A fake Claude app is spreading malware called RevStealer, and researchers say it targets more than 50 crypto wallets. The trap poses as a free desktop version of Anthropic’s AI assistant, but it quietly steals wallet data from anyone who installs it.
Security researchers at Morphisec Threat Labs uncovered the campaign. They found that RevStealer spread through a fake “Claude Opus 5 Free Desktop” project hosted on GitHub, impersonating Anthropic, the company behind Claude. For related coverage, see Ireland Excludes Crypto From New Tax-Friendly Accounts.
This matters because the attack preys on trust. People searching for popular AI tools may download the fake app without a second thought, then hand attackers the keys to their crypto. For related coverage, see Arizona Crypto ATM Law Helped 35 Scam Victims Recover $171,332.
How the Fake Claude App Delivers RevStealer
The lure is simple. Victims think they are getting a free desktop version of Claude, a well-known AI chatbot. Instead, they download a booby-trapped file. For related coverage, see THORWallet Launches Self-Custodial Crypto Card in 172 Countries.
Morphisec said the download was a roughly 101 MB archive that launched an Electron application with no visible window. An Electron app is software built with web technology; here, it ran silently with no interface, so the victim saw nothing happen.
Before unpacking its true payload, the malware ran a series of checks. It inspected memory, CPU cores, graphics hardware, and blocklisted usernames or hostnames, according to CyberInsider. These checks help malware avoid running inside a researcher’s test machine.
The stealth worked. Help Net Security reported that the malicious sample was flagged by only 1 of 66 antivirus engines in the research screenshots. That means nearly every scanner missed it.
This campaign follows a familiar pattern. Attackers recently hid the Lumma Stealer inside pirated movie downloads to target crypto wallets, showing how popular content becomes bait.
Why Crypto Wallet Users Are the Primary Target
RevStealer is built to rob crypto holders. Morphisec said its confirmed collection list covered more than fifty cryptocurrency wallets.
Wallet-targeting malware is especially dangerous. If it grabs your wallet’s login data or secret keys, an attacker can drain your funds. Unlike a bank, crypto has no fraud department to reverse the theft.
This is a direct threat to everyday holders, not just big traders. Anyone using self-custody, meaning you hold your own keys instead of an exchange, faces real exposure here.
The malware also had a clever backup plan. RevStealer could read a fallback command-and-control address from a Polygon smart contract if its main server went down. Smart contracts are automated programs on a blockchain, and using one made the malware harder to shut off.
The timing raises the stakes. Bitcoin’s market value sat near 1.55 trillion dollars in recent market data, showing how much wealth now sits in the ecosystem these thieves target.
Market mood is upbeat, which can lower people’s guard. The crypto Fear & Greed Index reads 69, signaling “Greed” among investors.
Morphisec researcher Shmuel Uzan described just how carefully the malware hides. He said “every stage of it is engineered around the assumption that something is watching.”
What Users Should Watch for After the RevStealer Alert
The clearest lesson is to avoid unofficial download sources. A GitHub project or random link promising a free AI app is not the same as an official release from the company.
Always verify software authenticity before installing. Check the developer’s official website first, and be suspicious of any “desktop” version of a tool that normally runs in your browser.
Crypto wallet users should review their device and account security now. If you installed anything odd recently, consider moving funds to a fresh wallet and scanning your device.
Fake software lures keep spreading fast. Researchers recently flagged 40 malicious Firefox add-ons aimed at crypto users, another reminder to install only what you can verify.
For anyone new to crypto, the safest habit is caution. Slow down before downloading, double-check the source, and treat your wallet keys like the password to your entire savings account.
Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.