Normal view

There are new articles available, click to refresh the page.
Before yesterdayMain stream

5 New Crypto-Stealing Malware Threats You Didn’t See Coming

31 August 2026 at 00:06

Malware is any malicious software designed to infiltrate and harm a system, and crypto-stealing malware specifically targets digital assets. These threats come in many forms, tricking users into installing them through fake apps, phishing links, or compromised software. Once inside a device, they can steal private keys, modify transactions, or deceive victims into approving fraudulent transfers, leading to significant financial losses.

In 2024 alone, wallet drainer malware stole nearly $500 million from over 332,000 victims, marking a sharp rise from the previous year. The largest single theft reached $55.48 million, with the first quarter seeing the highest activity. Hackers and scammers are pretty active, as we can see. That’s why we’ll explore here five relatively new andcunning malware types, from deceptive trojans to sneaky transaction-altering clippers.

SparkCat & SpyAgent

You know you should take care of your private keys, preferably outside the digital world. But have you ever felt lazy enough to just take a screenshot of them, and save it inside your gallery? Who will ever know, right? Well, this malware type is the very reason why you should stop doing that. Cybercriminals will know and snatch all your coins.

They’re now using optical character recognition (OCR) technology to scan images stored on your device for sensitive information. OCR-based malware can detect and extract text from screenshots, putting your cryptocurrency recovery phrases, passwords, and other private data at risk. If you’ve ever taken a screenshot of a wallet seed phrase, login credentials, or personal messages, this malware can find it and send it to attackers — giving them full control over your accounts.

SpyAgent Screenshots by McAffee

Kaspersky identified SparkCat, which has been active on both Google Play and the App Store, while McAfee discovered SpyAgent, mainly spreading through Android APKs outside official stores. The two malware strains are suspiciously similar, so they might as well be the same under different names. SparkCat has been found in popular apps like messengers and food delivery services, with over 242,000 downloads, targeting users in the UAE, Europe, and Asia. Meanwhile, SpyAgent has focused on South Korea, with signs of expansion to the UK.

To protect yourself, besides avoiding storing sensitive information in screenshots, only download well-ranked apps from official stores, and be cautious about granting unnecessary permissions. If you suspect an infection, remove the app immediately and use security tools to scan your device.

Fake Job Offers

Are you looking for a job in the crypto industry right now? You may be at risk of being scammed by the criminals behind this type of malware. They create fake job postings on trusted platforms like LinkedIn, CryptoJobsList, and WellFound, luring victims into fake interviews. The process seems professional at first, with initial exchanges happening over email or messaging apps like Telegram and Discord.

However, at some point, the recruiter asks the applicant to download special video conferencing software to complete the interview. This software, often presented as a tool like “Willo,” “Meeten,” or “GrassCall,” is actually a trojan designed to steal personal data and cryptocurrency. Once installed, the malware activates and begins gathering sensitive information from the victim’s device.

Meeten Malicious Website. Image by Cado Security

Among these malicious programs, Meeten stands out for its ability to steal cryptocurrency directly from browser wallets. Researchers from Cado Security Labs uncovered that Meeten’s malware can collect banking details, browser cookies, and even passwords stored in popular crypto wallets like Ledger and Trezor. GrassCall follows a similar pattern but is linked to a Russian cybercriminal group called Crazy Evil. This group specializes in social engineering attacks, using fake job interviews to gain victims’ trust.

Victims who download the GrassCall software unknowingly install a remote access trojan (RAT) alongside an infostealer. These programs allow attackers to log keystrokes, extract passwords, and drain crypto wallets. Security experts tracking this campaign found that the criminals even rewarded their affiliates with a share of the stolen assets, making it a highly organized operation.

To stay safe from such scams, always be cautious when asked to download software from unfamiliar sources, verify recruiters’ identities through official company websites, and use security tools to detect suspicious activity on your devices.

MassJacker

Clippers are a type of malware that specifically targets cryptocurrency transactions by monitoring the clipboard of an infected device. When you copy a wallet address, clippers silently replace it with one controlled by attackers. Since cryptocurrency transactions are irreversible, if you don’t double-check the address before sending funds, your money could be gone for good. Clippers are simple yet highly effective, as they don’t require sophisticated attacks — just an unnoticed swap in your copied text.

MassJacker configuration, including some crypto addresses. Image by CyberArk

MassJacker is a large-scale clipper campaign recently discovered to be using at least 778,531 fraudulent wallet addresses. At the time of analysis by CyberArk, only 423 of the wallets contained any funds, totaling about $95,300, but historical data suggests much larger sums have been stolen. The malware operators seem to rely on a central Solana wallet, which has received over $300,000 so far. MassJacker spreads through pirated software downloads, particularly from a site called pesktop[.]com.

When you run an infected installer (for a movie, a game, a tool, etc.), a hidden script executes a complex chain of malware loaders, eventually injecting MassJacker into a legitimate Windows process to evade detection. To avoid MassJacker and similar threats, be cautious when downloading software, especially pirated programs, as they are a common delivery method for malware. Always verify wallet addresses manually before confirming any transaction to ensure they haven’t been altered.

GitVenom

If you’re an open-source developer using GitHub, you should be extra cautious about the repositories you download. As discovered by Kaspersky, hackers have been spreading malware called GitVenom by creating fake projects that look legitimate. These projects often claim to be useful tools, such as Telegram bots for managing Bitcoin wallets or automation scripts for Instagram. They even come with well-written documentation, AI-generated README files, and artificially inflated commit histories to appear authentic.

Example structure of a malicious GitHub repository. Image by Kaspersky

However, once you download and run the code, GitVenom silently infects your system, stealing sensitive data, including your browsing history, passwords, and — most importantly — your cryptocurrency wallet information. Once active, GitVenom installs additional malware, including clipboard hijackers (clippers) that replace copied wallet addresses, redirecting transactions to attacker-controlled wallets. So far, cybercriminals have stolen at least 5 BTC, worth around $485,000, with most infections detected in Russia, Brazil, and Turkey.

Don’t just trust a GitHub project because it looks popular — inspect the code, check for unusual activity in commit histories, and be wary of newly created repositories with polished documentation. Running unverified code from GitHub without proper review could compromise your entire development environment and crypto assets.

DroidBot

Described by Cleafy, this malware targets banking and cryptocurrency apps to steal user credentials — and their funds. It has been active since June 2024, mainly in the UK, Italy, France, Spain, and Portugal, with signs of expansion into Latin America. The malware impersonates apps like Google Chrome, Google Play Store, and Android Security to trick users into installation.

Once on a device, it abuses Android’s Accessibility Services to record keystrokes, display fake login screens, intercept SMS messages, and even remotely control infected devices. Some of the affected platforms include Binance, KuCoin, BBVA, Santander, Kraken, and MetaMask. Over 77 targets have been identified, though.

Common decoy used in DroidBot campaigns. Image by Cleafy

A key characteristic of DroidBot is its operation as a Malware-as-a-Service (MaaS), allowing cybercriminals to rent the malware for $3,000 per month. At least 17 affiliate groups use the malware, each customizing it to attack specific targets. Researchers believe the malware’s creators are Turkish, as suggested by language settings in leaked screenshots. So far, 776 infections have been confirmed, mostly in Europe.

DroidBot’s infection vectors primarily rely on social engineering tactics, tricking users into downloading the malicious app through fake security updates or cloned applications. Once installed, it can remotely control the device, execute commands, and even darken the screen to hide its activity. Always be careful with the software you’re installing!

Protect Yourself Against Crypto-Stealing Malware

It’s necessary to stay vigilant in the online world. Likewise, you can take some preventive measures against potential attacks.

  • Avoid downloading apps from unofficial sources to reduce malware risks.
  • Regularly update your OS and apps to patch vulnerabilities. Always keep proper security tools (antivirus, antispyware, etc.)
  • When pasting crypto addresses, monitor your clipboard activity to detect unauthorized modifications. In Obyte, you can avoid crypto addresses and instead send funds through textcoins or attestations.
A received textcoin in Obyte
  • Keep your private keys outside the digital world. In Obyte, it’s also possible to erase the words from the wallet after writing them down physically.
  • Enable two-factor authentication (2FA) for all your accounts. In Obyte wallets, you can do this by creating a multidevice account from the Global Settings.
  • Limit browser and app permissions to prevent potential attacks. If you need to download an app, check its rank and number of downloads (legitimate apps often have thousands and millions of downloads.)
  • Verify GitHub repositories before downloading code.
  • Use well-known software tools for job interviews, instead of downloading new brands that you’ve never heard of before. If your potential employer insists, suspect them and research more about them.
  • Stay informed and updated on new security and crypto trends from reliable sources!

Featured Vector Image by Freepik

Originally Published on Hackernoon


5 New Crypto-Stealing Malware Threats You Didn’t See Coming was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

The Crypto Blacklist Problem: Sanctions and Restrictions

24 August 2026 at 09:29

In the world of cryptocurrencies, a “blacklist” usually means a list of addresses, accounts, or smart contracts that are banned from sending, receiving, or using tokens in centralized platforms — sometimes, even in some “decentralized” platforms, too. Governments and regulators use these lists to enforce financial laws, but they also raise hard questions about privacy and freedom in crypto. With pressure growing, many are asking: can truly decentralized systems survive blacklists?

Some distributed ledgers, like Ethereum, have had to walk a careful line between legal compliance and maintaining their open nature. Meanwhile, alternative networks like Obyte offer a different approach that could make censorship much harder. Let’s explore what’s happening, what’s at risk, and where things could go from here.

Blacklists and Ethereum — A Growing Challenge

Ethereum, the second-largest crypto network by market value, has faced several blacklist controversies. For example, after the U.S. sanctioned the privacy tool Tornado Cash in 2022, many Ethereum apps and services blocked addresses linked to it. Even stablecoins like USDC froze accounts that regulators flagged.

These moves show how central players in crypto ecosystems — like token issuers — can control access. Although distributed ledgers and smart contracts are supposed to run without middlemen, outside events can force changes that break this ideal. Developers are left caught between building open platforms and following real-world laws. For users, the consequences are even clearer: your assets could become unusable overnight if they land on a blacklist. For instance, if you, as a US citizen, mixed some funds on Tornado Cash and authorities found out.

Censorship in crypto doesn’t just block a few bad actors — it can reshape entire networks. After Ethereum switched to proof-of-stake (PoS), “validators” became the new gatekeepers (replacing mining pools), and some started filtering transactions to avoid dealing with blacklisted addresses. Tools like MEV-boost made it easier for them to choose which transactions to include.

This behavior weakens the original promise of crypto neutrality. Instead of treating every user equally, censored networks prioritize compliance over fairness. If enough “validators” cooperate with regulators, blockchains could lose their independence and start resembling traditional financial systems. Over time, this could drive away users who once turned to crypto for freedom.

Crypto’s Vulnerability: Custodians and Compliance

Even though crypto itself is designed to resist censorship to a degree, centralized players like exchanges and custodians are more vulnerable. Besides token issuers in blockchains, many firms choose to comply with regulations to protect their reputation and continue operating legally.

Major exchanges like Coinbase and Binance have enhanced Know Your Customer (KYC) and Anti-Money Laundering (AML) practices, restricting transactions linked to sanctioned entities. Although this protects their legal standing, it limits cryptocurrencies even more and potentially threatens the core ethos of crypto freedom. On the other hand, governments wouldn’t allow them to operate at all without this compliance. It’s an inescapable conundrum.

The tension between maintaining decentralization and complying with regulations is a delicate balancing act. While some projects strive to uphold the original ideals of financial autonomy, many large-scale operations prioritize business sustainability over ideology.

Alternative Approaches

At the very least, we can fix internal blockchain censorship by picking another network. Not all crypto platforms are built the same. Obyte, for example, uses a Directed Acyclic Graph (DAG) instead of a blockchain. There are no miners or “validators” deciding which transactions go through. Instead, transactions are added to the DAG directly by users themselves, removing centralized bottlenecks that can be targeted by regulators.

This structure makes censorship much harder. Since no single group controls transaction approval, it’s almost impossible to blacklist an account or address globally. In a world where blacklists are spreading, architectures like Obyte’s could offer real alternatives.

However, even the most censorship-resistant systems face practical limits. Crypto projects still need bridges, gateways, and exchanges to interact with the broader economy. In other words: you’ll need to turn your crypto into USD, EUR, or whatever fiat currency at some point. These points of contact, as we mentioned above, are often under legal pressure and can block users even if the underlying network resists.

Obyte is better protected at the protocol level, but users still risk exposure when cashing out or connecting to external services. No system is completely immune because people still live under legal systems. Designing censorship resistance is essential, but managing the risks outside the network matters just as much. But hey, good news? Crypto bans are rarely effective, even when exchanging for fiat.

Why Bans Often Fail to Stop Crypto

Despite regulatory efforts, crypto use persists in countries with bans — and platforms with sanctions are still very much used. Chainalysis’ Global Crypto Adoption Index shows that 50% of the top 10 countries with the highest crypto adoption rates have either full or partial bans. China, for instance, maintains strict regulations, yet still ranks within the top 20 for crypto usage.

In nations like Bangladesh, Egypt, and Morocco, where crypto is officially forbidden, enforcement struggles to keep pace with user activity. Individuals continue to buy, sell, and trade cryptocurrencies, often using decentralized platforms or peer-to-peer (P2P) networks to evade restrictions.

This isn’t just a sense of rebellion. Economic instability plays a significant role. In places where local currencies are unstable, citizens turn to crypto to preserve their wealth. In Venezuela and Nigeria, for example, crypto provides an alternative to hyperinflation and tight government controls. The decentralized design of cryptocurrencies makes it nearly impossible for authorities to shut down networks entirely, even if individual users may face risks.

Bans often push crypto activity into underground markets, removing the protective layers that regulation could have provided. Instead of stopping usage, heavy-handed laws often make crypto ecosystems more opaque and harder to supervise.

How Decentralized Players Are Facing Restrictions

Even as centralized players increasingly comply, decentralized systems remain resistant. Protocols without central authorities — like certain DeFi platforms and decentralized exchanges (DEXs) — cannot easily enforce blacklists or freeze funds. Without a governing body, these platforms continue operating globally, regardless of local bans.

Individual users have also been adapting creatively. Although Tornado Cash was sanctioned by the U.S. Treasury (until November 2024) and its domains and website were taken down, users still accessed it through decentralized interfaces like IPFS. According to Dune Analytics, users deposited variable amounts after the sanctions, up to $22 million in September 2024, despite legal hurdles.

Speaking of those legal hurdles, six users of Tornado Cash, backed financially by Coinbase, sued the U.S. Treasury Department after it sanctioned the mixer. In November 2024, the U.S. 5th Circuit Court of Appeals ruled that the Treasury overstepped its authority because Tornado Cash’s decentralized smart contracts aren’t “property” that can be sanctioned under current law. The court sided with the users, overturning the sanctions. Individuals are fighting back and winning some battles, too.

On the other hand, data from the Atlantic Council shows that at least 27 countries have imposed full or partial crypto bans. Yet crypto adoption is still highest in regions under pressure. In Nigeria, even with restrictions, over 46% of the population reports owning or using cryptocurrencies. In China, underground networks and offshore exchanges allow continued participation in the global crypto economy.

Countries with crypto regulations by Atlantic Council

Necessity drives innovation. In authoritarian regimes, citizens often use crypto to protect savings, send remittances abroad, or circumvent local banking restrictions. Bans, instead of halting crypto activity, push it further into decentralized, less traceable channels. Crypto’s foundational trait — censorship resistance — proves indispensable where freedom is under threat.

Toward a Freer Crypto Future

The rise of blacklists highlights a major tension in crypto: can these technologies stay open and neutral while fitting into the regulated world? Blockchains that allow easy censorship might survive in the short term, but they risk losing their core values — and users.

Systems like Obyte show that it’s possible to prioritize user freedom at the design level. Still, the bigger battle lies in how users, developers, and regulators shape the evolving crypto space. Whether people choose resilient platforms or prioritize convenience will define what crypto becomes in the next decade — and whether it stays true to its original vision.

As personal liberties continue to erode across the globe, users will likely, over time, gravitate toward more open and decentralized platforms. The future belongs to decentralization, as centralization has led to widespread surveillance, media manipulation, discrimination, financial censorship, data breaches, and countless other problems.

Featured Vector Image by pikisuperstar / Freepik

Originally Published on Binance Square


The Crypto Blacklist Problem: Sanctions and Restrictions was originally published in Coinmonks on Medium, where people are continuing the conversation by highlighting and responding to this story.

❌
❌