Cybercriminals promoted tradingclaw[.]pro as a fake AI crypto-trading assistant that delivered Needle Stealer, malware targeting seven Chromium browser wallet extensions: Phantom, Trust Wallet, Atomic Wallet, Coinbase Wallet, OKX Wallet, MetaMask and Tonkeeper. HP Wolf Security documented the campaign in its September 2026 threat report, published Sept. 17 and based on threats observed from April through June 2026; CryptoSlate reported the findings on Sept. 18. Search-engine poisoning and paid advertisements led victims to a ZIP archive containing a Microsoft-signed OLE/COM Object Viewer executable and a malicious DLL. Running the trusted-looking program loaded the DLL, which decrypted Needle Stealer and used process hollowing to operate inside a legitimate process. The malware replaced targeted wallet extensions with counterfeit copies that could collect wallet IDs, passwords entered into fake login screens and seed data, while connecting to attacker-controlled infrastructure. HP said abrupt browser restarts and renewed wallet-login prompts can indicate the extension-replacement technique. Its report also described QR-code phishing embedded in PDF invoices, which can shift targets from protected work computers to mobile devices. HP linked the broader threat landscape to Phantom Stealer, a commercially offered Malware-as-a-Service information stealer designed to collect browser data. The operation began with endpoint compromise rather than a breach of Coinbase, MetaMask or their official extensions, and HP did not disclose a campaign-wide victim count or aggregate crypto-loss figure. Users who installed an unfamiliar AI trading tool should treat wallets on that device as potentially compromised, move funds from a clean device, revoke token approvals and reinstall extensions only from verified sources.