Experts warn this fake Claude install guide can be used to empty crypto wallets
- Huntress reverse-engineers MacSync, a six-stage macOS stealer and remote access Trojan delivered through a fake Claude Code install guide hosted on a real claude.ai share URL and promoted via a paid Google ad
- The lure needed almost no forgery: the page sat under Anthropic’s own certificate, and the platform’s safety banner repeated the attacker’s chosen display name, “Apple Support,” back to the reader as fact
- The final stage rewrites installed Ledger and Trezor apps in place so a normal launch leads to a fake recovery message that harvests the seed phrase, draining the wallets of unsuspecting victims
Looking online for instructions on how to install Claude Code on a Mac could lead to you having your crypto wallet hijacked in the process
The victim ran a Google search, clicked the first result, a paid Google advertisement, and landed on a tidy step-by-step guide hosted on claude.ai, badged as shared by Apple Support, telling them to open Terminal and paste a single command.
What followed, according to a reverse-engineering write-up published by security firm Huntress was a six-stage macOS kill chain called MacSync: a stealer, a remote access trojan, a signed helper built to farm one specific system permission, and finally Trojanized copies of the victim’s own cryptocurrency wallet apps, rewritten in place to phish the recovery phrase.
Latest Videos FromTechRadar
A complex, intricate approach that resulted in a stolen wallet
The victim had pulled their machine offline before Huntress could extract the malware from disk, so the researchers reconstructed the loader’s request and instead downloaded every stage from the attacker’s own delivery servers.
The results showed a sophisticated campaign that had to fake little to appear legitimate.
Anthropic lets any user publish a conversation to a public share URL. The operator maliciously used that feature exactly as designed. The lure page sat on claude.ai itself, over HTTPS, under Anthropic’s own security certificates. There was no lookalike domain to squint at, no certificate warning to click past, and nothing in the address bar to give the game away.
The staging went much further than that. Whoever published the share set their display name to “Apple Support,” and Anthropic’s own safety banner, which sits directly above the content, duly reported that the reader was looking at a copy of a chat between Claude and Apple Support.
Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!
The platform repeated the attacker’s chosen name back to the reader as established fact, further cementing their ‘credentials’. The conversation itself was written to read like vendor documentation, promising that the install leaves personal files untouched and makes no system-level modifications without approval.
That same design decision has surfaced before for entirely different reasons. Wired had reported earlier private Claude conversations were turning up in Google and Bing results, because a share link is an ordinary public web page that search engines crawl like any other.
Users accidentally exposing their own chats and an operator deliberately planting a fake install guide are two outcomes of the same property: whatever gets published to a share URL is public, indexable, and served under Anthropic’s certificate.
It is also not a one-off. Huntress has previously documented the same delivery pattern with AMOS through poisoned ChatGPT and Grok conversations, a separate remote access trojan through fake Claude desktop malvertising, and fake installers for other AI tools hosted on GitHub.
The lure has changed somewhat, but the shape has not, and users need to exercise caution when clicking links or following commands from untrustworthy sources on the internet, even if they appear to come from a source that Google was paid to place above the correct answer.

Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.
Source
Huntress reverse-engineers MacSync, a six-stage macOS stealer and remote access Trojan delivered through a fake Claude Code install guide hosted on a real claude.ai share URL and promoted via a paid Google ad The lure needed almost no forgery: the page sat under Anthropic’s own certificate, and the platform’s safety…
Recent Posts
- Spotify helps me keep track of my favorite songs from each year — but this one upgrade would make it so much easier for grouping my favorite albums
- Zuckerberg’s yacht was closer, but someone else saved a stranded boat
- Experts warn this fake Claude install guide can be used to empty crypto wallets
- How to use ChatGPT’s new, more natural Voice Mode for conversations
- This VPN firm has created a way to stop Microsoft’s hidden tracking tool on Windows — although it will break some key cloud services
Archives
- August 2026
- July 2026
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023