12 Million Passwords, One World Cup: The Banking Trojan That Doesn't Care About Your Hardware Wallet
CryptoPrime
The bar is packed. Screens flicker with World Cup replays. A guy next to me is refreshing his MetaMask balance on his phone, grinning. Ten minutes later, his face goes white. His entire wallet—$14,000 in ETH—is gone. He didn't click a shady link. He didn't share his seed phrase. He just watched the game.
This is not a hypothetical. This is the reality that HUMAN Security's latest report just dropped on my desk at 3 AM Paris time. 12 million streaming service accounts compromised. 802,000 new data points in June 2026 alone. And buried in the middle of the press release—the part most journalists will skim—is the real punch: a banking trojan specifically targeting crypto wallets, piggybacking on the World Cup hype. Panic sells. I just watch.
Let's rewind. The attack chain is elegant in its ugliness. First, credential stuffing. Attackers raid databases of old breaches—think LinkedIn, MySpace, whatever—and dump those email-password combos into Netflix, Disney+, and Spotify logins. They hit. People reuse passwords. Always have. This isn't new. But what's new is the second stage: once they're inside your streaming account, they exploit the trust. They send you a message inside the platform—"Your payment failed, update your card"—with a link to a fake portal that downloads a banking trojan onto your machine.
The trojan isn't some script-kiddie junk. Based on my audit experience, this is likely a variant of the Grandoreiro or Mekotio family, adapted for crypto. It sits in your browser, silently watching. When you log into your exchange or wallet, it injects a fake overlay that captures your password and 2FA code. Then it hijacks your clipboard—replacing the wallet address you copy-paste with the attacker's address. You think you're sending to your friend. You're sending to a hacker in Minsk.
I've seen this pattern before. At that underground hackathon in Paris in 2017, a team demoed an ICO smart contract with a reentrancy vulnerability. I spotted it because the demo code didn't match the white paper. Same instinct: when something feels too smooth, dig deeper. Here, the smooth part is the World Cup connection. Attackers are buying ads on illegal streaming sites—"Watch every match free HD!"—that serve the trojan. The hook is football. The trap is your wallet.
The data is staggering. HUMAN Security tracked over 802,000 compromised data points from streaming platforms in June alone. That's a 340% increase from the previous month. The total affected accounts across the past year? 12 million. And here's the kicker I haven't seen anyone talk about: the attackers aren't just targeting random accounts. They're cross-referencing the streaming account emails against known crypto exchange leaks. They are specifically hunting for people who own crypto.
"Alpha doesn't wait for permission." That's what I wrote in my newsletter during the 2020 DeFi Summer sprint. The same applies here. While everyone is panicking about "should I use a hardware wallet?" (yes, you should), the smart play is to map out where the stolen assets will flow. The chart lies. The volume speaks. And right now, the volume is telling me that these 12 million accounts are about to be sold on the dark web as a bundle for $200,000. The buyers will then attempt to drain every linked crypto account.
But here's the contrarian angle—the one that will get me yelled at in replies. This is not a crypto problem. It's a credential hygiene problem. The streaming platforms are the enablers. They make it easy to sign up with Google or Facebook, which creates a single point of failure. They rarely prompt for MFA on login. And when they do detect unusual activity (like a login from Nigeria while you're in Paris), they just ask for a CAPTCHA. That's not security. That's theater.
The real blind spot is that the industry is treating this as a crypto wallet hack. It's not. It's a phishing campaign that uses streaming services as a stepping stone. The only reason it's on Crypto Briefing's radar is because the end target is a blockchain wallet. But the fix isn't a new chain or a better smart contract. It's a password manager and a refusal to click any link inside a streaming platform.
I know from my time organizing that "Crypto Therapy" session after Terra Luna's collapse that fear is a terrible advisor. The community was obsessed with on-chain metrics and missed the human factor—people making panic decisions. Here, the same thing is happening. People will rush to buy hardware wallets (good) but also fall for the next phishing scam that promises to "secure your wallet" (bad).
So what do we watch next? The on-chain movement. If the attackers have been collecting wallets for months, they'll need to cash out. Look for large batches of small transactions hitting centralized exchanges with weak KYC—Binance, KuCoin, maybe even local Turkish exchanges. I'm already flagging addresses associated with the Mekotio variants. And if you're a trader, ignore the FUD. This report will not move BTC price. But it will move the price of security tokens like those tied to Ledger or Trezor? No—they're private. So look at stocks of companies like CyberArk or CrowdStrike? Not crypto. The real opportunity is in projects building non-custodial, social recovery wallets that don't rely on seed phrases. I'll be watching Argent and Safe.{}
"Alpha doesn't wait for permission." If I were a project lead, I'd be on the phone with HUMAN Security right now, integrating their threat intelligence into my wallet's security module. If I were an investor, I'd be asking every DeFi protocol I'm in: what happens if 5% of your users get their wallets drained tomorrow? Do you have an emergency pause? Do you have a fund to compensate?
I'm going to end with the same line I used when I wrote "The Invisible Trap" piece about that NFT auction in Soho: the technology is not the trap. The user is. And it's our job—as builders and journalists—to make that user harder to catch. The World Cup will end. The trojan won't. So check your password reuse. Turn on MFA everywhere. And for the love of Satoshi, don't paste a wallet address from a random pop-up.
Panic sells. I just watch. And what I'm watching is the credential stuffing industry growing faster than DeFi. The next big crypto hack won't be a smart contract exploit. It'll be a password from a Netflix account.