Crypto RAT Malware Drains $235K in 48 Hours
A suspected crypto RAT has been linked to $235K in losses within 48 hours as attackers reportedly hijack active sessions & drain user wallets.
A suspected remote access trojan has been linked to more than $235K in cryptocurrency losses over roughly 48 hours, raising fresh concerns about malware that targets users not by directly exploiting blockchain protocols, but by compromising the devices and sessions through which crypto is accessed.
The incident surfaced publicly on September 20 after Coin Bureau warned that hundreds of users had allegedly lost crypto holdings after attackers hijacked active sessions. The alert said the malware was targeting crypto holders, while the method used to infect victims remained unknown.
How the Reported $235K Malware Campaign Works
Reports surrounding the incident describe the malware as a remote access trojan, or RAT, a type of malicious software designed to give an attacker remote visibility or control over an infected computer. According to reports published after the alert, the campaign allegedly combines capabilities such as credential theft and session manipulation.
Instead of requiring an attacker to break a wallet's cryptography, the malware may compromise the environment from which the victim is already interacting with an exchange, wallet or financial service. Session hijacking is particularly concerning because authentication does not necessarily end when a user enters a password.
Browsers and applications commonly maintain authenticated sessions using cookies or tokens. If malware can obtain or manipulate those sessions, attackers may be able to interact with services as if they were the legitimate user.
Crypto users have already faced multiple forms of malware distribution this year. EtherWorld previously reported how Lazarus-linked malware targeted Mac users through fake meeting links and malicious instructions capable of stealing browser credentials and wallet information.
More recently, a $90K crypto loss linked to compromised Chrome extensions demonstrated how browser-level compromise can expose passwords and seed phrases without any failure occurring at the blockchain layer itself.
⚠️ALERT: A malware targeting held crypto has STOLEN over $235,000 in the past 48 hours.
— Coin Bureau (@coinbureau) September 20, 2026
HUNDREDS of victims have lost ALL their CRYPTO holdings after a remote access trojan let attackers hijack their sessions.
How the malware is reaching victims remains UNKNOWN. pic.twitter.com/nGqq9aVQJB
What the Onchain Evidence Actually Shows
Unlike many malware reports that rely entirely on victim testimony, this incident includes a specific Ethereum address that can be examined publicly. The address 0x7028...5887 appeared in warnings as early as September 18, before the broader September 20 reports gained traction.
Blockchain-indexed data nevertheless shows multiple assets flowing into the address. One analysis found approximately $130,000 worth of USDC and USDT arriving from 13 addresses during a September 19 observation window, alongside other token movements.
The same analysis noted that the wallet's total displayed portfolio value of approximately $235,747 was not itself equivalent to a verified victim-loss calculation. A wallet may receive funds from multiple sources, assets may be swapped or bridged, and addresses may participate in activity that has not yet been fully attributed.
EtherWorld's coverage of the More Markets incident showed how initial loss estimates can change dramatically once blockchain security firms complete deeper tracing. Likewise, August 2026's major DeFi incidents demonstrated how early exploit figures, affected assets and attack paths frequently evolve during investigations.
Why Device & Session Attacks Are Growing
Crypto security discussions often focus on smart contract audits, validator security and protocol vulnerabilities, but attackers do not need to break Ethereum itself if they can compromise the person controlling an account. That has increasingly made the user's device one of the most attractive attack surfaces.
A phishing campaign covered by EtherWorld earlier this year drained $585K from Ethereum users after victims were tricked into signing malicious approvals. Another address poisoning attack caused a user to lose more than $100K without compromising the underlying wallet software.
Similarly, India's cybercrime authorities have warned about fake Trust Wallet verification websites designed to convince users to connect wallets and approve dangerous permissions. Even hardware wallets do not completely eliminate this problem.
A hardware device can prevent private keys from being directly extracted from an infected computer, but a compromised interface can still attempt to convince users to approve malicious transactions. EtherWorld explored this distinction following the COLDCARD security incident, which highlighted how assumptions around self-custody can break down when wallet-generation or operational security fails.
Earlier this month, an Ethereum Safe lost $7.73M in rsETH after an authorised third-party module was exploited, while a previous Gnosis Pay incident involved a vulnerability in the Zodiac Delay Module.
‼️ More than $230,000 drained from hundreds of wallets in the last 2 days
— VAL (@osint_based) September 20, 2026
Attack vector is still unknown, probably session hijacking
Amounts from each victim are mostly small, but the total is already big
Most of the funds are sitting in $USDC
Attacker wallet:… pic.twitter.com/ZqA2TPEOJy
What Crypto Users Can Do to Reduce the Risk
Because the malware distribution method in the current campaign has not been publicly identified, users should be cautious about treating any single defensive step as sufficient. The most important assumption is that a potentially compromised device should not be trusted simply because wallet passwords have been changed.
If a RAT retains access to the operating system, browser or authenticated sessions, new credentials could potentially be captured again. Users who suspect compromise should avoid conducting sensitive crypto activity on the affected machine until it has been properly examined or rebuilt.
Users should be especially cautious about installing crypto applications, browser extensions or software from links distributed through Telegram, Discord, email or social media. A recent SafePal customer data breach demonstrated how even leaked contact information can create opportunities for highly convincing targeted phishing attempts.
EtherWorld's security coverage has included compromised private keys affecting legacy Ethereum wallets, social engineering operations exposed in ZachXBT's alleged $5M crypto theft investigation and repeated protocol exploits across DeFi.
For now, the most important unanswered question surrounding the reported $235K campaign is how the malware actually reaches victims. Until researchers identify the infection vector and malware family, the scope of the operation remains difficult to establish.
To promote your Web3 articles, events, and projects, you may reach out anytime via EtherWorld PR for submissions and collaboration.
Related Articles
- Hundreds of Wallets Drained Across EVM Chains, ZachXBT Warns
- Ethereum Phishing Attack Drains $585K in 11 Hours
- Legacy Ethereum Wallets Exploited as $800K Gets Drained
- Crypto User Loses $100K to Address Poisoning Scam
- ZachXBT Exposes Alleged $5M Crypto Scam
To follow blockchain news, track Ethereum protocol progress, and read our latest stories, subscribe to our weekly today.
Join the EtherWorld & Avarch Internship Program and build your career in blockchain, content, social media, video, podcast editing, or operations. Send your resume and brief introduction to contact@etherworld.co.
Disclaimer: The information contained in this website is for general informational purposes only. The content provided on this website, including articles, blog posts, opinions, & analysis related to blockchain technology & cryptocurrencies, is not intended as financial or investment advice. The website & its content should not be relied upon for making financial decisions. Read full disclaimer & privacy policy.
To stay updated on blockchain news, Ethereum protocol progress, and our latest stories, subscribe to our weekly digest and YouTube channel for ELI5 content.
To promote your Web3 articles, events, project updates, and Press Releases, reach out anytime via EtherWorld PR for submissions and collaboration. For other queries, email contact@etherworld.co.
If you’d like to support our work, share the content and consider donating at avarch.eth.
Join our community on Discord and follow us on Twitter, Facebook, LinkedIn & Instagram.