Skip to main content
Sign in

Vanta Stealer — Python Infostealer Targeting Crypto Wallets

avoid.net/vanta-stealer-python-infostealer-targeting-crypto-wallets2/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Summary

Vanta Stealer is a Python-based information-stealing malware first publicly documented in late July 2026 by Point Wild's Lat61 Threat Intelligence Team and subsequently reported by multiple security vendors. The malware specifically targets cryptocurrency wallet seed phrases and private keys, browser credentials, Discord and Telegram session tokens, and gaming platform accounts on Windows systems. It uses PyInstaller packaging and multiple layers of PyArmor obfuscation to hinder analysis, and retrieves its browser credential extraction module dynamically at runtime to allow operators to update harvesting capabilities without redeploying the primary payload.

Have evidence about Vanta Stealer — Python Infostealer Targeting Crypto Wallets?

Timeline(7 events)

2026-07-28

Point Wild's Lat61 Threat Intelligence Team (researchers Prathamesh Shingare and Kedar Shashikant Pandit) published the primary technical dissection of Vanta Stealer, documenting its PyInstaller/PyArmor architecture, dynamic module retrieval, targeted data categories, exfiltration mechanism, and 20 SHA256 IOCs.

Point Wild Threat Intelligence

2026-08-06

Cyberpress published a report confirming Vanta Stealer distribution through cracked software, game cheating tools, and fake software update pages, corroborating the Point Wild findings.

Cyberpress

2026-08-06

Rankiteo catalogued the threat with a severity rating of 85/100, noting the malware's targeting of Discord, Telegram, Roblox, and Minecraft alongside browser passwords and cryptocurrency wallets.

Rankiteo Blog

2026-08-07

PCRisk documented Vanta Stealer in its malware removal guide database, providing antivirus detection names across Avast, Combo Cleaner, Microsoft Defender, and Kaspersky, and listing suspected distribution vectors.

PCRisk

2026-08-07

GBHackers reported on Vanta Stealer's use of PyArmor obfuscation, its cross-platform Python base, and its targeting of browser passwords, crypto wallets, and Discord tokens.

GBHackers

2026-08-10

CyberSecurityNews reported that Vanta Stealer empties browser vaults, crypto wallets, and gaming accounts, describing its speed of data extraction on compromised Windows systems.

CyberSecurityNews

2026-08-15

HackRead published coverage confirming gamers, cryptocurrency users, and web application users as the primary target demographics, and detailing the malware's harvesting of Steam, Valorant, Roblox, and Minecraft accounts alongside wallet seed phrases.

HackRead
Provenance & Audit Trail
4 Wayback Archives

Decision Log

  • #1publish⛓ pending8/15/2026, 11:03:30 PM
    hash: 8e3Qx3P76dKAucQ7njbKvFUzjdfvydxLZp6DCKiMkb2M

4 of 7 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/15/2026, 11:03:22 PM

last updated: 8/16/2026, 7:16:34 AM

avoid.net — verified advice for a post-truth world