The Wallets2 Stealer Log Means Someone Could Be Logging Into Your Accounts
Stealer Log "Wallets2" Exposes 7,974 Records
HEROIC analysts identified a stealer log file uploaded to a public Telegram channel on December 16, 2022, containing 7,974 records tied to United States accounts. The log, labeled "Wallets2," exposed email addresses, plaintext passwords, and API host URLs harvested directly from infected devices.
Why This Is Dangerous
Because the passwords in this log were captured and stored in plaintext, anyone who downloads the file can log directly into the affected accounts right now, without cracking or guessing anything. If your email and password ended up in this log, someone else could already be signing into your accounts, checking your inbox, or accessing a connected service, without you knowing.
What Was Exposed
- Email addresses
- Plaintext passwords
- API host URLs (the services each login connects to)
Why This Matters
With 7,974 sets of credentials exposed in plaintext, this log gives attackers a ready-made list for credential stuffing, testing each stolen email and password combination against banking sites, email providers, and other services. Anyone in this group who reused a password elsewhere faces real risk of account takeover, identity theft, and financial fraud.
How Stealer Logs Work
A stealer log is generated by information-stealing malware that infects a device, often through a malicious download, cracked software, or a phishing link, and silently harvests saved passwords, browser data, and visited URLs. The malware sends everything it collects back to whoever controls the infection, and the resulting log is then packaged and shared, in this case uploaded to a public Telegram channel where anyone can download it. Because the theft happens on the victim's own device, it bypasses the security defenses of the websites and services themselves.
Check If You Are Affected
If you want to know whether your email address is part of this stealer log or any of the thousands of similar breaches HEROIC tracks, use HEROIC's free breach scanner to check it against a database of more than 400 billion leaked records. It takes only seconds, and it lets you change any reused passwords before someone else uses them first.
Breach Breakdown
7,974 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds