What happened: Cybersecurity giant Kaspersky has identified a sophisticated multi-stage malware framework called 'OkoBot'. Active since April 2025, the malware uses 'SeedHunter' to inject malicious code into legitimate wallet applications like Ledger Live and Trezor Suite, tricking users into revealing their recovery phrases.
Why it matters: This is a major red flag for self-custody. Once your seed phrase is compromised, your funds are permanently at risk. The malware also records keystrokes and monitors over 100 applications, meaning even non-crypto credentials are at risk. Always download wallet software only from official sources and never enter your seed phrase into desktop pop-ups.