Cardano users began to be attacked through fake Eternl wallets, 2026/01/04 09:31:12

45

Cardano users are being attacked through fake Eternl wallets0

Users of the Cardano network are under the threat of a phishing attack: attackers distribute links to malicious software disguised as the Eternl wallet desktop application. The attack began on December 31 and is still ongoing.
Fraudsters are sending emails that imitate the official announcement of the release of a wallet for staking Cardano tokens. To instill trust, the letter mentions real ecosystem incentives, such as NIGHT and ATMA token rewards through the Diffusion Staking Basket program. Hackers created an almost exact copy of the official announcement of Eternl Desktop. The fake message talks about compatibility with hardware wallets, local key management and advanced delegation tools. 

New infrastructure + wallet software + MSI installer is a high-risk combination (Source - Malwr-analysis.com).jpg1

The newly registered domain download.eternldesktop.network is used to distribute the malicious installer. The installation package is not officially verified or digitally signed. An anonymous threat researcher and malware analyst under the nickname Anurag  said that he conducted a technical examination and discovered that the Eternl.msi file contains a hidden remote management utility LogMeIn Resolve.

When launched, the installer creates a new folder structure in the Program Files directory. Then it writes several configuration files, one of which enables the remote access feature without user intervention. Anurag said that the malware transmits information about system events to remote servers using hard-coded API keys. This creates a robust channel for command execution, system monitoring, long-term presence in the victim’s infrastructure, and collection of credentials. A security expert has categorized this behavior as a critical threat. 

Eternl is a universal lightweight wallet developed by the teams at TITAN and AHL, two popular Cardano staking pools. This is one of the most popular Cardano wallets on social networks among ADA owners. 

On January 2, anonymous blockchain researcher ZachXBT reported a large-scale attack on cryptocurrency wallets. An unknown attacker was actively withdrawing funds from multiple wallets on networks compatible with the Ethereum virtual machine. The hacker focused on wallets with relatively small amounts: the losses of each victim did not exceed $2,000. At the time of publication of the ZachXBT message, the total amount of funds withdrawn reached approximately $107,000.