Lisbon · Wednesday, 22 Jul 2026 NB Edition · Nº 086
← Back to news
Cibersegurança · Criptomoedas NB-L086

Your wallet's official app asked for the 24 words that unlock all your money

A module called SeedHunter injects a fake page inside Ledger Live and Trezor Suite and asks for the 24 words the moment you plug in the device. The hardware wallet did not fail, the screen you read the request on did.

Your wallet's official app asked for the 24 words that unlock all your money
FIG. NB-L086 · Cibersegurança · Criptomoedas

You plug your crypto wallet into the computer, open the app you always use, and it shows you a recovery screen asking for the 24 words. The layout is right, the timing is right, it appears the moment you connect the device. That is not your wallet talking to you, it is a module called SeedHunter, described on 15 July by Kaspersky's GReAT research team in a report on OkoBot, a set of more than twenty malicious programs working together on a Windows machine.

What matters here is not the theft, it is where it happens. The hardware wallet was not defeated, nobody broke the cryptography or opened the device, and the private key stayed exactly where it has always been. The attacker simply changed the screen on which you read the request, and that is where these campaigns win, in the window you trust without thinking.

The request shows up inside the genuine app

SeedHunter watches running processes and injects itself into Trezor Suite, Ledger Wallet and Ledger Live. Because those apps are built on Electron, the technology that assembles desktop software out of browser parts, the implant can hook the internal functions that draw the windows and add a page the app never had, with a different layout for each wallet it identifies. When it is set to wait, it runs periodic USB scans filtered by vendor and product identifiers, and only fires the prompt once it sees the device connected, which is the exact moment you are expecting to interact with it. The device's own screen shows nothing, because no legitimate request ever reached it.

Ledger support has been saying the same thing for years, it never asks for your 24 words and there is never a good reason to type your recovery phrase into a computer. It reads like boilerplate until the day the window doing the asking is the official one.

Taking your savings is only half the job

The wallet module is one of more than twenty. The same toolkit takes a screenshot every five minutes, copies whatever passes through the clipboard, and watches a list of over 100 programs, among them software wallets such as Exodus and password managers such as KeePassXC and 1Password, recording video of the window and logging keystrokes when it recognises one of them. It also installs hidden browser extensions and creates an account in the remote desktop group, keeping an SSH tunnel, an encrypted remote administration channel, that forwards that port every hour. Once it has your crypto, it still owns the house.

Entry comes through two unremarkable routes. One is ClickFix, the scam that shows you a fake error and talks you into pasting a command into the Windows console to "fix" it. The other is tampered software on GitHub, and the report's example is a cruel one, a repository posing as Microsoft's SQL Server Management Studio that ranked at the top of the results for the query "SSMS" and delivered the genuine Audacity with an implant buried in one of its libraries.

Kaspersky's telemetry counts hundreds of victims across more than 25 countries, concentrated in Brazil, Vietnam, Canada, Mexico and Türkiye. Dmitry Galov, who heads the Russia and CIS unit of the research team, says the campaign has been running for more than a year and was still under way in July 2026.

Portugal is not on that list, which means very little. On 23 June the Leiria district command of the Portuguese public security police warned about two victims in Caldas da Rainha who lost roughly 140,000 euros between them to crypto investment fraud, and one step of the scheme was a request for remote access to their computers. Same move, asked for by hand instead of installed by malware.

How to protect yourself

  • The recovery phrase is written once, on the device itself. If the request appears on your computer screen it is fraud, with no exceptions and regardless of how the window looks.
  • Always confirm the operation on the device's small screen, the one surface the attacker does not control.
  • Never paste a command a web page told you to copy, however convincing the error it showed you.
  • Download software only from the vendor's official site, never from the first search result.
  • If you suspect the machine, treat it as compromised and move the funds from different hardware, with a new phrase.
  • Look for OkoBot's traces, a scheduled task named "Apple Sync", the file hwid.dat under %PROGRAMDATA%, unknown accounts in the Remote Desktop Users group, and SSH connections leaving an ordinary workstation.

A recovery phrase is like evidence in a case, it is only worth something while nobody has touched it, and the chain of custody breaks at the weakest point it passed through. The device you bought still does its job and shows you the truth on a tiny screen nobody can redraw. Get used to believing that one, rather than the one where it is more comfortable to read.

Sources: Securelist, Kaspersky GReAT, The Hacker News, Diário de Notícias.

#StaySafe
🙏🖖

Keep reading

More stories

See all →
Mac malware clears Apple's security check to steal passwords and crypto wallets
Cibersegurança · macOS

Mac malware clears Apple's security check to steal passwords and crypto wallets

A macOS data stealer, CrashStealer, reached victims carrying Apple's notarization seal and cleared Gatekeeper without al...

4 MIN · 15 Jul 2026 · NB-L080
It poses as your phone's antivirus to steal your bank, your SMS codes, and your crypto
Cibersegurança · Android

It poses as your phone's antivirus to steal your bank, your SMS codes, and your crypto

A new Android trojan, Rokarolla, targets 217 banking and crypto apps and gives the attacker near-total control of the ph...

4 MIN · 18 Jun 2026 · NB-L042
The malware that asks you to tap your own card
Malware · Fraude Online

The malware that asks you to tap your own card

A GitHub repository hosted 56 fake banking apps. The NFCShare malware does not want your password: it tricks you into ta...

4 MIN · 9 Jun 2026 · NB-L023
Weekly · No spam

The Boletim

A weekly summary of the cybersecurity, AI and technology stories that matter — written to be read in five minutes.

Unsubscribe with one click, any week.
BRI assistant

Quer saber sobre um projeto, um serviço ou uma notícia recente? Pergunte. Conheço todo o conteúdo deste site.