BTCC / BTCC Square / Global Cryptocurrency /
Crypto Scam Group ’GreedyBear’ Steals Over $1M Using Malicious Extensions and AI-Generated Code

Crypto Scam Group ’GreedyBear’ Steals Over $1M Using Malicious Extensions and AI-Generated Code

Published:
2025-08-08 08:13:02
18
1
BTCCSquare news:

A cryptocurrency threat actor known as GreedyBear has orchestrated an industrial-scale theft operation, siphoning more than $1 million from unsuspecting victims. The group employs a multi-pronged approach, combining malicious browser extensions, malware, and scam websites to target digital asset holders.

Researchers from Koi Security identified over 650 malicious tools deployed in the campaign, marking a significant escalation from GreedyBear's earlier 'Foxy Wallet' scheme. The operation stands out for its simultaneous use of phishing, ransomware, and fake extensions—a departure from most cybercriminal groups that specialize in single attack vectors.

Notably, forensic analysis reveals traces of AI-generated code, suggesting the actors are leveraging automation to diversify and scale their attacks. This development coincides with PeckShield's recent report of a surge in crypto crime, with $142 million stolen across 17 major incidents in July alone.

|Square

Get the BTCC app to start your crypto journey

Get started today Scan to join our 100M+ users