Hijacked HBO Max Reddit Account Pushes 108 Crypto Malware Ads Using Onchain Contracts

By Abhinav Tewari // September 17, 2026 @ 08:04 AM Make AlphaWire Logo preferred on Google News

Share

344_hijacked_hbo_max_reddit_account_used_onchain_contracts_to_power_crypto_theft_malware_1x

Share

Points of Focus

  • Hackers ran 108 malicious ads from HBO Max’s hijacked Reddit account.
  • The malware included clippers and fake Ledger, Trezor, and Exodus wallet apps.
  • Attackers controlled the malware via Binance Smart Chain smart contracts.

 

 

Attackers hijacked HBO Max’s verified Reddit account, u/hbomax, and used it to run 108 malicious advertisements over roughly 48 hours starting around Sep. 6, according to joint research from Hudson Rock and ADAMnetworks.

 

 

The campaign, which researchers named PasteSwitch, delivered operating-system-specific malware built to steal passwords, browser data, and cryptocurrency from victims’ wallets.

Alon Gal, founder and CTO of Hudson Rock, said the account was ‘weaponized to blast 108 malicious ads across the platform, running an evasive cross-platform ClickFix operation’ before Reddit administrators shut it down. 

Reddit paused the ads and opened an investigation; Warner Bros. Discovery, HBO Max’s parent company, has not responded to press inquiries about the takeover.

 

How the ClickFix attack tricked victims into infecting themselves

The ads promoted a native HBO Max application for macOS that does not actually exist, a detail a Reddit user named Alex Cutts flagged after spotting the ad credited to the verified HBO Max account. Clicking through led to a convincing lookalike site, hbomaxx[.]us, where a download button displayed instructions telling victims to copy and paste a command into Terminal or PowerShell rather than downloading a file the conventional way.

That technique, known as ClickFix, has been rising in popularity specifically because it shifts execution to a trusted local tool the victim runs themselves, letting attackers sidestep browser download warnings and reputation-based malware scanners built to catch conventional installers.

 

The crypto-specific payloads and their on-chain infrastructure

Beyond general infostealers, PasteSwitch delivered fake versions of Ledger, Trezor Suite, and Exodus wallet software designed to capture victims’ recovery phrases, alongside two clipper malware variants, AnimateClipper and ZigClipper, that silently replace a copied cryptocurrency address with one the attackers control.

The clippers’ command-and-control setup is the campaign’s most technically distinctive feature. Rather than relying on a registered domain that researchers or platforms could take down, Hudson Rock said the malware pulls its current control address from Binance Smart Chain smart contracts, letting attackers redirect infrastructure instantly by updating an on-chain contract instead of standing up new servers. 

Hudson Rock documented 36 such mainnet changes from the same controller address between March and July 2026, meaning this infrastructure had been in active use for months before the HBO Max incident.

 

Why a verified account made the attack more effective

‘A malicious advertisement coming from a random account immediately raises suspicion, but an advertisement associated with a verified HBO Max account carries an implicit level of legitimacy,’ Ensar Seker, CISO at SOCRadar, told SC Media. Once attackers compromise a trusted brand’s identity, they inherit that trust as part of the social engineering chain, a pattern that applies equally to a verified exchange or wallet provider account as it does to a streaming service.

Reddit’s after-the-fact response, pausing the ads once flagged rather than catching them proactively, points to a persistent gap in ad-platform vetting for accounts that already carry a verified badge. 

This is not the first time a verified social account has been weaponized to reach crypto victims; high-profile account takeovers pushing fake token giveaways and phishing links have recurred across major platforms for years, because a verified badge substitutes for the skepticism a random, unverified account would trigger. 

PasteSwitch’s contribution is a more durable version of that same trust exploit, paired with infrastructure designed to survive takedown attempts rather than a one-shot scam link.

For crypto users specifically, the practical lesson is narrower than ‘don’t click suspicious ads’: no legitimate application update requires pasting a command into Terminal or PowerShell, and no wallet provider will ever need a recovery phrase entered into an app to ‘verify’ or ‘restore’ access. Both fake Ledger and Trezor apps rely on victims believing otherwise.

Disclaimer: This article is for informational purposes only and does not constitute financial or investment advice. Cryptocurrency prices are highly volatile. Always conduct your own research before making investment decisions.

Share

Default avatar

Abhinav Tewari

Abhinav is a researcher and author specializing in cryptocurrency, blockchain, and Web3, translating complex protocols into actionable insight for institutions and builders. Drawing on experience across digital marketing, management, and research, he focuses on tokenization, stablecoins and payments, DeFi, and real‑world assets, with rigorous analysis of protocol economics, security, governance, and layer‑2 scalability.

Table of content

Ad

Related Articles