HP says criminals are advertising fake AI trading agents that install malware and replace cryptocurrency wallet extensions with malicious lookalikes. Its September 17 Threat Insights announcement names Coinbase and MetaMask extensions among the targets.
According to the researchers, the downloaded malware scans the victim's browser for wallet extensions, substitutes copies, and captures credentials entered into them. A familiar-looking wallet interface can therefore appear after the browser environment has already been compromised.
New report, earlier observation period
The findings draw on consenting HP Wolf Security customers' data from April through June 2026. The publication date should not be read as the start date of every campaign described.
This is a report about malicious downloads and replacement extensions, not evidence that Coinbase or MetaMask's official services were themselves breached.
For wallet users, the relevant check starts before installation: an advertised trading tool can become the route into an otherwise familiar browser wallet. HP's announcement does not provide a crypto loss total for this campaign.