Fake Claude app is stealing crypto wallets and browser passwords

If you downloaded something called “Claude Opus 5 Free Desktop” recently, stop what you’re doing. Cybersecurity firm Morphisec has reported that a fake Claude desktop application is actively distributing RevStealer, a Windows malware strain built to quietly drain crypto wallets, grab browser passwords, and harvest messaging data before you notice anything is wrong.

The fake app impersonates Anthropic, the company behind the real Claude AI assistant, and promises free access to Claude Opus 5. It’s a simple but effective lure. People want free access to premium AI tools. Attackers know this, and they’ve built an entire fake project around that desire. Morphisec says RevStealer was previously distributed through GitHub repositories and game cheat sites, but this Anthropic impersonation is the most sophisticated delivery method seen so far.

What makes RevStealer particularly nasty is how thoroughly it covers its tracks. It targets browser databases, cookies, saved passwords, VPN and remote-access configurations, messaging app data, screenshots, and selected documents. It also goes after more than 50 cryptocurrency wallets specifically. That’s not a bug sweep. That’s a deliberate, targeted theft operation.

The malware also has a self-preservation mechanism that should concern anyone who thinks their security software will catch it. Before doing anything harmful, RevStealer checks whether it’s running on a real user machine or inside a security researcher’s analysis environment. It looks at available memory, processor core count, hostname, username, and graphics hardware. It also watches for the kind of debugging delays that analysts use when studying malware. If anything seems off, it stops and does nothing. This means it may sail past automated detection systems entirely, only activating on genuine user devices.

If the system passes those checks, the malicious payload is decrypted, saved under a random filename, and executed quietly in the background. By the time anything looks suspicious, the damage is already done.

This fits into a much broader pattern of attackers using trusted brand names to distribute malware. AI tools are the new bait. Anthropic, OpenAI, and similar companies have built massive public profiles in a short time, and millions of people are actively looking for ways to access their products, sometimes for free. Fake apps mimicking these brands are a logical next step for attackers, and the crypto community is a prime target because the potential payout is immediate and often irreversible.

RevStealer isn’t the only threat doing this right now. Kaspersky recently identified a separate malware framework called OkoBot, also aimed at cryptocurrency investors. OkoBot can harvest wallet files, inject malicious browser extensions, capture wallet application windows, and steal credentials. Two major infostealer campaigns targeting crypto users in close succession is not a coincidence. It reflects how valuable these targets have become.

For users, the practical takeaways are straightforward:

  • Only download Claude or any AI desktop app directly from the official developer’s website
  • Be suspicious of any project offering free access to a paid or invite-only AI product
  • Use a hardware wallet for meaningful crypto holdings, since software wallets are primary targets here
  • Check installed applications regularly for anything you don’t recognize
  • Treat browser-saved passwords as compromised if you’ve installed any unfamiliar software recently

Corporate AI brands are now attack surfaces. Anthropic didn’t do anything wrong here, but its name and reputation are being used as a weapon against its users. That’s a problem the whole industry needs to take seriously, because these fake apps will keep appearing as long as AI tools remain in high demand and users keep looking for shortcuts to access them.