Kaspersky Lab discovers malware to hack crypto wallets on macOS
The program gets on devices when downloading unofficial applications and allows hackers to steal passwords from wallets
23.01.2024 - 11:50
638
2 min
0
What’s new? Kaspersky Lab has discovered a malware that enters macOS’ devices via pirated software and replaces the software hot non-custodial crypto wallets Bitcoin Wallet and Exodus Wallet with infected versions. The program targets macOS versions 13.6 and above. The hackers gain access to the computer password when the user enters it into the activation field, as well as the crypto wallets’ private keys when the victim tries to open their compromised versions.
What else is known? Users are at risk of downloading malware when attempting to install applications from unauthorized sources, which also involves disabling the computer’s antivirus protection. The malware has a backdoor that allows running any scripts with administrator rights on devices, including replacing crypto wallet applications to steal seed phrases and gain access to assets.
Kaspersky Lab recommended using reliable websites, updating the OS in a timely manner and using antivirus.
Earlier, a method of stealing cryptocurrencies was also spread, where malware disguised as official wallets is uploaded to marketplaces or third-party sites. Last year, Kaspersky Lab also reported on the emergence of fake physical crypto wallets.
Kaspersky Lab speaks about the emergence of fake hardware wallets
Experts urged to buy devices only from trusted dealers
In March, the company warned about cases of cryptocurrency theft using the fake Tor browser. According to experts, a third of US crypto users had their assets stolen in 2022.
Useful material?
Incidents
Developers warned of potential risks to bridges across the ecosystem and asked exchanges for assistance.
Jun 22, 2026
Incidents
The defendant helped move funds stolen through investment scams and earned at least $4 million for his role in the operation.
Jun 10, 2026
Incidents
The company is linking the incident to a compromised private key on a service wallet, rather than a smart contract exploit
May 22, 2026
Incidents
Following the incident, the project temporarily halted trading operations and node activity.
May 15, 2026
Incidents
The user spent weeks unsuccessfully trying to guess the password until Claude helped find an old wallet backup file
May 14, 2026
Crypto regulations
Authorities are introducing mandatory registration for companies handling cross-border crypto transactions
May 8, 2026
Telegram
Twitter