Crypto: the PC becomes the weak point
The campaign allegedly relies on a Remote Access Trojan, or RAT, a type of malware that allows an attacker to control an infected machine remotely. Bref Crypto previously detailed how some malware now exploits browsers, passwords and exchange accounts. Here, the threat could go further by directly hijacking already authenticated sessions.
The mechanism is particularly dangerous. When a user logs in to an exchange or crypto service, the browser generally stores a cookie or session token so that the password does not need to be entered again with every click. An attacker capable of retrieving or manipulating that session can sometimes act as if the user were already logged in.
The password can therefore be strong.
2FA can be enabled.
The attacker may still bypass some of these protections if they take control of an already open session.
Coin Bureau claims that hundreds of victims may have been affected during the 48 hours preceding its September 20 alert. However, the initial vector remains unknown: no specific malicious download, fake software, extension or phishing campaign has yet been publicly identified.
The $235,000 figure still requires confirmation
An Ethereum address linked to the case, beginning with 0x7028 and ending with 5887, nevertheless provides an initial verifiable trace.
Blockchain data shows several transfers to this address. An analysis of the flows published by EtherWorld identified approximately $130,000 in USDC and USDT from 13 different addresses during a window observed on September 19, along with additional movements in WETH, WBTC and LINK.
The wallet’s total displayed value was then approximately $235,747.
However, this amount is not automatically equivalent to $235,747 stolen by the same malware. A wallet can receive different types of funds, some assets may have been bridged or exchanged, and not all transactions have yet been attributed.
This is precisely the case’s current weakness.
No recognized cybersecurity company has yet published a technical report detailing the malware, its hash, its command-and-control domains, its infection vector or the indicators that would allow it to be detected. It would therefore be premature to give it a name or confuse it with SilabRAT, another crypto RAT documented earlier in 2026.
The amount is credible.
The session-hijacking scenario is credible as well.
The technical investigation remains incomplete.
A seed phrase cannot protect a compromised computer
Above all, this case is a reminder that crypto security does not stop at the blockchain.
A hardware wallet can prevent a private key from physically leaving the device. It does not necessarily protect a user who personally approves a manipulated transaction from a compromised computer. An exchange account can have a complex password and strong authentication while remaining vulnerable if the attacker already controls the browser.
The problem becomes even more serious with RATs.
Depending on their capabilities, these programs can log keystrokes, steal cookies, monitor the screen, access the clipboard or manipulate certain applications. A user may then copy a correct address and see a different address appear at the time of payment.
Changing the password from the same machine may not be enough.
If the computer remains infected, the new information can be captured again.
For a user who suspects an infection, the priority is therefore to stop using the machine for any sensitive crypto operation, revoke sessions from a clean device and separately check the affected wallets and accounts. Phishing campaigns impersonating Google have already shown how effectively attackers can now produce credible lures.
This new campaign remains poorly documented.
But the risk it illustrates is not.
Attackers no longer necessarily need to break Ethereum, Bitcoin or a smart contract.
Sometimes, all they need to do is take control of the computer that controls the keys.