Criminals are using fake versions of Anthropic’s Claude app to target bitcoin and cryptocurrency wallets, cybersecurity researchers have warned, as interest grows in the newly released Fable 5.1 and Mythos 5.1 artificial intelligence models.
Researchers at Morphisec identified a malicious application called “Claude Opus 5 Free Desktop”, which was distributed through Github. The software claimed to offer free access to a paid AI model, but instead attempted to install a Windows infostealer on victims’ computers.
The malware is designed to search for data linked to cryptocurrency wallets, as well as browser databases, password managers and virtual private network configurations. According to Morphisec, the crypto-related applications targeted include Atomic, Armory, Cake Wallet, Sparrow, Wasabi, Ledger Wallet, Trezor Suite, Electrum and others.
It is not yet clear how successful the campaign has been. Ledger Wallet and Trezor Suite, for example, are interfaces used to manage hardware wallets rather than the wallets themselves.
Morphisec said the malware copies wallet files in their existing form, with the possibility that they are compressed before being uploaded.
“No product-specific password recovery, seed extraction or encrypted-wallet decryption occurs at this stage: Revstealer reliably steals the encrypted wallet material and configuration, while unlocking it depends on processing not demonstrated in this sample,” the researchers said.
The theft of wallet files does not necessarily give an attacker immediate access to the funds. However, a weak passphrase, reused login details or a password taken from a password manager could allow criminals to gain control of the assets.
The threat also extends beyond cryptocurrency. One user reported that their computer was infected with Revstealer after downloading software they believed was legitimate from Github.
“Despite the infection, their installed security product reportedly did not initially detect the malicious executable. The victim later reported that several online accounts, including Microsoft and EA accounts, had been compromised, illustrating how quickly an infostealer infection can lead to credential and session theft,” the researchers said.
Revstealer is intended to avoid detection and is capable of deleting itself, making it harder for victims and security teams to identify and investigate an infection.
Morphisec said the fake Claude application demonstrated that demand for AI software had become “a first-class social engineering surface.” In other words, the popularity of new AI tools is giving criminals another way to persuade people to download malicious files.
The researchers warned that similar scams could soon be aimed at users seeking free or early access to Fable 5.1 and Mythos 5.1, which were released on 1 September.
Fable 5.1 is generally available, while Mythos 5.1 can be accessed only through Anthropic’s trusted programmes. That restricted availability could make Mythos 5.1 particularly attractive to scammers offering supposed “exclusive access” to Anthropic’s most capable model.
Users looking for AI applications should therefore be cautious about download links and offers that promise free access to paid or restricted services, particularly when the software is hosted through unofficial channels.
This week, Numa Lunah, co-founder of Refi Hub, explained that he had been compromised after following a download link delivered…
