
What happened
According to Cointelegraph, a fake version of the Claude app is linked to RevStealer, which harvests crypto wallets and other data.
Why it matters
The report links a fake Claude app to malware affecting crypto wallets, browser credentials, and personal files, though the scale of the incident remains unconfirmed.
According to a report by Cointelegraph, a fake desktop version of the Claude app is spreading the RevStealer malware. The malware targets more than 50 crypto wallets, as well as browser passwords and cookies, messenger data, and select documents.
The practical risk lies in the fact that a single piece of malware affects not only crypto assets but also other data on the device. However, the available package contains only a synopsis of the publication, without the full text or independent confirmation; therefore, details regarding the attack mechanics, victims, and scale require verification.
Confirmed facts
- Cointelegraph reported the spread of the RevStealer malware via a fake Claude desktop app.
- According to the publication synopsis, RevStealer targets more than 50 crypto wallets.
- The report also cites browser passwords and cookies, messenger data, and select documents.
- The provided evidence has a status of metadata_only and represents a publisher metadata synopsis rather than the full text of the material or independent confirmation.
Context
The source is a Cointelegraph publication from 1 September 2026. The package includes one independent source, but its content is available only as a metadata synopsis.
What remains unknown
- How many devices and users are actually affected?
- How was the fake Claude app distributed?
- Which specific crypto wallets are included in the claimed list?
- Are there confirmed cases of asset theft or other data breaches?
- Have Claude developers or cybersecurity experts confirmed this information?
Editorial context
Confidence: medium
The likely consequence is an increased risk of compromising crypto wallets and local user data for those who install counterfeit applications. The next verifiable signal will be the publication of technical details, confirmation from developers, or data on victims. Substantial uncertainty remains due to the single source and the metadata format.