Skip to main content
AVOID.NET

Vanta Stealer — Python Infostealer Targeting Crypto Wallets

avoid.net/vanta-stealer-python-infostealer-targeting-crypto-wallets→0/100·82% conf.
[AI-DRAFTED · AWAITING VERIFICATION]

Auto-generated score, not yet verified against the scoring model. Under review — treat as indicative, not a verdict.

anchored·39SL5q…DYhr

Summary

Vanta Stealer is a Python-based information-stealing malware first publicly documented in late July 2026 by Point Wild's Lat61 Threat Intelligence Team and subsequently reported by multiple security vendors. The malware specifically targets cryptocurrency wallet seed phrases and private keys, browser credentials, Discord and Telegram session tokens, and gaming platform accounts on Windows systems. It uses PyInstaller packaging and multiple layers of PyArmor obfuscation to hinder analysis, and retrieves its browser credential extraction module dynamically at runtime to allow operators to update harvesting capabilities without redeploying the primary payload.

Connected Entities

1 entity

No connected entities recorded yet — this investigation is not currently linked to any other page in the index.

Have evidence about Vanta Stealer — Python Infostealer Targeting Crypto Wallets?

Timeline(7 events)

28 July 2026

Point Wild's Lat61 Threat Intelligence Team (researchers Prathamesh Shingare and Kedar Shashikant Pandit) published the primary technical dissection of Vanta Stealer, documenting its PyInstaller/PyArmor architecture, dynamic module retrieval, targeted data categories, exfiltration mechanism, and 20 SHA256 IOCs.

Point Wild Threat Intelligence

6 August 2026

Cyberpress published a report confirming Vanta Stealer distribution through cracked software, game cheating tools, and fake software update pages, corroborating the Point Wild findings.

Cyberpress

6 August 2026

Rankiteo catalogued the threat with a severity rating of 85/100, noting the malware's targeting of Discord, Telegram, Roblox, and Minecraft alongside browser passwords and cryptocurrency wallets.

Rankiteo Blog

7 August 2026

PCRisk documented Vanta Stealer in its malware removal guide database, providing antivirus detection names across Avast, Combo Cleaner, Microsoft Defender, and Kaspersky, and listing suspected distribution vectors.

PCRisk

7 August 2026

GBHackers reported on Vanta Stealer's use of PyArmor obfuscation, its cross-platform Python base, and its targeting of browser passwords, crypto wallets, and Discord tokens.

GBHackers

10 August 2026

CyberSecurityNews reported that Vanta Stealer empties browser vaults, crypto wallets, and gaming accounts, describing its speed of data extraction on compromised Windows systems.

CyberSecurityNews

15 August 2026

HackRead published coverage confirming gamers, cryptocurrency users, and web application users as the primary target demographics, and detailing the malware's harvesting of Steam, Valorant, Roblox, and Minecraft accounts alongside wallet seed phrases.

HackRead
Provenance & Audit Trail

Decision Log

This investigation is cryptographically anchored to the Solana blockchain (3 events). 6 of 7 cited source URLs have an Internet Archive snapshot.

model: claude-sonnet-4-6

generated: 8/15/2026, 11:03:22 PM

last updated: 8/25/2026, 10:17:36 AM

7 views

avoid.net — verified advice for a post-truth world