• About Us
  • Advertise
AltcoinReporter
  • Home
  • News
    • Bitcoin
    • Ethereum
    • Blockchain
    • Altcoins
    • DeFi
    • NFT
  • Press Releases
  • Reviews
    • Exchanges
    • NFT Marketplaces
    • Wallets
  • Market Analysis
  • Contact Us
No Result
View All Result
  • Home
  • News
    • Bitcoin
    • Ethereum
    • Blockchain
    • Altcoins
    • DeFi
    • NFT
  • Press Releases
  • Reviews
    • Exchanges
    • NFT Marketplaces
    • Wallets
  • Market Analysis
  • Contact Us
No Result
View All Result
AltcoinReporter
No Result
View All Result
Home Blockchain

Fake Claude Code Site Steals Crypto Wallets via Google Search Hack

Hackers used SEO poisoning to push a fake Claude Code install page to the top of Google, stealing crypto wallets from 250+ browser extensions. Bybit exposed it.

Salar Salek by Salar Salek
April 24, 2026
in Blockchain
Fake Claude Code Site Steals Crypto Wallets via Google Search Hack

If you searched Google for “Claude Code” in March and clicked the top result, you might have installed malware instead of Anthropic’s AI coding tool. That is not a hypothetical. It happened.

Bybit’s security team uncovered a malware campaign that used SEO poisoning to push a fake Claude Code installation page to the top of Google search results. macOS users who clicked the link downloaded what looked like a normal installer. Instead, it deployed a two-stage attack chain that stole browser credentials, macOS Keychain entries, Telegram sessions, VPN profiles, and cryptocurrency wallet data from over 250 browser extensions.

Related articles

Moody’s Just Launched Onchain Credit Ratings on Solana

Moody’s Just Launched Onchain Credit Ratings on Solana

June 18, 2026
The Quantum Computing Race Just Started: XRP Ledger, Bitcoin, and Ethereum All Move on Same Day

The Quantum Computing Race Just Started: XRP Ledger, Bitcoin, and Ethereum All Move on Same Day

June 15, 2026

The campaign was first spotted on March 12, 2026. The fake site looked almost identical to Anthropic’s real documentation. Most people would not have noticed the difference.

How Does the Claude Code Crypto Malware Work?

The attack was built in two stages. Both were designed to be invisible.

Stage one: when a user downloaded the fake installer, it dropped a Mach-O binary onto their Mac. That binary deployed a script-based info stealer that Bybit’s researchers said shows similarities to AMOS and Banshee, two well-known malware families that have been targeting Apple users since 2023. The stealer ran through a multi-phase process to dig through the system and grab everything it could find.

Stage two: it went after crypto specifically. The malware scanned for over 250 browser-based wallet extensions, the kind that millions of crypto users have installed in Chrome, Brave, and Firefox. It also targeted desktop wallet apps. In some cases, it tried to replace legitimate copies of Ledger Live and Trezor Suite with trojanised versions. So even if you checked your apps afterwards, they would look normal but would be quietly sending your data to the attacker.

The malware also used a clever social engineering trick. It popped up a fake macOS password prompt that looked exactly like the real system dialog. If you typed your password, it was captured and used to unlock your Keychain, which stores all your saved passwords, authentication tokens, and encryption keys. One password, and the attacker had everything.

Why Did Hackers Target Claude Code Users?

Claude Code is Anthropic’s command-line AI coding tool. It has become one of the most popular developer tools in 2026, used by software engineers, crypto developers, and AI researchers to write and debug code directly from their terminal.

That popularity is exactly what made it a target. CryptoTimes reported that developers are “high-value victims” because they typically have direct access to codebases, cloud infrastructure, signing keys, and personal crypto wallets on the same machine. A single compromised developer laptop can cascade into source code theft, CI/CD pipeline access, and in the worst cases, the kind of multisig signing exploits that enabled the $1.4 billion Bybit hack in February 2025 and the $285 million Drift Protocol exploit this month.

Microsoft’s Defender Experts team confirmed in February 2026 that macOS-targeted infostealer campaigns are increasingly using fake AI tool installers as delivery vehicles. Claude Code was not the first AI tool to be spoofed this way, and it will not be the last.

How Did Bybit Catch It?

This is where the story gets interesting. Bybit used AI to catch an AI-era attack.

The exchange’s Security Operations Center runs what it calls an “AI-assisted SOC” that can move from detection to full kill chain analysis in a single operational session. David Zong, Bybit’s Head of Group Risk Control and Security, said the entire process of decompiling the malware, extracting indicators, drafting the threat report, and writing detection rules was completed in one session. Work that used to take a team of analysts across multiple shifts was done in hours.

Bybit identified the malicious infrastructure on March 12, completed its analysis the same day, and published public detection guidance on March 20. The speed matters. Every day a fake installer sits at the top of Google is another day that developers are getting compromised.

Zong was blunt about what this means for the future: “We will face an AI war. Using AI to defend against AI is an inevitable trend.”

How to Protect Yourself From Fake AI Tool Installers

If you use Claude Code or any other AI developer tool, there are a few things you should do right now.

First, only download from official sources. Claude Code’s real installation instructions are on Anthropic’s official website and documentation. Never trust a Google search result that takes you to an unfamiliar domain, even if it looks legitimate.

Second, check your browser extensions. If you have crypto wallet extensions installed, verify they have not been modified. Look for unexpected permissions, recent update dates you do not recognise, or extensions you do not remember installing.

Third, check your desktop wallet apps. If you use Ledger Live or Trezor Suite, delete them and reinstall fresh from the official download pages. The malware in this campaign specifically tried to replace these apps with trojanised copies.

Fourth, change your passwords. If you entered your macOS password into any prompt you were not expecting, assume your Keychain has been compromised. Change your passwords for any service stored in Keychain, especially exchange accounts, email, and cloud infrastructure.

Fifth, use a hardware wallet. Keeping your crypto on a hardware device means that even if your laptop is compromised, the attacker cannot move funds without physical access to the device.

Frequently Asked Questions

What is the Claude Code malware campaign?
Hackers used SEO poisoning to push a fake Claude Code installation page to the top of Google search results in March 2026. macOS users who downloaded the fake installer had their browser credentials, crypto wallets, and system passwords stolen by malware similar to AMOS and Banshee variants.

How many crypto wallets were targeted by the Claude Code malware?
Bybit researchers identified targeted access attempts against more than 250 browser-based wallet extensions and multiple desktop wallet applications including Ledger Live and Trezor Suite. The malware attempted to replace legitimate wallet apps with trojanised versions.

How can I tell if I downloaded the fake Claude Code installer?
If you downloaded Claude Code from any source other than Anthropic’s official website or documentation, you may be affected. Check your browser extensions for unexpected changes, reinstall desktop wallet apps from official sources, and change any passwords you may have entered into unexpected macOS system prompts.

Salar Salek

Salar Salek Verified AltcoinReporter Author

Salar covers cryptocurrency markets, blockchain technology, DeFi, and emerging digital asset trends for AltcoinReporter. With a background in technology and finance, he has been actively following and investing in the...

Read More
Tags: BitcoinBlockchainEthereumSecurityWallets

Related Posts

Moody’s Just Launched Onchain Credit Ratings on Solana

Moody’s Just Launched Onchain Credit Ratings on Solana

by Salar Salek
June 18, 2026
0

For roughly a century, credit ratings have been the foundational language of fixed-income markets. Investors price bonds, structure portfolios, and...

The Quantum Computing Race Just Started: XRP Ledger, Bitcoin, and Ethereum All Move on Same Day

The Quantum Computing Race Just Started: XRP Ledger, Bitcoin, and Ethereum All Move on Same Day

by Salar Salek
June 15, 2026
0

Quantum computing has been a theoretical threat to blockchain security for years. Researchers debate whether "Q-day," the moment when a...

UFC Just Paid Fighter Bonuses in Trump’s USD1 Stablecoin at a White House Event

UFC Just Paid Fighter Bonuses in Trump’s USD1 Stablecoin at a White House Event

by Salar Salek
June 15, 2026
0

On Sunday June 14, the White House South Lawn was converted into a temporary UFC arena. UFC Freedom 250, organised...

75% of EU Crypto Firms Could Lose Their Licenses on July 1 as MiCA Deadline Approaches

75% of EU Crypto Firms Could Lose Their Licenses on July 1 as MiCA Deadline Approaches

by Salar Salek
June 15, 2026
0

On July 1, 2026, the European Union's grandfathering transition window under the Markets in Crypto-Assets regulation officially ends. After that...

Anthropic’s New Claude Fable 5 Could Make Crypto’s Next Hacker Move at Superhuman Speed

Anthropic’s New Claude Fable 5 Could Make Crypto’s Next Hacker Move at Superhuman Speed

by Salar Salek
June 15, 2026
0

Less than three weeks ago, Anthropic's Claude Opus 4.8 found a vulnerability in Zcash's Orchard shielded pool that had survived...

Load More
  • Trending
  • Comments
  • Latest
Solana Alpenglow Upgrade 2026: Launch Date, Features, and What It Means for SOL

Solana Alpenglow Upgrade 2026: Launch Date, Features, and What It Means for SOL

April 18, 2026
Justin Sun vs WLFI: “See You in Court” as Backdoor Token Freeze Row Explodes

Justin Sun vs WLFI: “See You in Court” as Backdoor Token Freeze Row Explodes

April 13, 2026
Former UK Chancellor Kwarteng Leads Bitcoin Firm as Farage Backs BTC

Former UK Chancellor Kwarteng Leads Bitcoin Firm as Farage Backs BTC

April 16, 2026
Bitcoin Price Hits Highest Since January as Bulls Eye $85K

Bitcoin Price Hits Highest Since January as Bulls Eye $85K

May 7, 2026
North Korea’s Six-Month Con: How Hackers Stole $286M from Solana’s Drift Protocol

North Korea’s Six-Month Con: How Hackers Stole $286M from Solana’s Drift Protocol

0
Ethereum’s Glamsterdam Upgrade: What It Is and Why It Matters in 2026

Ethereum’s Glamsterdam Upgrade: What It Is and Why It Matters in 2026

0
Bitcoin’s Worst Q1 Since 2018: Can April Turn the Tide?

Bitcoin’s Worst Q1 Since 2018: Can April Turn the Tide?

0
Former UK Chancellor Kwarteng Leads Bitcoin Firm as Farage Backs BTC

Former UK Chancellor Kwarteng Leads Bitcoin Firm as Farage Backs BTC

0
Sui Holds $0.75 After Processing $65 Billion in Stablecoin Volume in Eight Days

Sui Holds $0.75 After Processing $65 Billion in Stablecoin Volume in Eight Days

June 19, 2026
Bitcoin at $63,908 After Warsh Killed Rate Cuts: The Levels That Decide What Comes Next

Bitcoin at $63,908 After Warsh Killed Rate Cuts: The Levels That Decide What Comes Next

June 19, 2026
Fidelity and State Street Just Launched Stablecoin Reserve Funds Days Apart

Fidelity and State Street Just Launched Stablecoin Reserve Funds Days Apart

June 18, 2026
Moody’s Just Launched Onchain Credit Ratings on Solana

Moody’s Just Launched Onchain Credit Ratings on Solana

June 18, 2026

About

AltcoinReporter

AltcoinReporter is an independent crypto news platform built to keep you ahead of the market. We cover everything from Bitcoin and altcoins to DeFi, NFTs, regulation, and emerging blockchain technology.


Our editorial team delivers accurate news, detailed market analysis, and expert insights, with every article written and reviewed by named contributors. We are committed to transparent, independent reporting our readers can trust.

News

  • Altcoins
  • Bitcoin
  • Blockchain
  • DeFi
  • Ethereum
  • NFT

Reviews

  • Exchanges
  • NFT Marketplaces
  • Wallets

Company

  • About Us
  • Advertise
  • Write for Us
  • Contact Us

Disclaimer: AltcoinReporter.com provides cryptocurrency news for informational purposes only, not financial, investment, or legal advice. Crypto markets carry significant risk. Always do your own research and consult a financial advisor before investing. We may earn compensation through affiliate links, ads, and sponsored content, which are clearly labelled. AltcoinReporter is not responsible for any financial losses resulting from information on this site.

  • Cookie Policy
  • Ethics
  • Corrections
  • Editorial Standards
  • Privacy Policy
  • Terms & Conditions

© 2026 AltcoinReporter. All rights reserved.

No Result
View All Result
  • Home
  • News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFT
  • Press Releases
  • Reviews
    • Exchanges
    • NFT Marketplaces
    • Wallets
  • Market Analysis
  • Contact Us

© 2026 AltcoinReporter. All rights reserved.