Listen to Article — 7 min
Cybersecurity researchers have uncovered a malicious campaign distributing fake "Claude Opus 5 Free Desktop" apps on GitHub, designed to infect Windows users with a potent infostealer that targets cryptocurrency wallet files, browser databases, and password managers. The discovery comes as Anthropic releases its latest AI models, Fable 5.1 and Mythos 5.1, creating a fertile new attack surface for cybercriminals looking to exploit public demand for "free" access to premium artificial intelligence software. According to researchers at Morphisec, the malware, identified as Revstealer, is actively copying wallet data from a wide range of crypto-asset applications, though unlocking the stolen funds depends on the victim’s password hygiene. Fake Claude Opus 5 Desktop App Targets Crypto Wallets The campaign identified by Morphisec lures victims by offering a free version of Anthropic’s paid Claude Opus 5 AI model. Once downloaded from a deceptive GitHub repository, the executable silently installs an infostealer that specifically targets a broad spectrum of crypto wallet software. Security researchers reported that the malicious application seeks to extract data from local systems, scanning for files associated with both software-based and hardware-wallet interfaces. The targeted crypto asset apps include: Atomic Armory Cake Wallet Sparrow Wasabi Ledger Wallet Trezor Suite Electrum Morphisec’s analysis reveals that wallet files are copied and compressed for exfiltration to the attackers' server. The malware’s primary goal is the reliable theft of encrypted wallet material and configuration data, rather than immediate decryption of funds. Wallet files are simply copied as-is and may be compressed before being uploaded. “No product-specific password recovery, seed extraction or encrypted-wallet decryption occurs at this stage: Revstealer reliably steals the encrypted wallet material and configuration, while unlocking it depends on processing not demonstrated in this sample,” the researchers stated. How the Revstealer Malware Strikes Beyond crypto wallet files, Revstealer also collects a trove of sensitive data, including credentials, cookies, and session tokens. The malware’s reach extends to browser databases, password managers, and VPN configurations across common browser ecosystems. Researchers said the stealer is designed to operate quietly, evade detection, and can even delete itself after executing its task. Targeted Wallet / App Type / Interface Risk Profile / Malware Action Ledger Wallet Hardware wallet interface Wallet files copied; hardware private keys remain secure, but passwords and configs are at risk Trezor Suite Hardware wallet interface Wallet files copied; seed phrases may be exposed if stored on the compromised system Atomic / Cake Wallet Software / Hot wallet Wallet files and configs exfiltrated for potential decryption Sparrow / Wasabi / Electrum Bitcoin-focused software wallets Encrypted wallet files compressed and uploaded Browser Databases & VPN Configs General credentials / data Credential and session theft; account takeover post-infection The threat extends into the real world of compromised accounts. Morphisec documented one instance where a user was infected with Revstealer after knowingly downloading software from GitHub. No product-specific password recovery, seed extraction or encrypted-wallet decryption occurs at this stage: Revstealer reliably steals the encrypted wallet material and configuration, while unlocking it depends on processing not demonstrated in this sample. “Despite the infection, their installed security product reportedly did not initially detect the malicious executable. The victim later reported that several online accounts, including Microsoft and EA accounts, had been compromised, illustrating how quickly an infostealer infection can lead to credential and session theft,” the researchers said. The severity of the attack hinges heavily on the user's own security practices. If a wallet has a weak passphrase, reused credentials, or a password stolen from a password manager, criminals may gain access to the funds. The malware’s ability to delete itself complicates incident response, leaving victims with little forensic evidence of the breach. The New Attack Surface: Fable 5.1 and Mythos 5.1 Morphisec highlights that the demand for AI tooling has transformed into “a first-class social engineering surface,” and the release of new models marks a critical inflection point for cyber risk. On September 1, Anthropic released Fable 5.1 and Mythos 5.1. While Fable 5.1 is generally available to the public, Mythos 5.1 is restricted to Anthropic’s trusted programs, creating an even more tantalizing lure for scammers. Fable 5.1: Generally available to the public Mythos 5.1: Restricted access via Anthropic’s trusted programs; an attractive lure for "exclusive access" scams Given the success of the fake "Claude Opus 5 Free Desktop" campaign, analysts expect attackers to pivot quickly to impersonating these newly launched models. The scarcity of Mythos 5.1 access presents a golden opportunity for cybercriminals to spin up lookalike applications, promising users exclusive entry to Anthropic’s most capable model. Cybersecurity experts warn that the operational playbook will likely mirror the existing Revstealer deployment, swapping out the lure to match the latest release. Wider Implications and Immediate Security Measures The convergence of AI software demand and crypto asset stewardship creates a high-stakes environment where a single wrong download can drain a user's digital assets. With the release of Fable 5.1 and Mythos 5.1, the current threat landscape requires immediate awareness for crypto users, who are frequently targeted due to the irreversible nature of blockchain transactions. The Morphisec report reinforces that infostealer infections are becoming a primary vector for crypto theft, particularly for individuals who rely on on-device password managers or store wallet recovery phrases insecurely. Security researchers emphasize that for hardware wallet users, the interface is only a portal; the private keys remain secure on the physical device. However, the same users are still at risk of having their exchange accounts, email addresses, and social profiles compromised, as shown in the reported account takeover case. The urgent takeaway for the cryptocurrency community is the need to verify software sources rigorously. Given the speed of AI innovation and the proliferation of "free access" lures, the window for attackers to exploit user curiosity is wide open. As the new models debut, the immediate risk is that users searching for download links will encounter malicious cloned repositories, placing their digital wealth directly in harm's way. What Should You Do If You Downloaded a Fake Claude App? If you have downloaded a fake Claude app like the one described in the Morphisec report, you should immediately disconnect the affected device from the internet and run a full system scan with updated antivirus software. Since Revstealer can copy browser databases and password managers, you must also rotate all critical account passwords from a clean, uninfected device, starting with email, exchange, and financial accounts. Be aware that the malware can delete itself, so a forensic scan may be required to confirm infection status. How Does Revstealer Specifically Steal Bitcoin Wallets? Revstealer searches the local file system for files associated with a listed set of crypto wallet applications, including Ledger, Trezor, and Electrum. It can copy and compress the wallet configuration files and upload them to a remote server. However, the malware does not decrypt the wallets at the point of theft; it steals the encrypted wallet material, meaning a successful breach still requires the attacker to crack a weak passphrase or obtain related credentials. Is a Hardware Wallet Safe from This Malware? Hardware wallets themselves remain physically secure, as the private keys never leave the device. However, this malware targets the interface applications like Ledger Wallet and Trezor Suite on the computer. If an attacker steals your wallet files, a copy of your seed phrase stored unencrypted on the system, or your password via a compromised password manager, they may be able to sign fraudulent transactions without physical possession of the hardware wallet. What Are the Fable 5.1 and Mythos 5.1 Models? Fable 5.1 and Mythos 5.1 are newly released AI models from Anthropic, released on September 1. Fable 5.1 is generally available, while Mythos 5.1 is restricted to Anthropic's trusted programs. The scarcity of Mythos 5.1 creates a prime opportunity for scammers to lure victims with fraudulent promises of "exclusive access" or "free versions" of the paid model. Why Are Fake Claude Apps Surfacing Now? Cybercriminals closely follow trending topics to maximize the effectiveness of social engineering attacks. The public anticipation around the release of new premium models like Fable 5.1 and Mythos 5.1 drives users to search for free or "unlocked" versions, increasing the likelihood of clicking dangerous links. The demand for AI tooling is now considered a first-class social engineering surface.
Follow Our News on Google
Be instantly informed of developments.
Cybersecurity researchers have uncovered a malicious campaign distributing fake “Claude Opus 5 Free Desktop” apps on GitHub, designed to infect Windows users with a potent infostealer that targets cryptocurrency wallet files, browser databases, and password managers. The discovery comes as Anthropic releases its latest AI models, Fable 5.1 and Mythos 5.1, creating a fertile new attack surface for cybercriminals looking to exploit public demand for “free” access to premium artificial intelligence software. According to researchers at Morphisec, the malware, identified as Revstealer, is actively copying wallet data from a wide range of crypto-asset applications, though unlocking the stolen funds depends on the victim’s password hygiene.
Fake Claude Opus 5 Desktop App Targets Crypto Wallets
The campaign identified by Morphisec lures victims by offering a free version of Anthropic’s paid Claude Opus 5 AI model. Once downloaded from a deceptive GitHub repository, the executable silently installs an infostealer that specifically targets a broad spectrum of crypto wallet software. Security researchers reported that the malicious application seeks to extract data from local systems, scanning for files associated with both software-based and hardware-wallet interfaces.
The targeted crypto asset apps include:
- Atomic
- Armory
- Cake Wallet
- Sparrow
- Wasabi
- Ledger Wallet
- Trezor Suite
- Electrum
Morphisec’s analysis reveals that wallet files are copied and compressed for exfiltration to the attackers’ server. The malware’s primary goal is the reliable theft of encrypted wallet material and configuration data, rather than immediate decryption of funds. Wallet files are simply copied as-is and may be compressed before being uploaded.
“No product-specific password recovery, seed extraction or encrypted-wallet decryption occurs at this stage: Revstealer reliably steals the encrypted wallet material and configuration, while unlocking it depends on processing not demonstrated in this sample,” the researchers stated.
How the Revstealer Malware Strikes
Beyond crypto wallet files, Revstealer also collects a trove of sensitive data, including credentials, cookies, and session tokens. The malware’s reach extends to browser databases, password managers, and VPN configurations across common browser ecosystems. Researchers said the stealer is designed to operate quietly, evade detection, and can even delete itself after executing its task.
| Targeted Wallet / App |
Type / Interface |
Risk Profile / Malware Action |
| Ledger Wallet |
Hardware wallet interface |
Wallet files copied; hardware private keys remain secure, but passwords and configs are at risk |
| Trezor Suite |
Hardware wallet interface |
Wallet files copied; seed phrases may be exposed if stored on the compromised system |
| Atomic / Cake Wallet |
Software / Hot wallet |
Wallet files and configs exfiltrated for potential decryption |
| Sparrow / Wasabi / Electrum |
Bitcoin-focused software wallets |
Encrypted wallet files compressed and uploaded |
| Browser Databases & VPN Configs |
General credentials / data |
Credential and session theft; account takeover post-infection |
The threat extends into the real world of compromised accounts. Morphisec documented one instance where a user was infected with Revstealer after knowingly downloading software from GitHub. No product-specific password recovery, seed extraction or encrypted-wallet decryption occurs at this stage: Revstealer reliably steals the encrypted wallet material and configuration, while unlocking it depends on processing not demonstrated in this sample.
“Despite the infection, their installed security product reportedly did not initially detect the malicious executable. The victim later reported that several online accounts, including Microsoft and EA accounts, had been compromised, illustrating how quickly an infostealer infection can lead to credential and session theft,” the researchers said.
The severity of the attack hinges heavily on the user’s own security practices. If a wallet has a weak passphrase, reused credentials, or a password stolen from a password manager, criminals may gain access to the funds. The malware’s ability to delete itself complicates incident response, leaving victims with little forensic evidence of the breach.
The New Attack Surface: Fable 5.1 and Mythos 5.1
Morphisec highlights that the demand for AI tooling has transformed into “a first-class social engineering surface,” and the release of new models marks a critical inflection point for cyber risk. On September 1, Anthropic released Fable 5.1 and Mythos 5.1. While Fable 5.1 is generally available to the public, Mythos 5.1 is restricted to Anthropic’s trusted programs, creating an even more tantalizing lure for scammers.
- Fable 5.1: Generally available to the public
- Mythos 5.1: Restricted access via Anthropic’s trusted programs; an attractive lure for “exclusive access” scams
Given the success of the fake “Claude Opus 5 Free Desktop” campaign, analysts expect attackers to pivot quickly to impersonating these newly launched models. The scarcity of Mythos 5.1 access presents a golden opportunity for cybercriminals to spin up lookalike applications, promising users exclusive entry to Anthropic’s most capable model. Cybersecurity experts warn that the operational playbook will likely mirror the existing Revstealer deployment, swapping out the lure to match the latest release.
Wider Implications and Immediate Security Measures
The convergence of AI software demand and crypto asset stewardship creates a high-stakes environment where a single wrong download can drain a user’s digital assets. With the release of Fable 5.1 and Mythos 5.1, the current threat landscape requires immediate awareness for crypto users, who are frequently targeted due to the irreversible nature of blockchain transactions.
The Morphisec report reinforces that infostealer infections are becoming a primary vector for crypto theft, particularly for individuals who rely on on-device password managers or store wallet recovery phrases insecurely. Security researchers emphasize that for hardware wallet users, the interface is only a portal; the private keys remain secure on the physical device. However, the same users are still at risk of having their exchange accounts, email addresses, and social profiles compromised, as shown in the reported account takeover case.
The urgent takeaway for the cryptocurrency community is the need to verify software sources rigorously. Given the speed of AI innovation and the proliferation of “free access” lures, the window for attackers to exploit user curiosity is wide open. As the new models debut, the immediate risk is that users searching for download links will encounter malicious cloned repositories, placing their digital wealth directly in harm’s way.
What Should You Do If You Downloaded a Fake Claude App?
If you have downloaded a fake Claude app like the one described in the Morphisec report, you should immediately disconnect the affected device from the internet and run a full system scan with updated antivirus software. Since Revstealer can copy browser databases and password managers, you must also rotate all critical account passwords from a clean, uninfected device, starting with email, exchange, and financial accounts. Be aware that the malware can delete itself, so a forensic scan may be required to confirm infection status.
How Does Revstealer Specifically Steal Bitcoin Wallets?
Revstealer searches the local file system for files associated with a listed set of crypto wallet applications, including Ledger, Trezor, and Electrum. It can copy and compress the wallet configuration files and upload them to a remote server. However, the malware does not decrypt the wallets at the point of theft; it steals the encrypted wallet material, meaning a successful breach still requires the attacker to crack a weak passphrase or obtain related credentials.
Is a Hardware Wallet Safe from This Malware?
Hardware wallets themselves remain physically secure, as the private keys never leave the device. However, this malware targets the interface applications like Ledger Wallet and Trezor Suite on the computer. If an attacker steals your wallet files, a copy of your seed phrase stored unencrypted on the system, or your password via a compromised password manager, they may be able to sign fraudulent transactions without physical possession of the hardware wallet.
What Are the Fable 5.1 and Mythos 5.1 Models?
Fable 5.1 and Mythos 5.1 are newly released AI models from Anthropic, released on September 1. Fable 5.1 is generally available, while Mythos 5.1 is restricted to Anthropic’s trusted programs. The scarcity of Mythos 5.1 creates a prime opportunity for scammers to lure victims with fraudulent promises of “exclusive access” or “free versions” of the paid model.
Why Are Fake Claude Apps Surfacing Now?
Cybercriminals closely follow trending topics to maximize the effectiveness of social engineering attacks. The public anticipation around the release of new premium models like Fable 5.1 and Mythos 5.1 drives users to search for free or “unlocked” versions, increasing the likelihood of clicking dangerous links. The demand for AI tooling is now considered a first-class social engineering surface.
This article is provided for informational and educational purposes only. It is not offered or intended to be used as legal, tax, investment, financial, or other advice. The digital asset market is highly volatile, speculative, and subject to rapid regulatory changes. While we strive to ensure the accuracy of the information presented, market conditions change quickly, and data may become outdated. You are solely responsible for your own research (DYOR) and financial decisions. ATHPost, its owners, and its authors assume no liability whatsoever for any direct or indirect financial losses, liquidations, or damages arising from the use of this content.