Skip to content
News Crypto News

Crypto: Malware Allegedly Siphoned More Than $235,000 in 48 Hours

More than $235,000 in cryptocurrency was allegedly siphoned off in just 48 hours by a malware campaign capable of hijacking its victims’ sessions. Coin Bureau mentions several hundred affected users, some of whom allegedly lost all their funds. An Ethereum address associated with the operation is visible on-chain, with flows from multiple wallets. But one key element is still missing: no one has publicly identified how the malware infects machines.

Analyst examines a compromised crypto session whose access is leaking to an unidentified presence
The associated wallet holds approximately $235,000, but the infection vector and technical attribution remain unknown.

Crypto: the PC becomes the weak point

The campaign allegedly relies on a Remote Access Trojan, or RAT, a type of malware that allows an attacker to control an infected machine remotely. Bref Crypto previously detailed how some malware now exploits browsers, passwords and exchange accounts. Here, the threat could go further by directly hijacking already authenticated sessions.

The mechanism is particularly dangerous. When a user logs in to an exchange or crypto service, the browser generally stores a cookie or session token so that the password does not need to be entered again with every click. An attacker capable of retrieving or manipulating that session can sometimes act as if the user were already logged in.

The password can therefore be strong.

2FA can be enabled.

The attacker may still bypass some of these protections if they take control of an already open session.

Coin Bureau claims that hundreds of victims may have been affected during the 48 hours preceding its September 20 alert. However, the initial vector remains unknown: no specific malicious download, fake software, extension or phishing campaign has yet been publicly identified.

The $235,000 figure still requires confirmation

An Ethereum address linked to the case, beginning with 0x7028 and ending with 5887, nevertheless provides an initial verifiable trace.

Blockchain data shows several transfers to this address. An analysis of the flows published by EtherWorld identified approximately $130,000 in USDC and USDT from 13 different addresses during a window observed on September 19, along with additional movements in WETH, WBTC and LINK.

The wallet’s total displayed value was then approximately $235,747.

However, this amount is not automatically equivalent to $235,747 stolen by the same malware. A wallet can receive different types of funds, some assets may have been bridged or exchanged, and not all transactions have yet been attributed.

This is precisely the case’s current weakness.

No recognized cybersecurity company has yet published a technical report detailing the malware, its hash, its command-and-control domains, its infection vector or the indicators that would allow it to be detected. It would therefore be premature to give it a name or confuse it with SilabRAT, another crypto RAT documented earlier in 2026.

The amount is credible.

The session-hijacking scenario is credible as well.

The technical investigation remains incomplete.

A seed phrase cannot protect a compromised computer

Above all, this case is a reminder that crypto security does not stop at the blockchain.

A hardware wallet can prevent a private key from physically leaving the device. It does not necessarily protect a user who personally approves a manipulated transaction from a compromised computer. An exchange account can have a complex password and strong authentication while remaining vulnerable if the attacker already controls the browser.

Bref Crypto had already observed during the Coldcard vulnerability that self-custody remains robust, but that excessive reliance on a single device or a single key significantly increases risk.

The problem becomes even more serious with RATs.

Depending on their capabilities, these programs can log keystrokes, steal cookies, monitor the screen, access the clipboard or manipulate certain applications. A user may then copy a correct address and see a different address appear at the time of payment.

Changing the password from the same machine may not be enough.

If the computer remains infected, the new information can be captured again.

For a user who suspects an infection, the priority is therefore to stop using the machine for any sensitive crypto operation, revoke sessions from a clean device and separately check the affected wallets and accounts. Phishing campaigns impersonating Google have already shown how effectively attackers can now produce credible lures.

This new campaign remains poorly documented.

But the risk it illustrates is not.

Attackers no longer necessarily need to break Ethereum, Bitcoin or a smart contract.

Sometimes, all they need to do is take control of the computer that controls the keys.

Sources cited1
BrefCrypto Crypto news from Africa and around the world
Follow us on Google News →
Author

Lydie Musekwa