📈 Get daily crypto insights that make you smarter about your money

A Fake Claude Desktop App Is Stealing Crypto From More Than 50 Wallets — Here’s How to Spot the Trap

HEADLINE: A Fake Claude Desktop App Is Stealing Crypto From More Than 50 Wallets — Here’s How to Spot the Trap SEO_KEYWORDS: fake Claude app malware, RevStealer crypto theft, crypto wallet security TAGS: Blockchain Technology, Security, AI Integration, Bitcoin —CONTENT—

A fake “Claude Opus 5 Free Desktop” application is spreading RevStealer, a Windows malware strain built to steal cryptocurrency from more than 50 different wallets, along with browser passwords, cookies and messaging data, according to cybersecurity researchers.

By Keisha Williams | September 1, 2026

The fraudulent desktop app impersonates AI developer Anthropic and promises free access to the Claude chatbot, according to a Monday report by cybersecurity company Morphisec shared by Cointelegraph. Anyone who installs it hands over the keys to their digital life — crypto wallets first.

The Hook: Free AI, Expensive Consequence

The scam is simple and effective. Cybercriminals clone the look of a popular AI desktop application, offer it as a free download, and wait for victims to install it. Once inside a Windows machine, RevStealer gets to work quietly in the background while the victim sees a convincing — but fake — AI interface.

This is the latest twist in a growing pattern: as millions of people rush to try AI tools, criminals are building fake versions of them to harvest login credentials and crypto keys. RevStealer was previously distributed through GitHub repositories and game-cheat-themed sites, but the fake Claude project is the most notable campaign so far, the researchers noted.

On-Chain Evidence: What the Malware Actually Takes

RevStealer is designed to leave few traces as it searches a victim’s machine. According to Morpisec’s findings, the malware targets:

  • More than 50 cryptocurrency wallets — both wallet files and wallet application windows
  • Browser databases and cookies — which can contain saved sessions for exchanges and email
  • Password-manager records — the master key to everything else
  • VPN and remote-access settings — potential footholds for follow-up attacks
  • Messaging data, screenshots and selected documents

In plain terms: if this malware lands on your computer, it is not just your wallet at risk — it is every account whose password or session lives in your browser.

The Core Conflict: Malware That Avoids Detection

What makes RevStealer harder to catch than average malware is its caution. Before unlocking its malicious payload, it checks whether the machine looks like a real user device — examining available memory, the number of processor cores, hostname, username and graphics hardware. It also monitors for the debugging delays typical of malware analysis environments used by security researchers.

If RevStealer detects anything out of the ordinary — such as a virtual machine used by analysts — it refuses to move to the next stage of infection, staying dormant and invisible. Only when the system passes those checks is the payload decrypted, stored under a random file name and covertly executed on the victim’s machine.

This evasion matters because it means standard antivirus scans may come back clean even on infected machines. The malware is built to look boring until it is sure nobody is watching.

Market Implications: A Wider Wave of AI-Themed Threats

The fake Claude app is not an isolated case. The Morphisec report follows the discovery by Russian cybersecurity company Kaspersky of a new malware framework called OkoBot that also targets cryptocurrency investors — harvesting wallet files, browser data and user credentials, injecting malicious browser extensions and capturing wallet application windows to steal assets. Microsoft has separately warned users of “Crypto Clipper” malware spread via USB drives.

For the crypto market, consumer security failures are more than personal tragedies — they are adoption headwinds. Every high-profile theft story convinces some fraction of would-be investors that crypto is too dangerous to touch, even when the vulnerability lies in a fake app and not in the blockchain itself.

The Verdict: What This Means for You

The defense here is boring but effective. Only download AI desktop apps from the official website of the company that makes them — never from GitHub repositories, third-party download sites or links in messages. If an app promises free access to a paid product, treat that as a red flag rather than a bargain.

Crypto holders should add a second layer: move long-term holdings to a hardware wallet, which keeps private keys offline and out of reach of any malware, and use a dedicated browser profile or even a separate device for exchange accounts. RevStealer cannot steal what is not on the infected machine.

AI tools are genuinely useful. Fake versions of them are genuinely dangerous. The difference is usually just where you clicked download.

The cryptocurrency market remains highly volatile. This article is for informational purposes only and does not constitute financial advice.

Disclaimer: This article is for informational purposes only and does not constitute financial advice.

10 thoughts on “A Fake Claude Desktop App Is Stealing Crypto From More Than 50 Wallets — Here’s How to Spot the Trap”

  1. anthropic doesnt even have a free desktop opus, five seconds on their site would tell you that. people really install anything with AI in the name now

      1. takedowns are whack a mole when the payload rotates domains hourly. morphisec publishing indicators is honestly more useful than a single seizure

  2. 50+ wallets targeted plus browser cookies. the cookie part is nastier than the wallet drainer tbh, session hijack gets your exchange login too

    1. learned this the hard way, 2FA on the exchange means nothing when the session cookie is already in the attackers browser

  3. free claude opus 5 desktop lmao. if a company gives something away it lives on their real site, not some random installer

    1. it grabs cookies and passwords too, so even a hardware wallet wont save an exchange account once the session is hijacked

  4. RevStealer was spreading through GitHub repos before and people still install the fake desktop version. Only get it from anthropic.ai, takes two seconds to check.

  5. the fake installer even bundles a working looking chat UI so victims dont notice for days. biggest tell is the domain, anthropic has exactly one

Leave a Comment

Your email address will not be published. Required fields are marked *

BTC$77,596.00-1.2%ETH$2,432.27-1.3%SOL$101.31-1.1%BNB$684.60-0.5%XRP$1.37-0.4%ADA$0.1975+1.1%DOGE$0.0822-0.6%DOT$0.8615+4.7%AVAX$7.26+1.0%LINK$11.37+0.6%UNI$5.67+10.6%ATOM$1.48+1.1%LTC$49.67+2.7%ARB$0.1083+24.6%NEAR$1.98+7.2%FIL$0.7072+6.0%SUI$0.7268+1.2%BTC$77,596.00-1.2%ETH$2,432.27-1.3%SOL$101.31-1.1%BNB$684.60-0.5%XRP$1.37-0.4%ADA$0.1975+1.1%DOGE$0.0822-0.6%DOT$0.8615+4.7%AVAX$7.26+1.0%LINK$11.37+0.6%UNI$5.67+10.6%ATOM$1.48+1.1%LTC$49.67+2.7%ARB$0.1083+24.6%NEAR$1.98+7.2%FIL$0.7072+6.0%SUI$0.7268+1.2%
Scroll to Top