Early access. Early access is free. Member Club will be $9.99/mo or $99/yr when paid plans launch — advance notice before any charge. See what's included →
← Back to Explore
NationalNationalcryptotechnews
MacOS Malware Hijacks Telegram, Targets Crypto Wallets: New Threat to Digital Asset Investors
Photo: DS stories / Pexels · Pexels

MacOS Malware Hijacks Telegram, Targets Crypto Wallets: New Threat to Digital Asset Investors

Share

💡 • Crypto investors using Telegram for trading signals or bot automation should immediately enable two-factor authentication (2FA) on Telegram and avoid storing wallet recovery phrases on the same device. • Consider using a dedicated, clean machine or a virtual machine for crypto transactions to isolate Telegram sessions from wallet operations. • For side hustlers running Telegram-based arbitrage bots, ensure the bot account has limited wallet access and never holds private keys. • Regularly audit active Telegram sessions and revoke any suspicious logins; use hardware wallets for long-term holdings and keep only small amounts in hot wallets. • If you receive unexpected prompts to install software or enter recovery phrases, verify the request through a separate channel before acting.

A newly discovered macOS malware steals credentials to hijack Telegram sessions and decrypt cryptocurrency wallets, according to blockchain security firm SlowMist. The malware also tricks users into entering wallet recovery phrases through fake applications, posing a direct risk to crypto investors and traders who rely on Telegram for market signals and transactions.

Blockchain security firm SlowMist has identified a macOS malware that specifically targets cryptocurrency investors by hijacking their Telegram sessions. The malware is designed to steal login credentials, allowing attackers to take over active Telegram accounts. Once inside, the malware can decrypt cryptocurrency wallets stored on the device or trick users into revealing their wallet recovery phrases through counterfeit applications that mimic legitimate software.

The attack vector is particularly dangerous for investors who use Telegram for trading signals, group chats, or automated trading bots. By hijacking the session, attackers can impersonate the victim, execute trades, or drain wallets directly. The malware’s ability to decrypt wallets suggests that it may also extract private keys or seed phrases stored on the system, bypassing standard security measures.

SlowMist has not disclosed the specific distribution method, but the malware likely spreads through phishing links, fake downloads, or compromised software updates. The research highlights a growing trend of macOS-focused threats, as cybercriminals increasingly target the Apple ecosystem, which was once considered more secure. Investors who manage substantial crypto portfolios on Mac devices are at heightened risk.

For cryptocurrency investors, this development underscores the need to separate high-value wallets from everyday communication tools. Telegram sessions, often used for real-time market updates and peer-to-peer trading, have become a prime target. The malware’s ability to trick users into entering recovery phrases through fake apps means that even hardware wallet users could be compromised if they interact with the malicious software on their Mac.

The financial impact could be severe, especially for active traders who maintain large balances in hot wallets. Side hustles involving crypto arbitrage, airdrop farming, or Telegram-based trading bots are particularly vulnerable because they rely on continuous session access. Investors should also be wary of unsolicited download links or requests to install new software for crypto-related purposes.

As the crypto industry matures, security researchers expect more sophisticated malware strains to emerge. The SlowMist report serves as a reminder that the weakest link in digital asset security is often the user’s device and communication channel, not the blockchain itself. Mac users who engage in crypto trading should adopt multi-factor authentication, keep software updated, and avoid storing sensitive information on devices used for instant messaging.

Read the full story

Original reporting and related coverage — attribution links only, not paid recommendations.

Discuss this story

Trade this story

  • Robinhood logo
  • Webull logo
  • Hostinger logo

Broker buttons use invite / refer-a-friend links (rewards may be capped). Other partner links may pay OppHub a commission at no extra cost to you.

Tools & books on Amazon

Shop Amazon →

Relevant gear and reads when you want to go deeper — OppHub may earn from qualifying purchases.

Build My Playbook

Turn this headline into a clear plan: what to watch, how to express it (stocks, ETFs, or options education), and how you’d know you’re wrong — for beginners and active traders. Not personalized advice.

You’ll get theme → ETFs → stocks → options education → side income → kill switches.

Loading comments...
Share

Follow OppHub for more money news