verify domains manually, avoid entering recovery phrases online and isolate valuable assets in dedicated wallets or devices.