Read, Not Cracked: Crypto’s Infostealer Epidemic in 2026
Most stolen crypto in 2026 is not cracked or guessed, it is read off the owner's own device. Inside the infostealers, clippers, and poisoned packages quietly draining self-custody wallets.
The theft that never touches the math
Most of the public story about stolen crypto in 2026 is told in nine-figure numbers: a $285 million admin-key heist here, a drained bridge there. Those cases are real, and we have covered them at length. The larger story, the one that touches the most people, is quieter and far less cinematic. It is a text file named seed.txt on a freelancer’s laptop. It is a wallet address pasted from a clipboard that was not showing the characters the owner copied. It is a popular code library that shipped one extra function last Tuesday.
None of these attacks break cryptography. The private key is not guessed, and it is not brute-forced. It is simply read, lifted off a general-purpose device that the owner also uses for email, browser extensions, pirated software, and job applications. In a year when stolen keys and credentials, not broken smart contracts, drove the largest share of crypto losses, the humblest version of the problem turned out to be the most common: malware that harvests the secret where it already sits in plaintext.
With Bitcoin trading around $85,430 as of 2 October, per CoinGecko, the payoff for reading other people’s keys has rarely been higher. This piece is about that subclass of private-key compromise. Not cracked, not guessed, not taken at knifepoint. Just read.
Guessed, stolen, or just read: where this fits
Private-key compromise splits into a few clean families, and it helps to keep them straight. There is compromise-at-birth, where the key was generated with too little randomness and is simply guessable. There is theft-by-signature, where a victim is tricked into signing a malicious approval and authorizes the loss themselves. There is extraction-by-force, the physical “wrench attack,” where someone with a weapon asks for the recovery phrase in person. And there is the family this analysis is about: extraction-by-malware, where software on the victim’s own machine reads the key, or swaps the destination of a payment, without the owner realizing anything is wrong.
What makes this last family dangerous is that it sidesteps almost every defense the industry has built. Strong entropy does not matter if the finished key is sitting in a Notes file. Multisig and MPC raise the bar for a company treasury, but a retail holder with one hot wallet has one secret on one device. Clear-signing helps you understand what you are approving, right up until a clipboard hijacker changes the destination after you have read it. The malware does not attack the mathematics. It attacks the computer, which was never designed to keep a bearer secret safe from everything else running alongside it.
What an infostealer actually does
An infostealer is commodity malware, usually rented by the week. Once it lands on a machine it runs a fast, broad sweep: saved browser passwords, session cookies and tokens, locally stored API keys, browser-extension wallet data, desktop wallet files, and anything that resembles a seed phrase. The session-token theft is the subtle part, because stolen cookies can let an attacker resume a logged-in exchange or email session from their own machine without ever needing the password or the second factor.
The seed-phrase hunt is the blunt part. Modern families scan text files, documents, screenshots, and clipboard history for strings that match the BIP-39 wordlist, the 2,048-word dictionary that mnemonic phrases are drawn from. A twelve- or twenty-four-word phrase saved in a backup.txt, or screenshotted “just in case,” is not hidden from software that is grepping for exactly that pattern. Chainalysis, summarizing how individual holders lose funds, lists “seed phrases typed into fake sites, malware that siphoned private keys, and browser extensions that quietly drained approved tokens” in the same breath, because to a victim they feel identical: the money simply leaves. The whole sweep is often seconds of activity, after which the malware may delete itself, and the first sign of trouble is an empty wallet.
Browser-based wallets are a particular prize. A hot-wallet extension keeps its keys in an encrypted vault inside the browser profile, and stealers grab that vault wholesale, then try to crack the password offline at their leisure; a weak or reused password turns an encrypted file into spendable funds. The same sweep lifts the autofill database, any saved exchange passwords, and the two-factor seeds some people unwisely keep on the same machine. One infection, in other words, rarely costs only one account.
Lumma Stealer and the malware-as-a-service economy
The clearest picture of how industrialized this has become arrived in May 2025, when Microsoft’s Digital Crimes Unit, the US Department of Justice, Europol, and Japan’s cybercrime center moved against Lumma Stealer, also known as LummaC2. Microsoft, which called Lumma a favored tool of cybercriminals, said it had found more than 394,000 Windows computers infected in a roughly two-month window; the action seized or blocked about 2,300 domains that formed the malware’s backbone, and the FBI tied LummaC2 to at least 1.7 million information-stealing attempts. High on the list of data it was built to lift: crypto wallet seed phrases.
What makes Lumma instructive is the business model. It was sold as a subscription, malware-as-a-service, with tiered pricing and customer support, so the people deploying it rarely wrote a line of code. That is also why takedowns dent the problem without ending it: the infrastructure is cheap to rebuild, and the operators are not the customers. Researchers observed Lumma activity recovering within months of the 2025 action. For a self-custody holder the lesson is uncomfortable: you are not being hunted by a genius, you are being processed by a vending machine that happens to want your seed phrase.
Lumma is one name among many. RedLine, Vidar, StealC, and the macOS-focused Atomic family occupy the same market, and their output is a commodity in its own right: the stolen data is packaged into what criminals call “logs,” bundles of credentials, cookies, and wallet artifacts resold in bulk to other operators. Initial access brokers specialize in getting onto the machine, drainer crews specialize in cashing out, and the person who infected you may never touch your coins. That division of labor is what makes the retail threat so durable, and it is why the individual compromises counted in a single year are better understood as an assembly line than a crime wave.
The clipboard is a weapon
Not every piece of crypto malware wants your key. Some just want your copy-paste. A clipboard hijacker, or “clipper,” watches the clipboard for something shaped like a wallet address and silently replaces it with the attacker’s address in the same format. You copy a withdrawal address, paste what looks right (the first and last characters may even match, if the malware pre-generated a lookalike), and sign a transfer to an address you never chose.
The technique has spread to every platform. Atomic Stealer (AMOS), the dominant macOS infostealer sold as a service, added clipboard hijacking aimed at Mac users; a C++ variant known as “Odyssey” goes further and trojanizes locally installed wallet software such as Ledger Live and the Trezor app, on top of sweeping the keychain, Apple Notes, and documents. The clipper is a reminder that even a perfectly protected key offers nothing if the destination is swapped after you verify it. The only reliable check is the address shown on a hardware wallet’s own screen at signing time, which malware on the computer cannot edit.
ClickFix and the delivery problem
Malware still has to reach the machine, and in 2025 and 2026 the favored trick barely looks like an attack. It is called ClickFix: a web page shows a fake CAPTCHA or a bogus “error” and asks you to “verify you are human,” or to fix a display glitch, by copying a provided command and pasting it into your terminal or the Windows Run box. The command quietly downloads and runs the stealer. Recent campaigns delivered Atomic Stealer to macOS users through fraudulent CAPTCHA prompts, and the same pattern pushes Windows stealers through fake updates and cracked-app pages.
The other delivery rails are familiar but worth naming: malvertising that floats a poisoned download to the top of a search result, fake “AI tool” and game installers, over-permissioned browser extensions, and fake job interviews. That last one has a state-sponsored edge. Andrew Fierman, head of national security intelligence at Chainalysis, has described North Korean operators “embedding themselves within these organizations” to “gather intelligence, manipulate security protocols, and even facilitate insider breaches,” and the same crews run fake-recruiter campaigns in which a “coding test” is really a key-stealing payload. The social engineering is the exploit; the malware is just what gets installed.
A field guide to how keys leave the device
The vectors overlap and combine in practice, a ClickFix page can drop an infostealer that also carries a clipper, but it helps to see them laid out. The table below groups the main routes by which a private key, or a payment, leaves a user’s control in 2026, with a representative case for each.
| Vector | How it works | What it takes | Representative case |
|---|---|---|---|
| Infostealer (rented) | Broad sweep of files, browsers, and clipboard for secrets and BIP-39 strings | Seed phrases, wallet files, cookies, passwords | Lumma Stealer (May 2025 takedown) |
| Clipboard hijacker (clipper) | Swaps a copied address for a lookalike | Redirects an outgoing transfer | Atomic Stealer clipboard module (macOS) |
| Trojanized wallet app | Alters a locally installed wallet client | Keys and transaction targets | AMOS “Odyssey” vs Ledger Live and Trezor |
| Poisoned dependency | Malicious code shipped inside a trusted library | Keys and seeds at use, or swapped addresses | Injective SDK 1.20.21 (July 2026) |
| Fake job interview | Candidate runs attacker code as a test | Full device compromise | DPRK contagious-interview lures |
| ClickFix / fake CAPTCHA | User pastes a supplied command into a terminal | Installs any of the above | Atomic Stealer CAPTCHA campaigns |
When the library betrays you
The two most consequential malware events of the past year were not downloads a victim clicked. They were updates to code that millions of developers already trusted. In September 2025 an attacker phished the maintainer of a cluster of tiny but ubiquitous JavaScript packages, including chalk and debug, through a fake npm support domain, then published malicious versions. Those packages are downloaded collectively more than two billion times a week, which made it, by reach, the largest supply-chain compromise the JavaScript ecosystem had seen. The payload was a browser-side crypto-clipper that hooked into wallet and network calls to rewrite transaction recipients and approval targets to the attacker’s addresses.
And then almost nothing happened. Because the code was caught within hours, and because it went after browser transactions rather than keys at rest, the attackers walked away with roughly $503. Charles Guillemet, chief technology officer at Ledger, who raised the first loud alarm, summed up the strange result: the attack “fortunately failed,” with “almost no victims,” but, he warned, “the immediate danger may have passed, but the threat hasn’t.”
The threat he meant showed up in July 2026, when attackers compromised Injective Labs’ publishing pipeline and pushed a malicious version of its software development kit. This payload did not swap addresses; it stole keys. The code was disguised as telemetry, a function innocuously named trackKeyDerivation() that claimed to collect “anonymized usage metrics,” and it captured private keys and mnemonic seed phrases as developers’ applications generated them, batching the data over a two-second window before sending it to an external server; 18 packages were affected in all. The same trust that makes open source efficient becomes the delivery mechanism: you audited your own code, not the thousand dependencies sitting under it.
What makes this class so hard to stop is the shape of modern software. A single application can pull in hundreds or thousands of transitive dependencies, packages that depend on packages, and any one of them can run code at install time through a postinstall script. A developer who has vetted their direct dependencies still has not read the code three layers down, and a malicious update propagates to everyone who runs a routine install before anyone notices. Pinning exact versions with a lockfile, disabling install scripts by default, and keeping key material off the machines that build software all help, but they shrink the blast radius rather than close it. The uncomfortable implication is that a careful user can be robbed through a mistake made by someone they have never heard of.
Drainers and stealers are two different robberies
It is worth separating two things that get lumped together as “crypto hacks,” because they call for different defenses. A wallet drainer depends on you signing something: a malicious token approval, a Permit or Permit2 signature, a “claim your airdrop” transaction. The key is never stolen; your own signature authorizes the loss. That is the world the phishing economy lives in, and by one measure it is shrinking. Scam Sniffer counted about $83.85 million lost to wallet-drainer phishing in 2025, down 83 percent from roughly $494 million in 2024, across about 106,000 victims, with the average loss per victim falling to around $790 and only eleven incidents above $1 million all year, against thirty the year before. Better wallet warnings, transaction previews, and the collapse of some major drainer kits pushed those figures down.
Stealers and clippers are the other robbery, and they are not shrinking the same way. Here you do not knowingly sign anything: the malware either reads the key and spends later on its own schedule, or rewrites the destination of a transfer you did intend to make. A hardware wallet and a careful eye defeat most drainers, because you can simply refuse to sign. They do not automatically defeat a clipper, because the transaction you approve looks correct unless you verify the address on the device itself, and they do nothing for a seed phrase already sitting in a cloud note. The distinction matters because it tells you which control actually helps; it is also why understanding what your wallet is really empowered to do when you sign has become part of basic security hygiene.
The quiet epidemic, by the numbers
Zoom out and the retail picture is stark. Chainalysis logged roughly 158,000 personal-wallet compromises in 2025, hitting about 80,000 individual victims and accounting for around $713 million in losses, with the number of individuals affected roughly tripling since 2022. These are not the heists that get forensic write-ups; each loss is small, and the victim is usually alone with it.
The headline share can mislead, so it is worth being precise. Personal wallets made up about 44 percent of all stolen value in 2024, up from 7.3 percent in 2022, but that share fell back toward 20 percent in 2025, not because fewer people were robbed but because a handful of enormous institutional thefts, led by the roughly $1.5 billion Bybit heist, dominated the dollar count. Of the 2025 total of about $3.4 billion in stolen crypto, Chainalysis attributed close to $2 billion to North Korea-linked actors. The institutional cases are the ones with the post-mortems, like the $285 million admin-key theft at Drift; the retail grind, measured in thousands of dollars at a time, rarely gets one, which is part of why it persists.
Why cold storage is necessary but not sufficient
Moving to a hardware wallet is the single highest-impact step most holders can take, and nothing here argues against it. The private key is generated and held inside a secure element, never touches the internet-connected computer, and transactions are signed on the device. That alone defeats the core infostealer move, reading the key off the disk, because the key is not on the disk.
But three gaps survive, and they are precisely the ones 2026’s malware exploits. First, the clipper: if you verify a destination on your computer screen and the malware swapped it, the hardware wallet will faithfully sign the wrong transfer, so the full address has to be read on the device’s own screen, every time. Second, the companion app: a trojanized desktop client can misrepresent what you are approving unless you confirm the details on the device. Third, and most common, the recovery phrase: a hardware wallet protects the key, but if you photographed your seed phrase or typed it into a note or a password manager, you have recreated the plaintext secret that stealers hunt for. Guillemet’s advice during the npm scare, verify every transaction on the device if you use a hardware wallet, and avoid on-chain transactions entirely if you do not, is the whole doctrine in a sentence.
Defenses that actually move the needle
The controls that work share a premise: treat the computer and the phone as already hostile. The table maps the main threats to the defense that most directly neutralizes each, along with the risk that remains even when you do it right.
| Threat | Primary defense | Why it works | Residual risk |
|---|---|---|---|
| Infostealer reading the seed | Hardware wallet; never digitize the phrase | Key and seed never exist in readable form on a networked device | Theft or loss of the physical backup |
| Clipboard hijacker | Verify the full address on the device screen | The display sits outside the infected computer | Haste; skipping the check |
| Trojanized wallet app | Confirm every detail on the hardware screen | On-device confirmation is authoritative | Convincing fake update prompts |
| Poisoned dependency | Separate signing from the dev machine; pin versions | Limits what a bad package can reach | A zero-day in a trusted library |
| Malicious signature (drainer) | Simulate transactions; revoke stale approvals | You can decline before anything is signed | Signing fatigue |
| ClickFix / fake CAPTCHA | Never paste a command you did not write | Breaks the delivery step entirely | A single careless moment |
Translated into habits, the doctrine is short and mostly behavioral:
- Keep meaningful balances on a hardware wallet, and only spending money in a hot wallet.
- Keep the seed phrase on paper or metal, offline; never photograph it, type it into a computer, email it, or store it in a cloud note or password manager. If it has ever touched a networked device, move the funds to a freshly generated wallet.
- Verify the full receiving address on the hardware device’s screen at signing time, not on the computer.
- Use a wallet that simulates transactions and shows human-readable details, and revoke old token approvals periodically.
- Never paste a command into a terminal or the Run box because a web page told you to; no legitimate CAPTCHA works that way.
- Install software only from official sources, and be suspicious of search-ad downloads, cracked apps, and coding tests sent by strangers.
- Prefer app-based or hardware two-factor over SMS, assume session cookies can be stolen, and log out of exchange sessions you are not using.
None of this is exotic, which is the point. The malware is cheap and abundant; the discipline is the scarce resource.
Why the quiet robbery keeps working
Step back from the individual cases and one asymmetry explains the pattern. A private key, or the seed phrase behind it, is a bearer secret: whoever reads it controls the funds, with no second step, no reversal, and no central party to appeal to. Every other control in self-custody exists to keep that secret away from software, which is why the attacks that win are the ones that find it already copied somewhere it should not be: a note, a screenshot, a password manager, a clipboard, a config file in a code repository.
Detection barely exists at the individual level. There is no fraud department to flag an unusual transfer, no antivirus alert when a legitimate-looking app reads a text file, and no chargeback once a transaction confirms. Many victims learn they were compromised only when they open a wallet and the balance is zero, sometimes weeks after the malware finished its work and deleted itself.
The economics do the rest. Infostealers rent for the price of a streaming subscription, delivery is automated, and the payout is instant and irreversible, so an attacker does not need a high success rate to profit. Defenders have to be right every time, on every device, indefinitely. It is the same logic that drives the institutional heists we cover, from the governance-layer blind-signing at Drift to bridge exploits that turned on a single leaked credential, scaled down to one laptop. The difference is that an individual has no incident-response team, which is exactly why the quiet version of the robbery is the one that keeps working.
Who polices this, and who pays
When a protocol’s treasury is drained there is at least an organization with lawyers, a forensics firm, and sometimes a recovery negotiation. When an individual’s hot wallet is emptied by a stealer, there is usually nobody. US securities regulators oversee intermediaries and issuers, not the malware on a laptop; the Securities and Exchange Commission can hold an exchange to custody and disclosure standards, but it does not reimburse a self-custody holder who pasted a swapped address. The agency’s bandwidth for crypto has been its own running story this year, with a thinned-out commission (we have written about the two-person SEC and its stretched docket). Consumer malware cases fall instead to the FBI’s Internet Crime Complaint Center, the Secret Service, and CISA, which can occasionally claw funds back but rarely at retail scale.
That leaves the loss, and the tax question. For US individuals a stolen-crypto loss is hard to deduct, because the 2017 tax law suspended most personal casualty and theft-loss deductions through 2025, and whether a particular theft qualifies as an investment loss is fact-specific and worth professional advice (we have mapped the wider self-custody reporting gaps in our look at DeFi taxes and the frontier no broker reports). The blunt summary is that in self-custody you are your own custodian, your own security team, and your own insurer. The malware economy is built precisely on how many people have not yet absorbed that.
Frequently Asked Questions
Can malware steal crypto from a hardware wallet?
Not the key itself, if the device is genuine and you confirm transactions on its screen, because the private key stays inside the secure element and never reaches your computer. But malware on the connected computer can still swap a destination address or misrepresent a companion app, so always verify the full address on the hardware wallet’s own display and never store your recovery phrase on any networked device.
What is an infostealer, and how does it find my seed phrase?
An infostealer is commodity malware that sweeps an infected device for valuable data: saved passwords, session cookies, wallet files, and seed phrases. Modern families specifically scan text files, screenshots, and clipboard history for strings matching the BIP-39 wordlist, so a recovery phrase saved in a note or photographed on your phone is exactly what they are built to find.
What is a clipboard hijacker, or clipper?
A clipper is malware that watches your clipboard and silently replaces a copied wallet address with the attacker’s address in the same format, sometimes with matching first and last characters. You paste what looks correct and send funds to the thief. The only reliable defense is to verify the entire address on a hardware wallet’s screen before signing.
Are npm and other software supply-chain attacks a risk to ordinary users?
Yes, indirectly. When a trusted code library is compromised, as with the September 2025 chalk and debug packages or the July 2026 Injective SDK, the malicious code reaches every application built on it. Some variants swap addresses in the browser, while others steal keys as apps generate them. Using a hardware wallet and confirming transactions on the device limits the damage.
I think malware drained my wallet. What should I do?
Assume the device is compromised. From a different, clean device, move any remaining funds to a brand-new wallet with a freshly generated seed, revoke outstanding token approvals, and change passwords and sessions for your exchanges and email. Report the theft to law enforcement (in the US, the FBI’s IC3) and keep records for tax and any recovery efforts, and do not reuse the old seed phrase.
Marcus Feld is a security correspondent at HOGE Wire, covering wallet security, exploits, and the economics of crypto crime.