• About Us
  • Advertise
AltcoinReporter
  • Home
  • News
    • Bitcoin
    • Ethereum
    • Blockchain
    • Altcoins
    • DeFi
    • NFT
  • Press Releases
  • Reviews
    • Exchanges
    • NFT Marketplaces
    • Wallets
  • Market Analysis
  • Contact Us
No Result
View All Result
  • Home
  • News
    • Bitcoin
    • Ethereum
    • Blockchain
    • Altcoins
    • DeFi
    • NFT
  • Press Releases
  • Reviews
    • Exchanges
    • NFT Marketplaces
    • Wallets
  • Market Analysis
  • Contact Us
No Result
View All Result
AltcoinReporter
No Result
View All Result
Home Blockchain

Fake Claude Code Site Steals Crypto Wallets via Google Search Hack

Hackers used SEO poisoning to push a fake Claude Code install page to the top of Google, stealing crypto wallets from 250+ browser extensions. Bybit exposed it.

Salar S by Salar S
April 24, 2026
in Blockchain
Fake Claude Code Site Steals Crypto Wallets via Google Search Hack

If you searched Google for “Claude Code” in March and clicked the top result, you might have installed malware instead of Anthropic’s AI coding tool. That is not a hypothetical. It happened.

Bybit’s security team uncovered a malware campaign that used SEO poisoning to push a fake Claude Code installation page to the top of Google search results. macOS users who clicked the link downloaded what looked like a normal installer. Instead, it deployed a two-stage attack chain that stole browser credentials, macOS Keychain entries, Telegram sessions, VPN profiles, and cryptocurrency wallet data from over 250 browser extensions.

Related articles

UK FCA Crypto Crackdown: 8 Illegal P2P Trading Hubs Raided in London

UK FCA Crypto Crackdown: 8 Illegal P2P Trading Hubs Raided in London

April 23, 2026
DoorDash Is Paying Delivery Drivers in Stablecoins and It Could Change How Millions of Workers Get Paid

DoorDash Is Paying Delivery Drivers in Stablecoins and It Could Change How Millions of Workers Get Paid

April 22, 2026

The campaign was first spotted on March 12, 2026. The fake site looked almost identical to Anthropic’s real documentation. Most people would not have noticed the difference.

How Does the Claude Code Crypto Malware Work?

The attack was built in two stages. Both were designed to be invisible.

Stage one: when a user downloaded the fake installer, it dropped a Mach-O binary onto their Mac. That binary deployed a script-based info stealer that Bybit’s researchers said shows similarities to AMOS and Banshee, two well-known malware families that have been targeting Apple users since 2023. The stealer ran through a multi-phase process to dig through the system and grab everything it could find.

Stage two: it went after crypto specifically. The malware scanned for over 250 browser-based wallet extensions, the kind that millions of crypto users have installed in Chrome, Brave, and Firefox. It also targeted desktop wallet apps. In some cases, it tried to replace legitimate copies of Ledger Live and Trezor Suite with trojanised versions. So even if you checked your apps afterwards, they would look normal but would be quietly sending your data to the attacker.

The malware also used a clever social engineering trick. It popped up a fake macOS password prompt that looked exactly like the real system dialog. If you typed your password, it was captured and used to unlock your Keychain, which stores all your saved passwords, authentication tokens, and encryption keys. One password, and the attacker had everything.

Why Did Hackers Target Claude Code Users?

Claude Code is Anthropic’s command-line AI coding tool. It has become one of the most popular developer tools in 2026, used by software engineers, crypto developers, and AI researchers to write and debug code directly from their terminal.

That popularity is exactly what made it a target. CryptoTimes reported that developers are “high-value victims” because they typically have direct access to codebases, cloud infrastructure, signing keys, and personal crypto wallets on the same machine. A single compromised developer laptop can cascade into source code theft, CI/CD pipeline access, and in the worst cases, the kind of multisig signing exploits that enabled the $1.4 billion Bybit hack in February 2025 and the $285 million Drift Protocol exploit this month.

Microsoft’s Defender Experts team confirmed in February 2026 that macOS-targeted infostealer campaigns are increasingly using fake AI tool installers as delivery vehicles. Claude Code was not the first AI tool to be spoofed this way, and it will not be the last.

How Did Bybit Catch It?

This is where the story gets interesting. Bybit used AI to catch an AI-era attack.

The exchange’s Security Operations Center runs what it calls an “AI-assisted SOC” that can move from detection to full kill chain analysis in a single operational session. David Zong, Bybit’s Head of Group Risk Control and Security, said the entire process of decompiling the malware, extracting indicators, drafting the threat report, and writing detection rules was completed in one session. Work that used to take a team of analysts across multiple shifts was done in hours.

Bybit identified the malicious infrastructure on March 12, completed its analysis the same day, and published public detection guidance on March 20. The speed matters. Every day a fake installer sits at the top of Google is another day that developers are getting compromised.

Zong was blunt about what this means for the future: “We will face an AI war. Using AI to defend against AI is an inevitable trend.”

How to Protect Yourself From Fake AI Tool Installers

If you use Claude Code or any other AI developer tool, there are a few things you should do right now.

First, only download from official sources. Claude Code’s real installation instructions are on Anthropic’s official website and documentation. Never trust a Google search result that takes you to an unfamiliar domain, even if it looks legitimate.

Second, check your browser extensions. If you have crypto wallet extensions installed, verify they have not been modified. Look for unexpected permissions, recent update dates you do not recognise, or extensions you do not remember installing.

Third, check your desktop wallet apps. If you use Ledger Live or Trezor Suite, delete them and reinstall fresh from the official download pages. The malware in this campaign specifically tried to replace these apps with trojanised copies.

Fourth, change your passwords. If you entered your macOS password into any prompt you were not expecting, assume your Keychain has been compromised. Change your passwords for any service stored in Keychain, especially exchange accounts, email, and cloud infrastructure.

Fifth, use a hardware wallet. Keeping your crypto on a hardware device means that even if your laptop is compromised, the attacker cannot move funds without physical access to the device.

Frequently Asked Questions

What is the Claude Code malware campaign?
Hackers used SEO poisoning to push a fake Claude Code installation page to the top of Google search results in March 2026. macOS users who downloaded the fake installer had their browser credentials, crypto wallets, and system passwords stolen by malware similar to AMOS and Banshee variants.

How many crypto wallets were targeted by the Claude Code malware?
Bybit researchers identified targeted access attempts against more than 250 browser-based wallet extensions and multiple desktop wallet applications including Ledger Live and Trezor Suite. The malware attempted to replace legitimate wallet apps with trojanised versions.

How can I tell if I downloaded the fake Claude Code installer?
If you downloaded Claude Code from any source other than Anthropic’s official website or documentation, you may be affected. Check your browser extensions for unexpected changes, reinstall desktop wallet apps from official sources, and change any passwords you may have entered into unexpected macOS system prompts.

Tags: BitcoinBlockchainEthereumSecurityWallets

Related Posts

UK FCA Crypto Crackdown: 8 Illegal P2P Trading Hubs Raided in London

UK FCA Crypto Crackdown: 8 Illegal P2P Trading Hubs Raided in London

by Salar S
April 23, 2026
0

The UK's Financial Conduct Authority just went from sending warning letters to kicking down doors. On April 22, the FCA...

DoorDash Is Paying Delivery Drivers in Stablecoins and It Could Change How Millions of Workers Get Paid

DoorDash Is Paying Delivery Drivers in Stablecoins and It Could Change How Millions of Workers Get Paid

by Salar S
April 22, 2026
0

Most people think of crypto as something you trade on an exchange. Buy low, sell high, check the price twelve...

Crypto Scammers Are Demanding Bitcoin for “Safe Passage” Through the Strait of Hormuz

Crypto Scammers Are Demanding Bitcoin for “Safe Passage” Through the Strait of Hormuz

by Salar S
April 21, 2026
0

This might be the strangest crypto story of the year. Scammers are impersonating Iranian military officials, contacting cargo ships stranded...

LayerZero and Kelp DAO Are Blaming Each Other for the $290 Million Hack and North Korea May Be Behind It

LayerZero and Kelp DAO Are Blaming Each Other for the $290 Million Hack and North Korea May Be Behind It

by Salar S
April 20, 2026
0

Somewhere in the wreckage of a $290 million theft, two of DeFi's biggest infrastructure providers are pointing fingers at each...

The White House Just Told Banks to “Move On” from the CLARITY Act Stablecoin Yield Fight

The White House Just Told Banks to “Move On” from the CLARITY Act Stablecoin Yield Fight

by Salar S
April 19, 2026
0

The most important piece of crypto legislation in American history is stuck, and the White House just made it clear...

Load More
  • Trending
  • Comments
  • Latest
Former UK Chancellor Kwarteng Leads Bitcoin Firm as Farage Backs BTC

Former UK Chancellor Kwarteng Leads Bitcoin Firm as Farage Backs BTC

April 16, 2026
Justin Sun vs WLFI: “See You in Court” as Backdoor Token Freeze Row Explodes

Justin Sun vs WLFI: “See You in Court” as Backdoor Token Freeze Row Explodes

April 13, 2026
Bitcoin ETF Inflows Hit $471M: Are Institutions Buying the Dip?

Bitcoin ETF Inflows Hit $471M: Are Institutions Buying the Dip?

April 7, 2026
Bitcoin Breaks $72,000 as Iran Ceasefire Triggers $595M Short Squeeze

Bitcoin Breaks $72,000 as Iran Ceasefire Triggers $595M Short Squeeze

April 8, 2026
North Korea’s Six-Month Con: How Hackers Stole $286M from Solana’s Drift Protocol

North Korea’s Six-Month Con: How Hackers Stole $286M from Solana’s Drift Protocol

0
Ethereum’s Glamsterdam Upgrade: What It Is and Why It Matters in 2026

Ethereum’s Glamsterdam Upgrade: What It Is and Why It Matters in 2026

0
Bitcoin’s Worst Q1 Since 2018: Can April Turn the Tide?

Bitcoin’s Worst Q1 Since 2018: Can April Turn the Tide?

0
Former UK Chancellor Kwarteng Leads Bitcoin Firm as Farage Backs BTC

Former UK Chancellor Kwarteng Leads Bitcoin Firm as Farage Backs BTC

0
Fake Claude Code Site Steals Crypto Wallets via Google Search Hack

Fake Claude Code Site Steals Crypto Wallets via Google Search Hack

April 24, 2026
Cardano’s Leios Upgrade Targets 1,000 TPS as IO Cuts Budget by Half

Cardano’s Leios Upgrade Targets 1,000 TPS as IO Cuts Budget by Half

April 23, 2026
GSR’s New BESO ETF Offers Bitcoin, Ethereum and Solana in One Fund

GSR’s New BESO ETF Offers Bitcoin, Ethereum and Solana in One Fund

April 23, 2026
SparkLend TVL Jumps $1.4B as DeFi Capital Flees Aave After Hack

SparkLend TVL Jumps $1.4B as DeFi Capital Flees Aave After Hack

April 23, 2026

About

AltcoinReporter

AltcoinReporter is an independent crypto news platform built to keep you ahead of the market. We cover everything from Bitcoin and altcoins to DeFi, NFTs, regulation, and emerging blockchain technology.


Our global editorial team works around the clock to deliver accurate news, detailed price analysis, and expert insights so you never miss a beat in the crypto space. We believe in transparent, unbiased reporting and are committed to providing content that our readers can trust and rely on.

News

  • Altcoins
  • Bitcoin
  • Blockchain
  • DeFi
  • Ethereum
  • NFT

Reviews

  • Exchanges
  • NFT Marketplaces
  • Wallets

Company

  • About Us
  • Advertise
  • Write for Us
  • Contact Us

Disclaimer: AltcoinReporter.com provides cryptocurrency news for informational purposes only, not financial, investment, or legal advice. Crypto markets carry significant risk. Always do your own research and consult a financial advisor before investing. We may earn compensation through affiliate links, ads, and sponsored content, which are clearly labelled. AltcoinReporter is not responsible for any financial losses resulting from information on this site.

  • Cookie Policy
  • Editorial Policy
  • Privacy Policy
  • Terms & Conditions

© 2026 AltcoinReporter. All rights reserved.

No Result
View All Result
  • Home
  • News
    • Altcoins
    • Bitcoin
    • Blockchain
    • DeFi
    • Ethereum
    • NFT
  • Press Releases
  • Reviews
    • Exchanges
    • NFT Marketplaces
    • Wallets
  • Market Analysis
  • Contact Us

© 2026 AltcoinReporter. All rights reserved.