HBO Max Reddit Hack: 108 Malware Ads Targeted Crypto Wallets

HBO Max Reddit Hack: 108 Malware Ads Targeted Crypto Wallets

HBO Max’s Verified Reddit Account Hijacked in Malware Campaign

Hackers compromised HBO Max’s verified Reddit account and used the trusted profile to distribute 108 malicious advertisements over roughly 48 hours, according to cybersecurity researchers.

The campaign targeted both Windows and macOS users with malware capable of stealing browser credentials, passwords and cryptocurrency-related information. Researchers also identified fake cryptocurrency wallet applications designed to capture users’ wallet recovery phrases.

The operation was linked by security researchers at Hudson Rock and ADAMnetworks to a broader malware distribution campaign dubbed PasteSwitch. The campaign used a social-engineering technique known as ClickFix, which tricks victims into manually executing malicious commands on their computers.

Reddit subsequently paused the malicious advertisements and secured the compromised account, but researchers have not established how many people were infected or how much cryptocurrency, if any, was stolen.

108 Malicious Ads Were Posted in 48 Hours

Hudson Rock said attackers exploited the verified u/hbomax account to push 108 distinct malicious advertisements during a roughly 48-hour period.

The ads did not all use the HBO Max brand. Researchers found several different themes designed to appeal to different groups of Reddit users.

According to Hudson Rock and ADAMnetworks, the campaign included:

  • 46 HBO Max-themed advertisements
  • 36 advertisements impersonating AI and developer tools
  • 15 advertisements promoting a fake macOS disk utility
  • 11 advertisements using other developer-software themes

The campaigns were designed to direct users toward convincing websites before attempting to deliver malware through ClickFix techniques.

The use of a verified corporate account gave the advertisements an additional layer of credibility.

Fake HBO Max Mac App Used as a Lure

The incident was initially brought to wider attention after a Reddit user discovered an advertisement from the verified HBO Max account promoting what appeared to be a native HBO Max application for macOS.

However, HBO Max does not currently offer such a native Mac application.

The advertisement directed users to a website designed to resemble an official HBO Max page. Instead of providing a legitimate application download, the site presented instructions that attempted to persuade visitors to execute a command on their computers.

Security researchers identified this behavior as a ClickFix attack.

The technique is increasingly used by cybercriminals because it shifts an important part of the attack from the browser to the victim. Rather than simply downloading and executing a suspicious file, the victim is manipulated into running a command themselves.

What Is a ClickFix Attack?

ClickFix is a social-engineering technique in which a malicious website displays instructions claiming that users need to perform an action to solve a problem, verify themselves or install software.

In these attacks, victims may be instructed to:

  1. Copy a command supplied by the website.
  2. Open a legitimate system utility such as Terminal or PowerShell.
  3. Paste the command.
  4. Execute it.

The resulting code can download or launch malware.

Security researchers have warned that ClickFix has become increasingly prevalent because attackers can abuse legitimate operating-system tools and persuade users to initiate the execution themselves.

In the HBO Max campaign, macOS users were directed toward Terminal-based execution, while Windows users could be directed toward tools including PowerShell and Windows Run.

Fake Crypto Wallet Apps Targeted Recovery Phrases

One of the most serious elements for cryptocurrency users was the distribution of counterfeit wallet applications.

Researchers identified fake versions of popular crypto wallet software, including applications impersonating Ledger, Trezor Suite and Exodus.

These applications were designed to capture users’ wallet recovery phrases.

A cryptocurrency wallet recovery phrase, often consisting of 12 or 24 words, can provide the credentials necessary to restore access to a wallet. If a user enters the phrase into a malicious application, attackers may be able to gain control of the associated wallet.

The researchers therefore identified the fake wallet component as a direct cryptocurrency-theft risk, although publicly available research has not established how much crypto was actually stolen through the campaign.

Malware Also Targeted Passwords and Browser Data

The campaign was broader than cryptocurrency theft.

On macOS, researchers identified malware families including MacSync and an AMOS-related payload capable of harvesting sensitive information.

Reported targets included browser credentials, browser profiles, Telegram information, Apple Notes data, macOS passwords and cryptocurrency-related information.

Windows users could receive different malware, including the Amatera Stealer, which researchers linked to credential theft and other forms of information collection.

This operating-system-specific approach allowed the campaign to deliver different payloads depending on the victim’s device.

Cryptocurrency Clippers Added Another Threat

Researchers also linked the PasteSwitch operation to cryptocurrency clipboard malware, including AnimateClipper and ZigClipper.

These types of malware monitor cryptocurrency addresses copied to a computer’s clipboard.

If a victim copies a legitimate wallet address and then attempts to paste it into a transaction, the malware can replace the copied address with an attacker-controlled address.

This creates a particularly dangerous scenario because the victim may believe they are sending cryptocurrency to the intended recipient while the transaction is actually directed elsewhere.

Unlike a fake wallet application, clipboard malware can operate without requiring a user to intentionally enter a recovery phrase.

Attackers Used Blockchain-Based Infrastructure

The PasteSwitch operation also demonstrated an unusual use of blockchain infrastructure.

According to Hudson Rock, the attackers used Binance Smart Chain smart contracts as part of the command-and-control infrastructure associated with cryptocurrency clipboard malware.

Researchers observed 36 mainnet changes between March and July 2026 associated with the same attacker controller address.

The approach can allow attackers to change command-and-control information without relying entirely on conventional centralized infrastructure.

This demonstrates how blockchain technology can be incorporated into malware infrastructure even when the underlying cryptocurrency is not the primary target.

Why the Verified HBO Max Account Was Valuable

The attackers did not simply create a new Reddit account and advertise malware.

They first obtained control of an account associated with a recognizable entertainment brand and carrying a verification status.

That provided a significant social-engineering advantage.

Users are generally more likely to trust an advertisement when it appears to come from a legitimate company rather than an unknown account.

The incident demonstrates that a verified badge does not guarantee that every advertisement or link published through an account is safe.

If an account’s credentials are compromised, attackers can potentially abuse the reputation built around that account.

Reddit Paused the Malicious Ads

Reddit was notified about the malicious activity associated with the HBO Max account.

The company subsequently paused the advertisements and its security and safety teams investigated the incident.

Reddit told TechCrunch that an HBO Max advertising account had been compromised and used to run advertisements containing malicious links.

The precise method used to initially compromise the HBO Max account has not been publicly established.

BleepingComputer reported that it contacted HBO and Warner Bros. Discovery for comment but had not received a response at the time of publication.

Researchers Warn Users Not to Paste Commands From Websites

The incident has renewed warnings about copying commands from webpages into Terminal, PowerShell or other system utilities.

Security researchers recommend that users treat any webpage asking them to execute a command as a major warning sign, particularly when the instruction is presented as a requirement to install an application or solve a technical problem.

Malwarebytes recommends avoiding commands supplied through advertisements, websites, emails or messages unless the source is trusted and the user understands exactly what the command does.

For cryptocurrency users, additional precautions are important.

A legitimate wallet application should be downloaded through the wallet provider’s official distribution channels rather than through an advertisement on a social media platform.

How Crypto Users Can Protect Their Wallets

The HBO Max Reddit incident highlights several practical security measures for cryptocurrency users.

Never Enter a Seed Phrase Into an Unverified App

A wallet recovery phrase should be treated as highly sensitive information.

Users should not enter it into applications obtained from advertisements, unknown websites or links shared through social media.

Avoid Running Commands From Ads

If an advertisement tells users to open Terminal, PowerShell or Windows Run and paste a command, users should stop and verify the request through the company’s official website.

Verify Wallet Software

Crypto wallet applications should be obtained through the wallet provider’s official website or verified app-store listing.

Users should also check the publisher carefully because malicious applications can use names and branding that resemble legitimate products.

Check Cryptocurrency Addresses Before Sending

Users should verify the destination address immediately before approving a cryptocurrency transaction.

Clipboard malware can replace addresses without obvious visual warnings.

Do Not Trust Verification Badges Alone

A verified social-media account can still be compromised.

Users should evaluate the destination website and requested action rather than assuming that a verified account guarantees safety.

Keep Devices Updated

Operating-system and security updates can help protect devices against known vulnerabilities and improve malware detection.

The Campaign Targeted More Than Crypto Users

Although fake wallet applications and cryptocurrency clippers made the campaign particularly relevant to crypto users, the PasteSwitch operation was much broader.

Attackers also used fake AI software, developer tools and macOS utilities as lures.

Among the advertisements identified by researchers were campaigns impersonating OpenAI Codex and other developer-oriented software.

This suggests that the attackers were attempting to reach different categories of users rather than relying solely on cryptocurrency-related traffic.

The strategy also shows why malvertising can be effective: a user does not necessarily need to be searching for malware or cryptocurrency for the attack to reach them.

No Confirmed Figure for Victims or Crypto Losses

Despite the scale of the advertising operation, the number of people who actually executed the malicious commands remains unclear.

Likewise, researchers have not publicly confirmed a total amount of cryptocurrency stolen from victims through the fake wallets or clipboard malware.

That distinction is important.

108 malicious advertisements does not mean 108 victims.

Some users may have ignored the advertisements, while others may have clicked the links without executing the malicious commands. Security researchers can identify the infrastructure and malware without necessarily knowing how many people ultimately lost data or cryptocurrency.

A Warning for Social Media Platforms

The incident also raises questions about security controls surrounding advertising accounts.

Attackers were able to use a compromised, verified corporate account to distribute malicious advertisements through a legitimate advertising system.

That creates a challenge for platforms because traditional account verification does not necessarily protect against account takeover.

The incident demonstrates why platforms may need to combine account authentication with behavioral monitoring, advertisement analysis and rapid response systems.

ClickFix Threat Continues to Grow

The HBO Max incident is part of a broader rise in ClickFix attacks.

Researchers have increasingly observed campaigns using fake CAPTCHA pages, software downloads, browser warnings and technical-support prompts to convince users to execute commands themselves.

TechCrunch reported that ClickFix attacks have become a significant cybersecurity threat in 2026, with campaigns targeting both Windows and macOS users.

The technique is particularly effective against users who are accustomed to following online troubleshooting instructions.

What the HBO Max Reddit Hack Means for Crypto Security

For the cryptocurrency industry, the incident demonstrates that wallet security threats increasingly extend beyond traditional phishing websites.

Attackers are now combining:

  • Social-media account takeovers
  • Malvertising
  • Verified corporate identities
  • Fake software
  • ClickFix social engineering
  • Information-stealing malware
  • Fake crypto wallets
  • Clipboard hijackers
  • Blockchain-based command-and-control infrastructure

This combination can make attacks difficult for ordinary users to recognize.

The use of a legitimate-looking HBO Max Reddit account is particularly significant because it shows how attackers can exploit trust before attempting to steal credentials or cryptocurrency.

Bottom Line

Hackers hijacked HBO Max’s verified Reddit account and used it to run 108 malicious advertisements over roughly 48 hours, according to Hudson Rock and ADAMnetworks.

The campaign, linked to the broader PasteSwitch operation, targeted both Windows and macOS users with ClickFix attacks and multiple forms of malware. Researchers identified information stealers, cryptocurrency clipboard hijackers and fake Ledger, Trezor Suite and Exodus wallet applications designed to capture recovery phrases.

Reddit subsequently paused the malicious advertisements and secured the compromised account. However, the number of affected users and any cryptocurrency losses have not been publicly confirmed.

The incident serves as a significant warning for crypto users: a verified social-media account does not guarantee that an advertisement is legitimate. Users should avoid installing wallet software from advertisements, never enter recovery phrases into unverified applications and never execute commands supplied by unfamiliar webpages.

As ClickFix campaigns continue to evolve, cybersecurity researchers expect attackers to keep exploiting trusted brands and legitimate distribution channels to make malicious software appear credible.

Also Check: David Bailey Says AI Could Drive Bitcoin Adoption by Simplifying Wallets

author avatar
Sks Web Developer & Content Writer
Suraj Kumar Sah is a tech enthusiast, web developer, and content creator with 5 years of experience in the field of technology and digital solutions. Holding a B.E. in Computer Science and Engineering (CSE), he specializes in building functional and visually appealing websites that transform ideas into reality. With a strong passion for innovation, he focuses on creating engaging and user-friendly web experiences. His work reflects a keen attention to detail, clean coding practices, and a commitment to continuous learning. He continues to refine his expertise through hands-on projects, delivering original, high-quality, and impactful digital solutions.
Scroll to Top