Hackers Abuse Google Sheets to Steal Cryptocurrency Wallet Addresses
Hackers are using Google Sheets as an unlikely control channel in a cryptocurrency theft campaign. The operation turns a browser session into a place where malicious code runs, rather than placing a conventional program on a victim's computer.
The attackers promote a fake report claiming to expose profitable flaws at cryptocurrency swap services. Victims are told to paste JavaScript into Chrome's address bar or add it to a browser extension, allowing the code to run on the trading site they are visiting.
The campaign began with ClickFix-style lures in October 2025 and adopted Google's Visualization API in March 2026. The researchers found messages on Telegram, DarkForums, email, and paste sites, targeting people interested in trading, coding, hacking, and quick financial gains.