LIVE
Bitcoin $72-73K: ETF Realized Price and Coinbase PremiumConsensys Split: MetaMask Goes Its Own WayMexican Musician, Family Reportedly Killed Over Bitcoin WalletSecret Service Freezes $52.8M in Crypto Tied to XinbiClarity Act Lobbying: Crypto, Banks Target Senators' Home States1inch Routes Over $800B as Co-Founder Flags DeFi Profit HurdleMalone Lam Pleads Guilty in $245 Million Bitcoin TheftScam Center Strike Force Restrains $52M in Crypto in One DayDee Goens Replaces Jacob Horne as Zora CEORipple's Alderoty Urges Crypto Holders' Input on Clarity ActBitcoin $72-73K: ETF Realized Price and Coinbase PremiumConsensys Split: MetaMask Goes Its Own WayMexican Musician, Family Reportedly Killed Over Bitcoin WalletSecret Service Freezes $52.8M in Crypto Tied to XinbiClarity Act Lobbying: Crypto, Banks Target Senators' Home States1inch Routes Over $800B as Co-Founder Flags DeFi Profit HurdleMalone Lam Pleads Guilty in $245 Million Bitcoin TheftScam Center Strike Force Restrains $52M in Crypto in One DayDee Goens Replaces Jacob Horne as Zora CEORipple's Alderoty Urges Crypto Holders' Input on Clarity Act
Homepage/News/Hackers Hijack HBO Max Reddit Account to Push Crypto-Stealing Malware
NEWS

Hackers Hijack HBO Max Reddit Account to Push Crypto-Stealing Malware

·4 MIN READ·
MakeThe CC Presspreferred onGoogle

Hackers hijacked the verified HBO Max Reddit account and used it to blast 108 fake advertisements at unsuspecting users, all designed to steal cryptocurrency wallets and browser credentials in a sophisticated cross-platform malware campaign researchers are calling PasteSwitch.

KEY FINDINGS - EVIDENCE LEVEL: MULTI-SOURCE
3Key sections mapped in this report
0Internal references connected to related coverage
3External source domains cited in the article
4 minEstimated time to read the full report

Hudson Rock researchers say the compromised u/hbomax account ran 108 distinct ClickFix advertisements over a 48-hour window. The account was verified, meaning Reddit users had every reason to trust what they saw.

Compromised-account campaign
108
distinct ClickFix ads were reportedly run in 48 hours from the verified u/hbomax account, according to Hudson Rock.

HBO Max’s Reddit Account Reportedly Used to Spread Malware

The ads sent users to convincing lookalike download pages that looked like legitimate HBO Max installers. Once there, macOS users were told to paste commands into Terminal; Windows users were directed to paste into Run or PowerShell. This is the hallmark of ClickFix, a social-engineering technique that tricks victims into executing malware themselves. For related coverage, see Senate Rejects CLARITY Act, Raising Bitcoin Uncertainty.

Malwarebytes reports that macOS victims could receive MacSync or the Atomic macOS Stealer (AMOS), both designed to siphon browser credentials, Telegram session data, saved passwords, and cryptocurrency wallet recovery phrases. Windows users faced Amatera, an in-memory infostealer that leaves minimal forensic traces.

The identity of the threat actors and the exact method used to take over the HBO Max account have not been publicly confirmed. The PasteSwitch operation’s blockchain infrastructure, however, left a clearer trail. This mirrors patterns seen in BNB Chain malware campaigns that used fake CAPTCHAs to deliver similar clipboard-hijacking payloads.

How the Crypto-Stealing Malware Threat Could Affect Users

PasteSwitch is not just a simple info-stealer campaign. Hudson Rock’s research reveals a cryptocurrency clipboard-clipping branch that used BNB Smart Chain smart contracts as mutable command-and-control dead drops. When a victim copies a wallet address to make a crypto payment, the clipper silently replaces it with an attacker-controlled address.

Researchers observed 36 BSC mainnet contract changes made by the same controller between March and July 2026, suggesting the operation ran for months and actively rotated its infrastructure to stay ahead of blocklists.

PasteSwitch infrastructure
36
BSC mainnet C2-contract changes were observed from one controller between March and July 2026, according to Hudson Rock.

Using smart contracts as C2 infrastructure is a calculated move. Blockchain transactions are immutable and public, but the attacker controls what wallet address is written into the contract at any given moment. Victims and defenders see the theft happen on-chain but cannot easily block a decentralized smart contract the way they would a malicious domain. This technique has also been linked to multi-chain crypto thefts that have drained millions from exchanges.

The total number of victims and the value of any cryptocurrency stolen through this campaign remain unconfirmed, according to reporting from Decrypt. No public statement from HBO Max or Reddit has been located.

What Crypto Users Should Do After Seeing Suspicious Reddit Posts

Malwarebytes says Reddit administrators paused the affected ads and opened a security investigation after reports were received. But the ads ran for 48 hours, and anyone who interacted with them during that window could be at risk.

If you clicked a link or downloaded a file from the u/hbomax account during the campaign period, the priority is your crypto wallets. Disconnect any connected wallets from unknown sites immediately. Move assets to a fresh wallet generated on a clean, unaffected device before doing anything else.

Never enter a recovery phrase or private key into any site you reached through a social media post, even one from a verified account. A checkmark means the account is authenticated, not that it is safe. Attackers specifically target high-trust accounts for this reason. Always verify promotions and app downloads through official company websites directly.

Report any suspicious posts to Reddit and to HBO Max through its official channels. The faster platform administrators are alerted, the sooner compromised accounts are locked down. Given that even major exchange hacks have seen partial recoveries when response time is fast, early reporting matters.

With clipboard-clipping malware spreading through increasingly creative social-engineering channels, the question is no longer whether trusted brand accounts will be targeted again. It is which one gets hijacked next, and how many wallets get drained before anyone notices.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency and digital asset markets carry significant risk. Always do your own research before making decisions.

SOURCE TRANSPARENCY
  • External Source - Referenced domain: hudsonrock.com
  • External Source - Referenced domain: theccpress.com
  • External Source - Referenced domain: malwarebytes.com
  • Byline - Reported by Joshua Trelawen
  • Coverage Desk - Primary editorial category: News
  • Media Asset - Featured image served from the WordPress media library
Hackers Hijack HBO Max Reddit Account to Push Crypto-Stealing Malware | TheCCPress