A malicious desktop application impersonating Anthropic's Claude AI assistant has emerged as a vector for cryptocurrency theft. The fake Claude app distributes RevStealer, a sophisticated information-stealing malware that targets more than 50 cryptocurrency wallets while simultaneously harvesting browser passwords, cookies, messaging data, and selected documents.

RevStealer operates as a multi-purpose credential harvester. It extracts data from popular crypto wallets including MetaMask, Trust Wallet, Phantom, and others across the targeted 50-plus wallet ecosystem. The malware also exfiltrates sensitive browser data, making it effective at capturing login credentials, session cookies, and authentication tokens that could grant attackers access to exchange accounts, email addresses, and other crypto-adjacent services.

The distribution method leverages social engineering at scale. Users searching for Claude desktop applications or visiting third-party download sites encounter the compromised installer. Since Claude is a widely-used AI tool, particularly among technical users and developers who overlap significantly with crypto participants, the malware benefits from high-intent traffic. Victims believe they are installing legitimate software from Anthropic.

The targeting of both wallets and browser data reveals a comprehensive theft strategy. Attackers harvest wallet recovery phrases, private keys, and account credentials through the wallet extraction vectors. Simultaneously, they vacuum browser data including saved passwords and cookies, which often contain authentication tokens for exchange accounts, email accounts linked to wallets, and cloud storage services. This dual approach maximizes the attacker's ability to compromise multiple layers of a victim's digital assets and accounts.

RevStealer's focus on "selected documents" adds another layer to the threat. Rather than indiscriminately copying all files, the malware intelligently targets specific document types. This typically includes text files, PDFs, and spreadsheets that commonly contain seed phrases, private keys written down, two-factor authentication backup codes, or exchange API keys. This selectivity suggests the malware developers understand the crypto security landscape and how users store sensitive information.

The attack vector highlights persistent gaps in endpoint security awareness within crypto communities. Many users remain willing to download applications from alternative sources without verification. Official Anthropic channels recommend installation only through authorized distribution methods, yet the existence of convincing fakes indicates some users either miss these warnings or lack sufficient skepticism about third-party app sources.

Anthropic has not publicly released an official desktop client for Claude at the level of complexity this malware assumes. This gap between user demand for a native desktop application and official supply creates an opening for malicious actors to fill with convincing counterfeits.

The incident underscores critical security practices for crypto users. Hardware wallets provide isolation from potentially compromised systems and represent the strongest defense against RevStealer-class malware. For those using software wallets, recovery phrase storage on air-gapped devices remains essential. Browser-based wallet extensions face inherent risks from system-level malware, making this threat particularly relevant to MetaMask and similar browser wallet users who represent the largest segment of retail crypto participants.

Organizations within the crypto space should audit download sources users access. Phishing links directing to malware distribution sites require reporting to platforms and security vendors. Web3 security firms have begun tracking RevStealer distribution infrastructure to disrupt deployment chains.