How does macOS malware harm cryptocurrency users?
An information-stealing malware targeted at macOS systems that can compromise the asset security of cryptocurrency users by hijacking Telegram desktop sessions and collecting passwords, authenticated sessions, wallet databases, and browser extension data. The malware steals information from databases of macOS keychains, Safari cookies, Apple memos, Telegram desktops, and dozens of cryptocurrency wallets. After obtaining this data, attackers can use stolen passwords and local session files to log in to their accounts, or try to crack the wallet database offline.
This attack method is particularly dangerous because it connects multiple attack methods into a complete attack chain. The malware does not rely on a single wallet vulnerability, but collects everything that might help attackers escalate from device access to account takeover, wallet hacking, or recovery phrase theft. This puts the threat far beyond regular password theft. Cryptocurrency users typically store browser wallets, desktop wallets, hardware wallet applications, memos, mnemonic reminders, and instant messaging sessions on the same device. Once a device is infected, attackers may correlate this data and gradually build a path to asset theft.
Why are Telegram sessions a high-value target?
The malware is capable of copying authenticated Telegram desktop session data, allowing an attacker to resume sessions on another Mac device without going through the normal login process. Tests have shown that attackers used stolen Telegram desktop session data to resume sessions without entering a mobile phone number, Captcha, or a two-factor authentication password. This means that in this scenario, Telegram's two-factor authentication mechanism cannot fully protect users. Instead of initiating a new login request, the malware reuses an already trusted local session.
This poses a significant risk for cryptocurrency users, as Telegram is widely used in exchange customer service, trading groups, project communities, over-the-counter trading discussions, and private communications involving wallets. Once an attacker obtains an active Telegram session, they may pretend to be the victim, read private conversations, identify wallet holdings, launch attacks against counterparties, or push malicious links through a trusted account. This risk is not limited to infected users themselves, but may also spread further through professional networks and cryptocurrency communities that rely heavily on Telegram for real-time communications.
Investor tip
This attack shows that cryptocurrency security cannot rely solely on two-factor authentication or hardware wallets. If a local trusted device is compromised, an attacker can attack sessions, wallet files, passwords, and recovery processes simultaneously.
Which wallets and apps are at risk?
Target wallets for the malware include software wallets such as Exodus, Atomic, Electrum, Wasabi and Monero. It also searches for data related to hardware wallet applications such as Ledger Live and Trezor Suite. In addition, the malware searches wallet data stored by full-node clients, including Bitcoin Core, Litecoin Core, Dash Core, and Dogecoin Core. This widespread targeting suggests that attackers are not just focusing on ordinary retail wallet users, they are also looking for users who run wallet infrastructure locally or maintain legacy wallet databases on machines.
Once wallet databases are stolen, attackers can use passwords obtained from infected devices to attempt to decrypt those databases offline. This is a key risk because instead of immediately cracking wallet encryption on the victim's machine, an attacker can move the stolen files elsewhere and subsequently test the password. The malware could also replace legitimate Ledger and Trezor applications with fake versions, tricking users into entering recovery phrases. This approach targets the user's recovery process, not the hardware wallet itself. If a user enters mnemonic words in a fake application, an attacker can control the assets of the hardware wallet itself even if it has never been compromised.
How should affected users respond?
Users who suspect that the device has been infected should treat this Mac device as an untrusted device. The first priority is to terminate existing Telegram sessions, establish a new trusted login, and change the Telegram dual authentication password and the Telegram desktop password. In terms of wallet security, users should avoid entering recovery phrases, passwords, or hardware wallet credentials on affected machines. New recovery phrases should only be generated on clean devices and transfer assets to new addresses that have not been created or managed on the infected system.
This incident has also brought broader operational lessons to cryptocurrency investors and institutions. Sensitive wallet operations, exchange access, private communications, and recovery information should not all rely on the same day-to-day device. Isolation is crucial. Using a separate clean device for wallet management, strictly validating applications, limiting the number of browser extensions, and regularly checking sessions can effectively reduce the damage caused by malware to major workstations. For exchanges, wallet providers and institutional trading desks, the threat also provides new reasons for strengthening endpoint control on macOS devices. The attack chain does not rely solely on the weaknesses of the cryptocurrency itself, it leverages local credentials, session files, and user behavior. This makes equipment security, employee training, and recovery phrase management core aspects of digital asset risk management.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC
DASH
DOGE
LTC
XMR