Buy now

Ask ten people what crypto malware is and you will get two different answers, both correct. One group means the software that quietly borrows your computer to mine coins for somebody else, which is annoying and expensive and will not empty your wallet. The other group means the code that goes looking for keys, and that is the family worth an hour of your attention, because it took a visible step forward in the first week of September 2026.

We make hardware wallets. That shapes how we read this, so the section below on what this software cannot touch is written to be checkable rather than reassuring.

What the stealing kind is built to find

Key-hunting malware wants one of three things, and the differences matter because your defences are different for each.

The first target is a stored secret. Recovery phrases end up in screenshots, notes apps, password managers, browser profiles and cloud drives, and a program running with your permissions can read all of those without any exotic technique. It is looking through your own files the way you would.

The second target is the moment of payment. Address-substitution code watches the clipboard, spots something shaped like a wallet address, and swaps in one the attacker controls, so the destination you pasted is not the destination that gets signed. People catch this by comparing the first and last characters, which works until the malware is patient enough to match those too.

The third target is your signature. Rather than steal a key, a drainer persuades you to authorise a transaction or a token approval that hands over the balance, which means the software never has to break anything cryptographic at all. That is where the September cases sit.

Two lures from one week in September

On 1 September 2026 Malwarebytes published a teardown of a fake GTA 6 fan page offering a leaked copy of the game for 50 USD or 1 SOL. Behind the countdown clock sat inline code that checked the balance of any Solana wallet connected to it, left just enough behind to cover the network fee, and prepared to move the rest out. A second script, running to 2.4 MB, wrapped a widely used library for connecting sites to wallets around additions that inventoried and took assets across seven other networks including Ethereum, Base, Arbitrum and Polygon. The page even refused to load for visitors in ten countries, which tells you the operators were managing their own legal exposure while doing it.

The same week, Ukraine's security service and national police dismantled a Kyiv ring that had been turning over as much as 1 million USD a month with a drainer of its own. Investigators identified 62 victims across more than twenty countries, and the method is worth memorising. Marks were recruited through Telegram with an investment pitch, then asked to connect their main wallet and approve one small test transaction to prove the platform worked. The test was the theft.

Neither operation needed a zero-day. Both needed a person to click approve.

What this software cannot do

Here is the boundary, and it holds regardless of how sophisticated the lure gets. A private key generated inside a certified secure element and never exported cannot be read by code running on your laptop, because there is no interface that returns it. The chip signs things when asked and hands back a signature. Software on the other side of that boundary can ask, and it cannot copy.

On Ryder One the key is generated inside an EAL6+ certified Infineon SLC38 and stays there, and the firmware has been independently audited by Halborn, with the report published in full. Connectivity is NFC only, so there is no USB data path and no Bluetooth or Wi-Fi radio waiting to be spoken to; the chip is reachable when you hold the device against a phone and unreachable the rest of the time. Address-substitution attacks run into a second wall, because the transaction is rendered on the 1.6-inch AMOLED touchscreen on the device itself, receive addresses can be checked there before you hand one out, and the confirm button is wired straight to the secure element so nothing signs without a press.

That leaves the third attack, and we should be plain about it: hardware does not stop you from approving a transaction you choose to approve. What it does is put the true destination and amount in front of you on a screen the infected machine does not control, which turns an invisible swap into something you can catch by reading. The defence is the readable screen plus the habit of using it.

Backups are where the damage usually started

Go back through the incidents and a pattern shows up well before the malware does. The wallet that got emptied often had its recovery words sitting in a photo album, a synced notes app or a cloud drive, waiting for any program that could read the user's own files.

Paper avoids that and brings its own exposures, since it burns, runs in water, and gets thrown out by someone tidying. Steel plates handle those three and leave your entire holding resting on one object staying unfound for twenty years, an upgrade on paper without being a fix. TapSafe Recovery removes the single point of failure instead: a Recovery Tag holds 50% of recovery, your paired phone holds 50% stored encrypted in your iCloud or Google Drive rather than on the handset, and optional Recovery Contacts hold 25% each while seeing nothing about your wallet. Built on our own implementation of Shamir's Secret Sharing, it means no single item an attacker reaches is enough on its own. The BIP-39 seed phrase is still available on the device as a last resort, so you are never tied to our hardware.

What to do this week

Search your own devices for your recovery words before anyone else does, and delete every copy that lives in a photo album, a notes app or a synced folder. Review the token approvals your addresses have granted and revoke the ones you cannot account for, since an old permission is a standing invitation. Treat any site that wants a small test transaction before releasing your money as the drainer the Kyiv case showed it to be, and treat a leaked game, an airdrop and a support agent who found you first with the same suspicion.

Then decide where the keys themselves should live. Software can only take what a machine can reach, which makes the strongest move in the whole list moving the key somewhere that machine cannot go.

Want your keys somewhere malware cannot read them? Get your Ryder One for 149 USD.


Meta description: Crypto malware explained: how stealers, clipboard swaps and drainers take coins, what September's GTA 6 and Kyiv cases showed, and what a secure element blocks.

Target keyword: crypto malware

Meet Ryder One

Meet Ryder One
Meet Ryder One

The only crypto wallet you can install on a crowded subway.
Set it up in less than 60 seconds and just tap your phone to send, swap, and recover.

Learn More