
SlowMist discovered macOS malware that displays fake Ledger/Trezor wallets to steal recovery phrases, drain funds, and hijack Telegram sessions.
SlowMist, a blockchain security firm, has uncovered a new malware strain targeting macOS devices. The malware can steal Telegram session tokens, crypto wallet data, and saved passwords. It also displays fake Ledger and Trezor wallet applications to trick users into entering recovery phrases, the firm said.
The attack unfolds in several stages. Once installed, the malware quietly collects sensitive information without alerting the victim. The largest risk, SlowMist noted, is Telegram session theft. By stealing active sessions rather than passwords, the malware lets hackers bypass two-factor authentication and access private chats instantly. Many crypto traders use Telegram for exchange accounts, OTC deals, and private investment groups, making these accounts valuable targets.
The security firm urged Mac users to avoid installing unknown applications, keep recovery phrases offline, and verify every wallet request. Even experienced crypto users can fall victim to fake wallet windows or unknown software, SlowMist said.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.