Subscribe to our Telegram channel!

Hackers have learned how to steal cryptocurrency through Telegram sessions without cracking passwords

12:58 pm, July 20, 2026

Researchers have discovered malware that collects Safari cookies, Apple Notes, and browser extension data, and then uses the stolen passwords to access crypto wallets and steal seed phrases. What sets this virus apart is that it doesn’t just intercept passwords; it collects a full set of data sufficient to completely take over the victim’s account.

Crypto investors often store browser and desktop wallets, hardware wallet apps, notes containing seed phrase hints, and active messenger sessions all on a single device. Once such a device is infected, attackers cross-reference all this data and gain full access to the victim’s digital assets.

One of the malware’s most dangerous features is its ability to copy active Telegram sessions. With this data, hackers can restore a session on another Mac device without entering a phone number, verification code, or two-factor authentication password. Two-factor authentication is rendered useless in this scenario, as the attacker is already using a trusted local session. Once they gain access to the account, hackers can read messages, impersonate the victim, and spread malicious links among the victim’s contacts.

The program specifically targets Exodus, Atomic, Electrum, Wasabi, and Monero wallets, as well as the Ledger Live and Trezor Suite hardware wallet apps. In addition, it searches for wallet data in clients running full nodes: Bitcoin Core, Litecoin Core, Dash Core, and Dogecoin Core. After stealing the files, the attackers can decrypt them offline using passwords from the compromised device, meaning the breach does not necessarily occur immediately.

Separately, the malware is capable of replacing the original Ledger and Trezor applications with counterfeit versions. The unsuspecting user enters their seed phrase into the fake interface, after which the attackers gain full control over the assets—without any technical compromise of the hardware wallet.

Cybersecurity experts recommend that anyone who suspects an infection immediately close all active sessions in Telegram, set up a new login, and change their two-factor authentication password. A new seed phrase should be generated exclusively on a clean device, and crypto assets should be transferred to addresses that were not created on the compromised device. Storing passwords for crypto platforms and personal correspondence on the same device is strongly discouraged.

Meanwhile, experts have also reported the discovery of the OkoBot malware, which steals login credentials and seed phrases from crypto wallets. According to their findings, OkoBot infiltrates the Trezor Suite, Ledger Wallet, and Ledger Live applications—meaning that attacks on users of hardware wallets are becoming increasingly widespread.

BTC

$65,078.12

1.17%

ETH

$1,909.29

2.28%

BNB

$572.40

0.69%

XRP

$1.11

1.72%

SOL

$77.94

2.04%

All courses
Show more