Close Menu
Crypto Breaking News
    Crypto Breaking News
    • News
      • Press Release
      • Featured
      • Events
      • Exchanges
      • Bitcoin
      • Ethereum
      • Solana
      • Ripple
      • Artificial Intelligence (AI)
      • Real World Assets (RWA)
      • Markets & Finance
      • Regulation & Policy
      • Press Releases by PR Newswire
      • News by CoinPedia
      • News by Coincu
      • News by Blockchain Wire
    • Crypto
      • Companies
      • Events
      • Partners
      • Buy Crypto
      • Timers
    • Advertise
      • Submit a Press Release
      • Logos
      • About
      • Services
    • Offers
      • Marketing Services
      • Wallets & Tools
    • Account
    • Video
    • Contact
    Submit PR
    Crypto Breaking News
    Altcoins Bitcoin Crypto News

    SlowMist: macOS Malware Hijacks Telegram Sessions to Target Crypto Wallets

    17 July 2026
    FacebookTwitterLinkedInCopy Link
    News Feed
    Google NewsRSS
    Slowmist: Macos Malware Hijacks Telegram Sessions To Target Crypto Wallets
    Slowmist: Macos Malware Hijacks Telegram Sessions To Target Crypto Wallets

    A macOS information-stealing malware can compromise Telegram Desktop sessions and, from there, target both software and hardware cryptocurrency wallets, according to blockchain security firm SlowMist. The report describes an attack chain that harvests credentials and wallet data from multiple macOS sources, then leverages that access to swap or drain funds through techniques that do not rely on breaking Telegramโ€™s two-step verification in the usual way.

    SlowMist says the malware extracts secrets from macOS Keychain, Safari cookies, Apple Notes, Telegram Desktop and database files tied to more than a dozen cryptocurrency wallets. After collecting passwords and authenticated session data, it copies Telegram Desktop session information along with wallet databases and browser wallet extension data, enabling follow-on account takeover attempts.

    Key takeaways

    • SlowMist reports malware can hijack existing Telegram Desktop sessions on macOS by reusing authenticated local data rather than forcing a new login.
    • In addition to stealing passwords, the malware targets wallet databases and application data for both popular software wallets and hardware wallet managers.
    • Telegram two-step verification may not block the attack because the malware avoids the need to pass verification challenges.
    • SlowMist outlines two follow-up strategies: offline wallet database decryption using harvested passwords, or replacing wallet apps (e.g., Ledger/Trezor software) with decoys to capture recovery phrases.

    How Telegram Desktop becomes the entry point

    SlowMistโ€™s core warning is that Telegram Desktop accounts on macOS may be compromised even when users have enabled two-step verification. The reason, the firm says, is architectural: instead of creating a fresh login that requires verification, the malware reuses an already authenticated local session stored on the device.

    In its tests, SlowMist restored stolen Telegram Desktop session data on another Mac without requiring the user to enter a phone number, verification code, or two-step verification password. That distinction matters for users because two-step verification is designed to protect logins, while this method targets session material that can be carried over to a new environment.

    The practical takeaway is that Telegram Desktop should be treated as a high-value target when credentials and session files are accessible to malware. If an attacker can move a session to another machine, subsequent stepsโ€”such as obtaining access to linked accounts, exchanging information, or guiding victims toward risky actionsโ€”can proceed without triggering the protections that apply to new authentication.

    Wallet data theft spans software wallets, hardware managers, and node databases

    SlowMist says the malware is not limited to Telegram. It also harvests wallet-related data from a wide range of sources, including wallet applications and full-node clients.

    On the wallet side, SlowMist names software wallets such as Exodus, Atomic, Electrum, Wasabi and Monero. It also points to targeting hardware wallet software interfaces, including Ledger Live and Trezor Suiteโ€”software layers that manage hardware devices and frequently coordinate how users view balances and initiate transactions.

    Beyond standalone wallets, the report says the malware searches for wallet data stored by full-node clients, listing Bitcoin Core, Litecoin Core, Dash Core and Dogecoin Core among those affected. For investors and traders, the implication is straightforward: wallet information does not only live in wallet apps. If malware can reach local storage associated with node software, it may uncover additional material that helps attackers attempt to access or reproduce wallet capabilities.

    SlowMist also describes collecting data beyond wallet databases, including Safari cookies and Apple Notes. Those components can increase an attackerโ€™s ability to persist access, understand user behavior, or extract sensitive information that is not stored in one dedicated wallet folder.

    Offline cracking and fake recovery flows

    After harvesting passwords and authenticated session data, SlowMist says attackers can attempt to decrypt stolen wallet databases offline. The attacker would use passwords taken from the infected device, reducing the need for repeated online attempts that might trigger rate limits or other defenses.

    SlowMist also describes a second approach: replacing legitimate Ledger and Trezor applications with fake versions. In this scenario, victims could be tricked into entering recovery phrases into the counterfeit softwareโ€”an especially dangerous outcome because recovery phrases are effectively โ€œmaster keysโ€ for accessing funds.

    SlowMist states it reproduced the attack chain in an isolated environment, supporting its claim that the described steps can be executed together rather than as unrelated capabilities.

    For users, the key risk is that wallet compromise can be multi-stage. Even if attackers initially acquire Telegram session access, the malwareโ€™s broader collection of wallet databases and application data can enable direct attempts to extract value or pivot to social engineering that captures recovery credentials.

    Why Telegramโ€™s usual protections may not be enough

    SlowMistโ€™s findings highlight a recurring theme in account takeover incidents: security features sometimes assume a specific threat model. Telegram two-step verification helps protect new logins, but the malwareโ€™s methodโ€”carrying over an authenticated local sessionโ€”changes the conditions.

    Instead of challenging the user during sign-in, the attacker operates with session data that the device has already established. That makes โ€œI turned on 2FAโ€ less reassuring when malware is already present and can read session-related files.

    SlowMist also recommends immediate operational steps for anyone who suspects compromise. It urges users to terminate existing Telegram sessions, create a new trusted login, and update both the Telegram two-step verification password and the Telegram Desktop Passcode. Those steps aim to invalidate the hijacked session material and force Telegram to re-establish trust through a fresh authentication flow.

    The firm further advises generating a new recovery phrase on a clean device and moving assets to new addresses. The goal is to break the link between the compromised wallet state and the assets that need protection. If wallet apps or recovery material were exposed, reusing the same recovery phrase after a compromise can leave funds vulnerable to attackers who already have enough information to regain access.

    SlowMistโ€™s report serves as a reminder that cryptocurrency security is not only about securing keys on paper or enabling 2FA on messaging apps. When malware can access both session data and wallet databases locally, protections must extend to device hygiene and rapid incident response. Users should watch closely for signs of compromise, verify which Telegram sessions remain active, and be prepared to move funds to fresh addresses after any suspected infection.

    Risk & affiliate notice: Crypto assets are volatile and capital is at risk. This article may contain affiliate links. Read full disclosure

    Crypto Breaking News
    • Website
    • Facebook
    • X (Twitter)
    • Pinterest
    • Instagram
    • Tumblr
    • LinkedIn

    The Crypto Breaking News editorial team curates the latest news, updates, and insights from the global cryptocurrency and blockchain industry.

    Related Posts

    Bitmine Reaches 4.9% Of Ethereum Supply After Adding 53.5k Eth

    Bitmine Reaches 4.9% of Ethereum Supply After Adding 53.5K ETH

    51 minutes ago
    Webull Launches Crypto Trading In Canada With Coinbase Pact

    Webull Launches Crypto Trading in Canada With Coinbase Pact

    2 hours ago
    Webull Launches Crypto Trading In Canada Via Coinbase Partnership

    Webull Launches Crypto Trading in Canada via Coinbase Partnership

    3 hours ago
    Bitcoin Fluctuates As Us Bond Yields Target A New 20-Year High

    Bitcoin Fluctuates as US Bond Yields Target a New 20-Year High

    4 hours ago
    Bitmine Gains 53,500 Eth, Lifts Stake To 4.9% Of Ethereum Supply

    Bitmine Gains 53,500 ETH, Lifts Stake to 4.9% of Ethereum Supply

    5 hours ago
    Strive Acquires 1,800 Bitcoin For $143m, Ranks No. 5 Among Firms

    Strive Acquires 1,800 Bitcoin for $143M, Ranks No. 5 Among Firms

    6 hours ago

    Search Crypto News

    Featured Crypto News

    Latest News

    • Bitmine Reaches 4.9% of Ethereum Supply After Adding 53.5K ETH
    • Webull Launches Crypto Trading in Canada With Coinbase Pact
    • Webull Launches Crypto Trading in Canada via Coinbase Partnership
    • Bitcoin Fluctuates as US Bond Yields Target a New 20-Year High
    • Bitmine Gains 53,500 ETH, Lifts Stake to 4.9% of Ethereum Supply
    • Strive Acquires 1,800 Bitcoin for $143M, Ranks No. 5 Among Firms
    • Why an Early Bitcoin Holder Burned $1M: Mystery Explained
    • Bitcoin Price Faces $80,000 Test As Technical And On-Chain Signals Diverge
    • Strategyโ€™s First Corporate Bitcoin Buy Tops $370M Since June
    • Hyperliquid and Pump.fun Drive 90% of $638M Record Crypto Buybacks: FT

    Join 20,000+ Crypto Followers

    • Facebook2.4K
    • Twitter4.5K
    • Instagram7.2K
    • LinkedIn4.3K
    • Telegram55
    • Threads1000
    Ledger
    Tangem 300x300

    About Crypto Breaking News

    About Crypto Breaking News

    Crypto Breaking News is a fast-growing digital media platform focused on the latest developments in cryptocurrency, blockchain, and Web3 technologies. Our goal is to provide fast, reliable, and insightful content that helps our readers stay ahead in the ever-evolving digital asset space.

    Web3 Digital L.L.C-FZ
    License Number: 2527596
    ๐Ÿ“ž +971 50 449 2025
    โœ‰๏ธ info@cryptobreaking.com
    ๐Ÿ“Meydan Grandstand, 6th floor, Meydan Road, Nad Al Sheba, Dubai, United Arab Emirates

    FacebookX (Twitter)InstagramPinterestYouTubeTumblrBlueskyLinkedInRedditTikTokTelegramThreadsRSS

    Links

    • Crypto News
    • Submit a Press Release
    • Advertise
    • Contact Us
    • Privacy Policy
    • Disclaimer
    • Terms and Conditions
    • Stocks Breaking News

    advertising

    eToro Crypto 300x300
    © 2026 CryptoBreaking.com | All rights reserved | Powered by Web3 Digital & Osom One

    Type above and press Enter to search. Press Esc to cancel.

    Change Location
    Find awesome listings near you!